{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a0e4d9d8-1e63-5581-8b8b-adce1016b377",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4",
      "type": "library",
      "group": "io.netty",
      "name": "netty-handler-proxy",
      "version": "4.1.75.Final-tuxcare.4",
      "purl": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:d529bc03-8ca6-5043-aa80-bdc3cd288e42",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24823 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ed5af20-1dc5-5446-9818-aa55b544e4a6",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41881 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c1751ed-162a-5096-9934-768758e85ae0",
      "id": "CVE-2022-41915",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-41915 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83f27cc7-4243-52a6-b91c-3d1d6e539910",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34462 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c47b41dc-3484-5378-8f61-1781927b7091",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bbeaeb2-b249-55c7-8667-f0f125e121a2",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-handler-proxy 4.1.75.Final-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6b36a77-7103-5308-963e-80b5df72022e",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-29025 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bd4f8b3-dd88-5130-a0d3-e486397b4aeb",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47535 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ae05f46-f728-5005-86f1-948b4c083cbc",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24970 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2441b45-3a05-5267-b970-2f3faa2499d0",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-25193 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:819b112c-060e-5f4d-bebe-e60e9fabd4c3",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55163 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04ee9ff3-8ab3-5f77-aea2-1cf0512323d8",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58056 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:714539d1-f933-5f1d-904c-56b7840ddada",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58057 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2abc3fd3-94e9-5e1b-bec4-f934db37d1a8",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59419 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e2ee935-057c-54ad-8c97-22f07f591e79",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67735 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc09cb8a-ad2b-5352-a0a6-2f155c714cbc",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46952185-d721-5727-97fd-debab23511ea",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71da0af6-6dea-5ad1-9f8f-79fec4a15161",
      "id": "CVE-2026-41417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41417 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b86a882-fe03-5b75-875f-92fad383cdf3",
      "id": "CVE-2026-42577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42577 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca014a25-4247-5985-be3c-c94e810fb0dd",
      "id": "CVE-2026-42578",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42578 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00020821-c48b-5f91-b33a-28a8b4f8a711",
      "id": "CVE-2026-42579",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42579 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bec5b39b-b76e-5f4f-be12-704bdb45dc20",
      "id": "CVE-2026-42580",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42580 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47215baa-417b-551e-8c1b-3bea3b269365",
      "id": "CVE-2026-42581",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42581 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:643aeea2-51b4-5793-beb0-3cfe4dc0bf74",
      "id": "CVE-2026-42583",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42583 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29a6109b-97e3-579e-8666-3ade393bc2c7",
      "id": "CVE-2026-42584",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42584 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c50c4fe9-2bc9-5f6c-9d87-b1755b3b107b",
      "id": "CVE-2026-42585",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42585 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4da8a9f7-4dfc-5f67-bc35-607df939e952",
      "id": "CVE-2026-42586",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42586 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c74968d4-2491-58d0-9503-978767487e3f",
      "id": "CVE-2026-42587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42587 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46a939eb-4a18-5104-a04f-37ceeac17f33",
      "id": "CVE-2026-44248",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44248 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9dafaf9c-2e6b-557a-8946-672f8ba611ef",
      "id": "CVE-2026-44249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44249 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d0684eb-0fc0-57f2-ad44-3267c867d8e9",
      "id": "CVE-2026-44250",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44250 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9159c947-0606-534a-9230-241c698f41a3",
      "id": "CVE-2026-44890",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44890 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1dc4388-f82a-5e2e-8ac0-eefa8b56c7a5",
      "id": "CVE-2026-44891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44891 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:119836c5-83bc-59e9-99ab-e8c86e43ed6d",
      "id": "CVE-2026-44893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44893 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b18ae332-2960-5208-8a06-8377f4130cef",
      "id": "CVE-2026-45416",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45416 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26112405-f970-563c-aa09-b2e323f71add",
      "id": "CVE-2026-45536",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45536 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbd08768-6cb9-566d-9d2d-39c1b50f578a",
