{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:fa026c9e-69f1-5b2b-ac8c-7171e63307f7",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4",
      "type": "library",
      "group": "io.netty",
      "name": "netty-common",
      "version": "4.1.75.Final-tuxcare.4",
      "purl": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:8768283d-d088-59a4-9d78-efc2581ecfbe",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24823 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d0d728b-5867-5d9d-8e1f-859acc665640",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41881 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d243a957-ca80-5fff-b5f6-084d6f26cfb9",
      "id": "CVE-2022-41915",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-41915 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c69dc0b3-0ba9-56c5-b1fb-3c8fc05094e5",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34462 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f5fd6ab-ce6e-5ea6-b277-4bab623e7db9",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e69da63a-c3a3-5746-aa7f-fd68852487fc",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-common 4.1.75.Final-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79cb251e-1abb-5518-a642-c94b1b4feb00",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-29025 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f189c38-a485-527a-9103-4b7e6314ff4f",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47535 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00c81ce8-b28d-5044-9539-1ecf61781048",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24970 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82a4a778-9b22-57f2-8449-d159588eeccb",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-25193 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c20ede6-256e-5d0b-a306-cfc3d8318849",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55163 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3717da92-4dee-518a-bc3f-9e47ba7a42eb",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58056 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23718b0a-fadb-5f34-aede-ff88cc1610f7",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58057 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34d0bb79-74cd-5806-8b93-1b5d6ef030c6",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59419 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de1df464-023a-5bff-8c2c-26c793b0eb79",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67735 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc63c8a8-2589-536d-b629-9f8a83e54ee3",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47b6da9b-cbef-5680-83cc-a97261e0400a",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a21a5e3-c345-5a77-8a98-35e56ddc180c",
      "id": "CVE-2026-41417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41417 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b5c54ca-bd6d-56ef-8eb9-68689b7afead",
      "id": "CVE-2026-42577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42577 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:318ec74a-8c0a-58c7-91a2-386344a486f4",
      "id": "CVE-2026-42578",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42578 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c450572-b435-5272-9c23-9f0f576d2f0f",
      "id": "CVE-2026-42579",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42579 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27dae142-5360-5f81-856e-00f879589662",
      "id": "CVE-2026-42580",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42580 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:551524ed-70c1-5257-abd9-c43e3cb437b7",
      "id": "CVE-2026-42581",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42581 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be17883e-9c6e-5d5b-a15a-ead177a80264",
      "id": "CVE-2026-42583",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42583 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:512a5af5-3f15-5f6f-a631-a6296248e2f5",
      "id": "CVE-2026-42584",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42584 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20a08509-cef4-5f2a-a2cf-bb6f7e243082",
      "id": "CVE-2026-42585",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42585 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8150e49b-344d-5c47-bfbd-006bafa0d910",
      "id": "CVE-2026-42586",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42586 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ecdb6c09-eaa3-556c-acb7-ef30b4d43739",
      "id": "CVE-2026-42587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42587 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc529457-3eeb-5d0b-a5d2-59b88b732049",
      "id": "CVE-2026-44248",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44248 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2135d600-5fc5-54ea-aa7a-aa5f1343a683",
      "id": "CVE-2026-44249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44249 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73ac3491-1820-5388-bfe1-55555a10e7de",
      "id": "CVE-2026-44250",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44250 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93557c99-8ac0-5e1e-aa29-db048b57c515",
      "id": "CVE-2026-44890",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44890 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7cf934a9-8604-59da-b950-85c9f6623195",
      "id": "CVE-2026-44891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44891 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0a0e071-37b1-5e65-872f-2971458f3bcb",
      "id": "CVE-2026-44893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44893 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:317d26ca-6981-52af-ad4b-f015be27b7a4",
      "id": "CVE-2026-45416",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45416 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b20b6cb-f767-53ac-81ce-47e41de9152f",
      "id": "CVE-2026-45536",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45536 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c1386ab-d0ce-5312-bf53-ae224b913970",
