{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:71a1534c-d599-5dd9-b1cf-4cad071d21a5",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3",
      "type": "library",
      "group": "io.netty",
      "name": "netty-handler-proxy",
      "version": "4.1.73.Final-tuxcare.3",
      "purl": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:f968916b-43e7-538d-8405-1697f02f72c5",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24823 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15553cb3-f981-5a40-a0f6-21b47d1da4f0",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41881 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a7e4e6d-7d1b-5639-91d2-70a265ad8b28",
      "id": "CVE-2022-41915",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-41915 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ef345ad-c1e4-5e97-a4db-ad7101a4ddd4",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-34462 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5190a3a7-5a77-50a0-bf6d-41380fa8a161",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35d3ea53-6627-5ddb-95e7-4f2a590a195f",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-handler-proxy 4.1.73.Final-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83b2b845-4974-57bf-8fd3-0862b6a5a72c",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-29025 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c88f4428-c447-5ed5-a23e-d7a59dd9706f",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47535 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:296286be-b2f8-5bfb-965e-d4be13c4cbb3",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24970 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4478a6c-ebfb-52ab-b27b-f4049b78f8fa",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-25193 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19a16409-edd3-5b77-883e-004702defd40",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55163 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49bdf088-fd97-5e7d-bee6-438402580dfb",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58056 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f1d74a5-1433-5d08-9d0b-16f7628531c8",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58057 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:063d1a72-787b-5454-87b5-c02a8953ed5c",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59419 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e278c2c-a197-58ae-bcf9-cfe256597aee",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67735 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd4f9fb5-87bf-5ff5-b57a-38044a02402f",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:693802b5-af1f-50c9-bbad-51b29587544c",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36e1d9b4-d94b-559b-b204-1e1302102bde",
      "id": "CVE-2026-41417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41417 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17759029-3239-5539-b1e8-42c3b3f77af8",
      "id": "CVE-2026-42577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42577 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbc35263-e3ad-5aab-a83b-6615cf6bc55b",
      "id": "CVE-2026-42578",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42578 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9ed960d-d037-5771-a4e4-ac0596750260",
      "id": "CVE-2026-42579",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42579 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:091fc8ce-193a-5ba6-8326-18625b534e02",
      "id": "CVE-2026-42580",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42580 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91c16b20-6d58-5f46-add2-bac17f8f66d7",
      "id": "CVE-2026-42581",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42581 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:edf9dceb-377a-50c3-a4e4-275bfde61056",
      "id": "CVE-2026-42583",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42583 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e268f814-9dcc-5f88-a61b-3c7e275a837d",
      "id": "CVE-2026-42584",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42584 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:692932bb-029c-50a9-811a-83542ef4e378",
      "id": "CVE-2026-42585",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42585 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d67f1e6-b636-57a6-8f87-52c3407f7b14",
      "id": "CVE-2026-42586",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42586 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08841c4f-4894-5c9a-9b68-df6aa6f7ef22",
      "id": "CVE-2026-42587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42587 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46d9d374-a38a-56b1-a7ee-73d1180f1eec",
      "id": "CVE-2026-44248",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44248 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7bbe801-cfe8-5632-a5ed-615aa31836b9",
      "id": "CVE-2026-44249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44249 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91623ef0-1980-5542-a2fd-8d733c82a8c0",
      "id": "CVE-2026-44250",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44250 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f951316-e210-5ba8-8acf-e6375ca2b84f",
      "id": "CVE-2026-44890",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44890 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f118274f-5db2-5b80-a289-c594e7456d4c",
      "id": "CVE-2026-44891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44891 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a658d70-385e-5308-9685-ba7e83c6bf0f",
      "id": "CVE-2026-44893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44893 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20087164-eed8-54fc-af7b-d5789847636e",
      "id": "CVE-2026-45416",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45416 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a2f7652-5509-5635-adcb-87990cb7d3b5",
      "id": "CVE-2026-45536",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45536 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c006954-c1fc-5f79-af39-969b288014d5",
