{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:fe5720c4-3b58-5ba9-aa4c-41c710184f16",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3",
      "type": "library",
      "group": "io.netty",
      "name": "netty-common",
      "version": "4.1.73.Final-tuxcare.3",
      "purl": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:b758a723-f0de-5425-b9c4-1277fa0d5230",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24823 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eeec0799-65ed-5b89-b697-025046c59548",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41881 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:faa71a7a-5e19-5546-ad05-9fd1f164965f",
      "id": "CVE-2022-41915",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-41915 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9aae0f7-722b-5444-b1d0-a5aaf11e49ee",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-34462 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:364d2355-1398-5182-8b44-8b301bf49b9c",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32717de0-a566-5a97-80df-1c0d3396d019",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-common 4.1.73.Final-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a7d42d9-d8a1-5709-8c88-412cf9b78728",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-29025 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bae263ec-4622-59d3-b138-7c321a18df3c",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47535 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5164efe6-405c-59ec-9da0-477437f4e179",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24970 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81a8354c-88a5-5f15-8e46-0b5cf83e1bf6",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-25193 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e94b1dc-aac1-593b-8e68-140fcee3ee46",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55163 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2924f595-04f0-5a74-b088-2a703f507c72",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58056 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88af2a97-97e0-514e-ba7a-bdf6b958bc14",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58057 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f414c22d-bb09-557c-beb5-9e1533bb985b",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59419 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e99a149-2cb0-564f-9b29-ba853bbe9517",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67735 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2bf6f94-64ea-5221-a786-2d01408ac57d",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e135039-534b-5af7-850c-cd4e1411408d",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f1876c9-707e-5ef7-b71c-ad723da1152a",
      "id": "CVE-2026-41417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41417 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a731e7be-61ee-51b2-9cc8-50b6084c4a8a",
      "id": "CVE-2026-42577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42577 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a6497c3-ad9e-562c-a00c-44cf04a75afd",
      "id": "CVE-2026-42578",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42578 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90313617-31d5-5e64-915e-f748c384cf32",
      "id": "CVE-2026-42579",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42579 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbc93ba8-401b-5b5c-b64a-341341194faf",
      "id": "CVE-2026-42580",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42580 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcbd47fa-5baf-53b5-81ab-c19055b083e9",
      "id": "CVE-2026-42581",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42581 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30caed83-066a-5a0c-a007-cb0013ba2405",
      "id": "CVE-2026-42583",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42583 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:304d4cab-d336-5397-af4b-a2080345c757",
      "id": "CVE-2026-42584",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42584 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:788a21a0-ef9b-5996-99e9-97dbea9f8008",
      "id": "CVE-2026-42585",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42585 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:283dc4e9-ec62-55d5-9c15-d19c9bebb017",
      "id": "CVE-2026-42586",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42586 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:baec726c-8cd7-5515-a01a-b08c98c782c7",
      "id": "CVE-2026-42587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42587 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4de8143-6291-5dc9-ad11-38227bcbd53e",
      "id": "CVE-2026-44248",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44248 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8afb96ef-cdff-5090-b481-ec2a8be36b84",
      "id": "CVE-2026-44249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44249 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8b33b98-12af-5765-89a1-0ac3af462920",
      "id": "CVE-2026-44250",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44250 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6528ec5-f121-5e96-a20e-6ba07c6059e3",
      "id": "CVE-2026-44890",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44890 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62390ba0-b248-5ecd-aeba-3c2908744c22",
      "id": "CVE-2026-44891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44891 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6ee8870-c7ec-5ab0-a6b7-2ce86b3cd2fe",
      "id": "CVE-2026-44893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44893 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:531e22fb-20e7-51c9-854a-1440f8b72772",
      "id": "CVE-2026-45416",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45416 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:694a82e1-1002-5196-baeb-3fc92892e19b",
      "id": "CVE-2026-45536",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45536 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf623fbe-23ca-577b-886c-90260d5fe962",
      "id": "CVE-2026-45673",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45673 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45f6648b-2eed-5c1a-a344-ce7a67fe5aee",
