{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4a4916b2-b211-587a-aa88-f27ed27c18e1",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3",
      "type": "library",
      "group": "io.netty",
      "name": "netty-handler",
      "version": "4.1.73.Final-tuxcare.3",
      "purl": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:0ade6c78-b17a-5364-9cc4-190b2382db86",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24823 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7cb45b45-835a-502c-bed6-76e60d91750c",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41881 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69f5cc0e-8c24-5958-ad55-b768706b159e",
      "id": "CVE-2022-41915",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-41915 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:386598b2-2dda-5b73-90f1-58629004d129",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-34462 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78648c91-b301-5395-8100-6b41553712b4",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2168f88d-cebc-5cef-a407-172ccf25a5e6",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-handler 4.1.73.Final-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f277a0a-cad8-5c14-af23-c629ddf369b9",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-29025 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee76ce52-1ccf-5c07-b314-00957d9f34a0",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47535 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f9a54f1-a03d-59cb-a1a2-3eaa7697f243",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24970 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ca51879-5ef5-5276-ae3c-e3aa5156db23",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-25193 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb60391a-bda5-58e2-b5ea-9b6aa29956af",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55163 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1133c094-0ff7-57e6-b07b-458809fc3036",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58056 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e73ab174-9b25-507c-91c5-42e505778cfa",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58057 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8329797-ee4a-56d3-a06f-d3e15cc6bff8",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59419 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed091752-3b49-57c6-b278-dc38cc2c774a",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67735 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c5332df-431e-59ad-b762-d3586c75a30b",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4d8cc93-cce4-55a1-961b-8254c21267fa",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad338896-7ef2-5923-83a6-af7143d043ff",
      "id": "CVE-2026-41417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41417 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c27932ac-2908-54a4-8851-072386e17659",
      "id": "CVE-2026-42577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42577 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef6fd8b9-dcf7-5495-ac06-37e210df7f3a",
      "id": "CVE-2026-42578",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42578 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb3bf9ca-7b04-575e-b105-bf9694f85d9d",
      "id": "CVE-2026-42579",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42579 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7299c188-f74a-58c6-96f7-c6956e33de8d",
      "id": "CVE-2026-42580",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42580 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ea14417-5aea-53d1-ad80-08b0bd4c8fbc",
      "id": "CVE-2026-42581",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42581 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9a2d899-20de-5ed6-9f47-c403f40317ac",
      "id": "CVE-2026-42583",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42583 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef8144c2-02fd-5666-bc66-460556ec87df",
      "id": "CVE-2026-42584",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42584 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4313528-c0ff-5f84-be88-12d5010604b4",
      "id": "CVE-2026-42585",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42585 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:600c9106-7317-55db-af72-617bc6466b9d",
      "id": "CVE-2026-42586",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42586 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f96cfad-c287-5dc3-ac56-22b2cf714ef6",
      "id": "CVE-2026-42587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42587 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1d7afd8-6bf8-518a-b093-eb59c5bbc22d",
      "id": "CVE-2026-44248",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44248 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53d69de3-2fff-50d3-af16-2e8d265b9916",
      "id": "CVE-2026-44249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44249 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c08d7f6-a4b1-5581-8c17-dfd3264f75a0",
      "id": "CVE-2026-44250",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44250 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99d2a8d1-767c-57e3-8862-03c73c792dc5",
      "id": "CVE-2026-44890",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44890 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1a1be0b-06e9-5f6a-acca-e9d2015af253",
      "id": "CVE-2026-44891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44891 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a702f0d4-193a-5dcd-88a9-53966de22059",
      "id": "CVE-2026-44893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44893 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:482ed2e9-ff31-5412-83db-02b9b444ac8d",
      "id": "CVE-2026-45416",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45416 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:916c4c51-885a-55db-b9d6-5d8f5a7e2207",
      "id": "CVE-2026-45536",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45536 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f243717-0014-57f8-b465-6bd1a7814026",
      "id": "CVE-2026-45673",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45673 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08fe6375-0e21-5da2-b3e6-41c0f6789804",