      "id": "CVE-2026-45673",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45673 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd623ca6-505f-541c-b178-046b35d411a9",
      "id": "CVE-2026-45674",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45674 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fce44c60-1812-55ae-9171-5c84a36e03e8",
      "id": "CVE-2026-46340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46340 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c04e7b3-e94d-5840-9eec-024fa998aaa8",
      "id": "CVE-2026-47244",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47244 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00b489a3-170e-5deb-b3e6-e682a5b73821",
      "id": "CVE-2026-47691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47691 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b84353c0-f7c4-5dcc-8e57-50d47939054f",
      "id": "CVE-2026-48006",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48006 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60fb5fa2-cd3f-5c4e-80c5-b5f6db372a56",
      "id": "CVE-2026-48043",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-48043 does not affect version 4.1.75.Final-tuxcare.4 of io.netty:netty-common. already_fixed \u2014 The target repository (Netty 4.1.75.Final-tuxcare.1) already contains equivalent protection against CVE-2026-48043. While the upstream patch targets a newer architecture with a ChannelInboundHandlerAdapter tail handler (introduced in CVE-2025-58057 refactoring), the target's older architecture implements the same defensive pattern: a try-finally block ensuring ByteBuf.release() is called uncond..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea62c1fd-2f3a-5a7d-acc9-d9c557c3bcea",
      "id": "CVE-2026-48059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48059 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16657e55-81ad-5844-8448-48b61db19b80",
      "id": "CVE-2026-50010",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50010 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:337366b0-2fca-5caf-ae29-abecd2843e6e",
      "id": "CVE-2026-50011",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50011 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe82ee09-d457-57ce-b751-501817b5cc82",
      "id": "CVE-2026-50020",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50020 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c172308f-bdb8-541e-80a5-0824143cc4fe",
      "id": "CVE-2026-50560",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50560 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee55c7aa-402d-56b3-b350-47415389af49",
      "id": "CVE-2026-55831",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55831 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e246eee-03df-5289-9f84-82ec31588a93",
      "id": "CVE-2026-55833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55833 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72739502-35f8-5bd7-9ff3-c604e57016f2",
      "id": "CVE-2026-55851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55851 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01b22002-9322-5525-9f51-a8c6f2c90fae",
      "id": "CVE-2026-56745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56745 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b6384a2-54d1-53f0-9929-bcd8d9c16162",
      "id": "CVE-2026-56746",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56746 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a75e49b5-26fc-52d1-8306-3be231de4634",
      "id": "CVE-2026-56817",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56817 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d325221f-d4f2-54f5-a389-38f368d2e090",
      "id": "CVE-2026-56818",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56818 does not affect version 4.1.75.Final-tuxcare.4 of io.netty:netty-common. not_affected \u2014 The target version 4.1.75.Final (released March 2022) predates the introduction of the vulnerable feature by over 4 years. CVE-2026-56818 describes incomplete cleanup when the `maxElements` limit is exceeded in RedisArrayAggregator. However, the `maxElements` configuration parameter and associated exception handling were introduced in June 2026 (commits e51c64c964 and 728c98b8ec), neither of wh..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d43374c3-6d9f-5cc9-a73e-55e9bcb917b2",
      "id": "CVE-2026-56819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56819 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b272fe0e-cc84-54ec-809f-b86026f8898b",
      "id": "CVE-2026-59898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59898 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9209e101-c788-52a0-90ab-c1c7aac3beec",
      "id": "CVE-2026-59899",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59899 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e843ee18-56e7-51d1-b2d1-4b585cd91493",
      "id": "CVE-2026-59900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59900 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:708ea9e9-cda6-5af6-a85e-4d8978e7a24c",
      "id": "CVE-2026-59901",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59901 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07d4a0dd-c794-525a-bee5-a1244d808cfa",
      "id": "CVE-2026-59919",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59919 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81947306-120e-5505-b755-2e65fe8a6f99",
      "id": "CVE-2026-59920",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59920 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b47f0c6-1de8-51b5-891e-f73357b31d4b",
      "id": "CVE-2026-59921",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59921 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72c18130-d08c-5565-8fed-2dd8510353af",
      "id": "GHSA-mfg7-5gfp-c4w3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mfg7-5gfp-c4w3 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67ca96d1-e677-5f8c-adfe-add312107e5f",
      "id": "GHSA-v74w-7mr3-4qg3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-v74w-7mr3-4qg3 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f526ad0-36e9-5398-b543-b3bf2d4a6544",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-common."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-common@4.1.75.Final-tuxcare.4"
    }
  ]
}