      "id": "CVE-2026-45673",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45673 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8e688ac-b5e0-5454-9e94-1c83c03bcece",
      "id": "CVE-2026-45674",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45674 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afd070df-a131-52cc-b7cb-7bffc2a09ff1",
      "id": "CVE-2026-46340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46340 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e0791ec-4b11-54d5-98e8-2a578e4512cf",
      "id": "CVE-2026-47244",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47244 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6344946f-07fc-59f0-a1de-0ab84ac2bc12",
      "id": "CVE-2026-47691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47691 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2320868e-4cd3-574a-b36e-78836d6ad2c2",
      "id": "CVE-2026-48006",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48006 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fc54bbf-18d4-587c-a8f4-ad4656ea0520",
      "id": "CVE-2026-48043",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-48043 does not affect version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy. already_fixed \u2014 The target repository (Netty 4.1.75.Final-tuxcare.1) already contains equivalent protection against CVE-2026-48043. While the upstream patch targets a newer architecture with a ChannelInboundHandlerAdapter tail handler (introduced in CVE-2025-58057 refactoring), the target's older architecture implements the same defensive pattern: a try-finally block ensuring ByteBuf.release() is called uncond..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe4982cb-5c10-5969-80c3-ea475f7f1429",
      "id": "CVE-2026-48059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48059 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe6f7e30-6918-5d65-93e3-5c8e5fb8f9d7",
      "id": "CVE-2026-50010",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50010 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5782858-91a8-5194-a827-0d8d5058a6be",
      "id": "CVE-2026-50011",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50011 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2f5d411-2a62-53f5-bdc0-0420b915e186",
      "id": "CVE-2026-50020",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50020 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b361156-c180-589b-956b-5595a37b9fe2",
      "id": "CVE-2026-50560",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50560 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfde490c-5e72-5428-ba95-05d1a37936fa",
      "id": "CVE-2026-55831",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55831 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c495f0b-cf61-592a-9fdf-68069e3ba479",
      "id": "CVE-2026-55833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55833 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0732b36-b82f-5a5f-869c-705e660e8106",
      "id": "CVE-2026-55851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55851 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c98bd819-49f2-5d3d-87e9-43a472ef4762",
      "id": "CVE-2026-56745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56745 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3837fcf5-5188-5ce6-b71e-af17b0b7227b",
      "id": "CVE-2026-56746",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56746 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0cb21c73-6e72-545f-9971-3733cc59691b",
      "id": "CVE-2026-56817",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56817 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e103c909-bfb7-546c-93b0-6e524645c1f1",
      "id": "CVE-2026-56818",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56818 does not affect version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy. not_affected \u2014 The target version 4.1.75.Final (released March 2022) predates the introduction of the vulnerable feature by over 4 years. CVE-2026-56818 describes incomplete cleanup when the `maxElements` limit is exceeded in RedisArrayAggregator. However, the `maxElements` configuration parameter and associated exception handling were introduced in June 2026 (commits e51c64c964 and 728c98b8ec), neither of wh..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9160845-4118-5ea5-961e-f079b9b23ba8",
      "id": "CVE-2026-56819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56819 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b85b0e92-2387-5ecb-9259-2ccc5e44194c",
      "id": "CVE-2026-59898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59898 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:202efd0e-e6c0-538a-b908-59c26b0ac287",
      "id": "CVE-2026-59899",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59899 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3447d3ff-e1a9-5720-b3fc-79262c6d66d0",
      "id": "CVE-2026-59900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59900 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6226c8cc-13bb-5f88-a5cb-f0ac35953e8a",
      "id": "CVE-2026-59901",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59901 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92554fc0-3b27-5f54-994d-fa2d57f6a0cb",
      "id": "CVE-2026-59919",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59919 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c215f76-735f-5231-bb52-310aa7ee911c",
      "id": "CVE-2026-59920",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59920 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95ce0644-6540-5b4e-83e2-f3e437c4e284",
      "id": "CVE-2026-59921",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59921 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7282c21e-ace7-51ab-b2eb-e91bf2d8f3fe",
      "id": "GHSA-mfg7-5gfp-c4w3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mfg7-5gfp-c4w3 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2057b0a2-327e-559a-a658-ad2f6c68932a",
      "id": "GHSA-v74w-7mr3-4qg3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-v74w-7mr3-4qg3 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e43b08f-bed9-5c39-a311-aabc8e8ac47b",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler-proxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-handler-proxy@4.1.75.Final-tuxcare.4"
    }
  ]
}