      "id": "CVE-2026-45673",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45673 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d8b222a-1f3a-5d5e-acc0-408bf9633497",
      "id": "CVE-2026-45674",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45674 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a59a7143-d79c-543a-9983-1ce3ada6e008",
      "id": "CVE-2026-46340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46340 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fef00d93-01a1-5a9f-b451-660a37532813",
      "id": "CVE-2026-47244",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47244 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80a2f216-de68-5aef-a354-d5df56262441",
      "id": "CVE-2026-47691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47691 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:995855d3-b04b-53c6-acb1-e8603c0c02fa",
      "id": "CVE-2026-48006",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48006 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fbc042b-c56b-502b-9def-6e5e30c77be3",
      "id": "CVE-2026-48043",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-48043 does not affect version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy. not_affected \u2014 Version 4.1.73 is not affected by CVE-2026-48043. The target uses a loop-based architecture with try-finally protection (introduced in 2016) that prevents the buffer leak described in the CVE. The vulnerable ChannelInboundHandlerAdapter pattern that the upstream patch fixes does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56b9a8e6-61bb-5b90-b1b9-f16432bbd26e",
      "id": "CVE-2026-48059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48059 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fedf171a-5145-5353-a2ae-3815d42b91c7",
      "id": "CVE-2026-50010",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50010 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6807ca42-78e6-5db8-aaef-7ad8e903c390",
      "id": "CVE-2026-50011",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50011 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c657823-dfda-5b75-a629-9f93fd6f8a8e",
      "id": "CVE-2026-50020",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50020 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bba37df5-3b59-50e6-881a-17d35cd6c684",
      "id": "CVE-2026-50560",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50560 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0dd0a1ad-b218-504b-9292-41e3ca17d462",
      "id": "CVE-2026-55831",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55831 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b3a9f37-42e1-5c36-8294-b3d2367a67b1",
      "id": "CVE-2026-55833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55833 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18b79b12-3e6d-568b-af58-583608354eea",
      "id": "CVE-2026-55851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55851 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b2bca9a-70ab-55d9-b94f-160100587b70",
      "id": "CVE-2026-56745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56745 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52877ede-73f3-535f-884a-7516ee3ab846",
      "id": "CVE-2026-56746",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56746 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7b653d4-f5df-591e-a611-6ae93aa2bcaa",
      "id": "CVE-2026-56817",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56817 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:416cbbd5-a9e7-5d51-b627-0eb09fd6ec3b",
      "id": "CVE-2026-56818",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56818 does not affect version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy. not_affected \u2014 The target version 4.1.73.Final-tuxcare.2 is NOT AFFECTED by CVE-2026-56818. The vulnerable code pattern (configurable `maxElements` limit check without cleanup, contrasting with `maxNestedArrayDepth` limit check WITH cleanup) was introduced in version 4.1.135.Final through commits e51c64c964 and 728c98b8ec (dated 2026-06-01/02). The target version predates these features entirely and does not ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3be2108-83cb-5bef-864f-fed4604e5a17",
      "id": "CVE-2026-56819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56819 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f83cf97-3e1f-5372-8ed4-a3a9236048f2",
      "id": "CVE-2026-59898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59898 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8db8f846-a072-539b-abd5-1c50857f1dfe",
      "id": "CVE-2026-59899",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59899 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1fab16fa-6910-53b8-bd90-41d16a535974",
      "id": "CVE-2026-59900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59900 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92faf567-3764-5df7-a997-56bd3e8ed90b",
      "id": "CVE-2026-59901",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59901 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f19c2c3-2861-5a07-a14d-248c4434db3d",
      "id": "CVE-2026-59919",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59919 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa734712-824b-538f-baed-0183366d23a7",
      "id": "CVE-2026-59920",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59920 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cdab11b3-34e9-59fd-878e-a17a74ded1da",
      "id": "CVE-2026-59921",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59921 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8e8fbb7-1f11-5cc7-b9fc-7c19c6b0f12d",
      "id": "GHSA-mfg7-5gfp-c4w3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mfg7-5gfp-c4w3 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:048129da-50f0-5b71-8d3e-49b147c7410a",
      "id": "GHSA-v74w-7mr3-4qg3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-v74w-7mr3-4qg3 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc9b0276-263d-53b7-8628-1ed38fcd686b",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.73.Final-tuxcare.3"
    }
  ]
}