      "id": "CVE-2026-45674",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45674 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:757c5279-42dc-5208-ae37-8a54c557ed3b",
      "id": "CVE-2026-46340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46340 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92dc68a6-3a45-52a1-a002-b271455733b5",
      "id": "CVE-2026-47244",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47244 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:beba1faf-4267-5cc3-a630-591ea43d6775",
      "id": "CVE-2026-47691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47691 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27328947-2e6f-58e9-ad80-9636ece27f7e",
      "id": "CVE-2026-48006",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48006 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bce1fab4-1115-5ee7-be58-49a52904e490",
      "id": "CVE-2026-48043",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-48043 does not affect version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler. not_affected \u2014 Version 4.1.73 is not affected by CVE-2026-48043. The target uses a loop-based architecture with try-finally protection (introduced in 2016) that prevents the buffer leak described in the CVE. The vulnerable ChannelInboundHandlerAdapter pattern that the upstream patch fixes does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4e343d1-bc5f-5a38-aa99-7ad9e8e21817",
      "id": "CVE-2026-48059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48059 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4b31d65-d49e-5dd2-9455-832cba2a63d3",
      "id": "CVE-2026-50010",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50010 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c1c0185-afc4-5853-922e-bc43e972aeea",
      "id": "CVE-2026-50011",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50011 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0627ef7b-cb92-5ef9-9ea3-7b2bad4ef6a0",
      "id": "CVE-2026-50020",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50020 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf6ec319-ebd9-5db4-be28-74c149de37dc",
      "id": "CVE-2026-50560",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50560 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4bd95377-a70f-5519-b042-28f0465fe063",
      "id": "CVE-2026-55831",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55831 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:526a8a36-d22e-5e39-80ba-680924bcf86a",
      "id": "CVE-2026-55833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55833 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:034b0fbf-fdb9-557a-ac2b-eaa6beea6b41",
      "id": "CVE-2026-55851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55851 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc7bf084-0170-5d28-9692-2c39a599977a",
      "id": "CVE-2026-56745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56745 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4871f354-d565-5bf7-aaf2-95e42a6a38ba",
      "id": "CVE-2026-56746",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56746 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff72e02b-4994-5d90-a665-7bc597fbf04c",
      "id": "CVE-2026-56817",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56817 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db902d87-ea01-562f-991a-9aa564964916",
      "id": "CVE-2026-56818",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56818 does not affect version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler. not_affected \u2014 The target version 4.1.73.Final-tuxcare.2 is NOT AFFECTED by CVE-2026-56818. The vulnerable code pattern (configurable `maxElements` limit check without cleanup, contrasting with `maxNestedArrayDepth` limit check WITH cleanup) was introduced in version 4.1.135.Final through commits e51c64c964 and 728c98b8ec (dated 2026-06-01/02). The target version predates these features entirely and does not ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:027822d2-dc8a-5f30-bac1-f1b733c8f135",
      "id": "CVE-2026-56819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56819 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81361557-2f95-5b4c-a057-1c300f350747",
      "id": "CVE-2026-59898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59898 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8f8080f-1cef-56fb-8170-8189d0d6c9b4",
      "id": "CVE-2026-59899",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59899 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86249d8b-8f85-55d9-a1eb-404b84ac29ea",
      "id": "CVE-2026-59900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59900 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b34fe65-43f7-57f2-8e26-93a67c0f4297",
      "id": "CVE-2026-59901",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59901 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f0bde5e-046d-5564-b827-e63a08c88d7a",
      "id": "CVE-2026-59919",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59919 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e6b162c-66ba-5dbb-8184-304be8f43988",
      "id": "CVE-2026-59920",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59920 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a085df24-00ea-5bde-85a0-98b8626abdf8",
      "id": "CVE-2026-59921",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59921 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00ed991f-1c04-5b1b-b256-524dd512aab3",
      "id": "CVE-2026-73507",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-73507 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd0b936c-dd98-552f-bb6c-4cab97f57d2a",
      "id": "CVE-2026-73508",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-73508 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39d6cbf9-52ae-5526-a8f0-93f323b3a42c",
      "id": "GHSA-mfg7-5gfp-c4w3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mfg7-5gfp-c4w3 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bacf2146-bab3-5594-82f4-189ae3f39237",
      "id": "GHSA-v74w-7mr3-4qg3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-v74w-7mr3-4qg3 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69b1dae6-5d87-5882-848d-e4a5753013d1",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-handler@4.1.73.Final-tuxcare.3"
    }
  ]
}