      "id": "CVE-2026-45674",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45674 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10d01509-14b3-50aa-a324-f815ec89d725",
      "id": "CVE-2026-46340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46340 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04435527-dd6e-58b9-bb61-b18234be7bd0",
      "id": "CVE-2026-47244",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47244 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:938a183e-f086-58b1-8e0f-cbd6ac494bbc",
      "id": "CVE-2026-47691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47691 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98b34f1b-1be0-5a0f-b6e7-6d80ae15601e",
      "id": "CVE-2026-48006",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48006 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3543efa3-2c3c-5efa-97b1-2818450eb4b2",
      "id": "CVE-2026-48043",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-48043 does not affect version 4.1.73.Final-tuxcare.3 of io.netty:netty-common. not_affected \u2014 Version 4.1.73 is not affected by CVE-2026-48043. The target uses a loop-based architecture with try-finally protection (introduced in 2016) that prevents the buffer leak described in the CVE. The vulnerable ChannelInboundHandlerAdapter pattern that the upstream patch fixes does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92097e16-e7f4-5fdd-bf75-baf07a3f8ecb",
      "id": "CVE-2026-48059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48059 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e06ba0fc-c4d1-5ea5-a19f-dafeb0196a5d",
      "id": "CVE-2026-50010",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50010 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a091413f-9e62-5112-b1c8-3f520e58cd7b",
      "id": "CVE-2026-50011",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50011 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfece11d-32ad-57e3-92b8-0f1b0b32767e",
      "id": "CVE-2026-50020",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50020 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2a05a74-4e27-56eb-b5e8-7f35f5599f6b",
      "id": "CVE-2026-50560",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50560 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac9ac921-472b-5b62-917b-34585a3e5295",
      "id": "CVE-2026-55831",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55831 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a25ce67-1ac0-56bf-9961-10ab7fcc4ed4",
      "id": "CVE-2026-55833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55833 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49526180-eae2-52ca-9f1b-73e420e9226d",
      "id": "CVE-2026-55851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55851 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21b84335-e311-58c2-ac4b-810f4863dbbc",
      "id": "CVE-2026-56745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56745 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83684371-0aba-5c29-b97d-acceaad0a066",
      "id": "CVE-2026-56746",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56746 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a83102f-4c1b-5031-b897-cf18b4af15f7",
      "id": "CVE-2026-56817",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56817 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc5b8aa9-6bbb-5f32-ad1d-6d64512abf65",
      "id": "CVE-2026-56818",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56818 does not affect version 4.1.73.Final-tuxcare.3 of io.netty:netty-common. not_affected \u2014 The target version 4.1.73.Final-tuxcare.2 is NOT AFFECTED by CVE-2026-56818. The vulnerable code pattern (configurable `maxElements` limit check without cleanup, contrasting with `maxNestedArrayDepth` limit check WITH cleanup) was introduced in version 4.1.135.Final through commits e51c64c964 and 728c98b8ec (dated 2026-06-01/02). The target version predates these features entirely and does not ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08213fe7-25d2-5e5b-b3b2-c810a05983e0",
      "id": "CVE-2026-56819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56819 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf1a7d16-eb3a-5ea3-987f-5464d29a4311",
      "id": "CVE-2026-59898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59898 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2439c90-d667-593f-bbb2-3cca55c26bb6",
      "id": "CVE-2026-59899",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59899 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfd9de71-0b17-568d-8638-360ca094c1c5",
      "id": "CVE-2026-59900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59900 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23d13b9f-a153-559b-9e8b-5d2919548ead",
      "id": "CVE-2026-59901",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59901 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c218ae9-6cc0-52b1-a38a-e1128f6738fa",
      "id": "CVE-2026-59919",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59919 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d30015bf-a69e-5c9b-a2d3-cf29903a06e1",
      "id": "CVE-2026-59920",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59920 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85437c5a-8344-5b9f-be2c-0c5ca1b2aa4a",
      "id": "CVE-2026-59921",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59921 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b9d861a-8ef9-5f4e-9350-3ae0806c8092",
      "id": "CVE-2026-73507",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-73507 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f095cd6f-b148-5cec-afae-8d8032e6fb5d",
      "id": "CVE-2026-73508",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-73508 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67ff9cb2-ec77-506f-a13f-e8c9ecfc2001",
      "id": "GHSA-mfg7-5gfp-c4w3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mfg7-5gfp-c4w3 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:836f9324-0073-5dbe-8fc6-9834e329f33e",
      "id": "GHSA-v74w-7mr3-4qg3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-v74w-7mr3-4qg3 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1493f213-72f3-5227-985b-219b5c96f94e",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-common@4.1.73.Final-tuxcare.3"
    }
  ]
}