{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e1f38aec-7946-57d6-9724-834cc2125057",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4",
      "type": "library",
      "group": "io.netty",
      "name": "netty-handler",
      "version": "4.1.75.Final-tuxcare.4",
      "purl": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:2b5e4355-a268-5d9f-a1f7-9a18fd39fdee",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24823 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ccb0e7a1-0770-5703-86b9-8cad9fe30248",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41881 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:243a6974-422c-55d3-adca-f5f371df832c",
      "id": "CVE-2022-41915",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-41915 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f8bc597-a79f-523c-885d-64be6bc79fd9",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34462 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:488dbf0a-defb-53f3-9b1d-b8f4c67fdae5",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3220f241-ecfe-5270-ba20-2ae34551362b",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-handler 4.1.75.Final-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94c8bbb7-74dd-5258-86ca-574ea2f5a425",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-29025 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c927d116-117c-536c-bcf1-f44371a86c97",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47535 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e277e1b0-7bfe-5d64-b38d-0d0c0137b494",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24970 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b06cc07b-13b8-5dcc-87ef-0495fd8ce25c",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-25193 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:190c1540-ec51-5701-8f54-4ee591b4bc1c",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55163 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94b8c574-2017-5699-a738-453f2bc51abc",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58056 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a47a6e54-28cb-58c2-8d9a-1d9c32eba7d8",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58057 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e11c5b25-a653-5bd3-a40a-fd16bfd9f09b",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59419 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a47e6eff-2799-5a60-8478-7335e8657afa",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67735 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a00b0cd3-533c-5f4a-94dd-02151ea3bbfe",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13493074-0f8b-55c1-994d-398f3d9f5445",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f577b753-16dc-528a-8df0-9b2fe308c1d8",
      "id": "CVE-2026-41417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41417 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4598b76-5af2-58b4-8609-a02f4c518de6",
      "id": "CVE-2026-42577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42577 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a07f03f-ab3e-50ae-ac9f-4939b30c355d",
      "id": "CVE-2026-42578",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42578 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aea8940d-3b64-5380-95fb-f5d986d4331e",
      "id": "CVE-2026-42579",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42579 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:744ec881-fca8-5bba-b855-cfbe831d6776",
      "id": "CVE-2026-42580",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42580 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:887ed8f0-5d66-5576-b6b0-34bff47cb17f",
      "id": "CVE-2026-42581",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42581 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:913382a4-2b18-50b8-aa20-40d8c070a749",
      "id": "CVE-2026-42583",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42583 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78d3d625-5057-50b6-9963-b3d4a732d513",
      "id": "CVE-2026-42584",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42584 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca8f228b-0e78-5a75-9c18-b02d8607351a",
      "id": "CVE-2026-42585",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42585 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd2a88a3-efca-5116-a31c-0eac099bef97",
      "id": "CVE-2026-42586",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42586 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd2b01c5-98f7-599a-b1d2-6507aba8702a",
      "id": "CVE-2026-42587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42587 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78d6f999-0b9a-5902-81e9-c811615bb910",
      "id": "CVE-2026-44248",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44248 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c2f0ca1-317a-55f3-87c3-58bee8998fe6",
      "id": "CVE-2026-44249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44249 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ecabcd96-a7b2-560b-814b-c63ab76b53de",
      "id": "CVE-2026-44250",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44250 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:992fe38e-7de7-56f8-9aa4-a6ba3d52009d",
      "id": "CVE-2026-44890",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44890 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3697e82b-42b0-5553-9579-ffcef33d0bd8",
      "id": "CVE-2026-44891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44891 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb70c4db-71a1-50ce-a134-80f4e56506ad",
      "id": "CVE-2026-44893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44893 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd36c64d-cacd-5613-9a0d-e56e6810ac4f",
      "id": "CVE-2026-45416",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45416 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4bde1bf-e0b1-5bb8-99db-6dc71a47b067",
      "id": "CVE-2026-45536",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45536 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97d8ef9c-4076-5734-8572-9fe4b102542c",
      "id": "CVE-2026-45673",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45673 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5679cdce-d5da-5983-b448-1d596a08d7b9",
      "id": "CVE-2026-45674",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45674 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af4ec57e-2045-575c-a6f9-cef2d2929069",
      "id": "CVE-2026-46340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46340 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13225c78-f85a-5331-988a-09a864c67688",
      "id": "CVE-2026-47244",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47244 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82b573d0-b672-5876-a414-c59c6d3cf710",
      "id": "CVE-2026-47691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47691 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11223de0-11e2-56b9-b608-261318a58a46",
      "id": "CVE-2026-48006",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48006 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2fdaa26-b40c-5f6f-aa94-568db60a26dd",
      "id": "CVE-2026-48043",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-48043 does not affect version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler. already_fixed \u2014 The target repository (Netty 4.1.75.Final-tuxcare.1) already contains equivalent protection against CVE-2026-48043. While the upstream patch targets a newer architecture with a ChannelInboundHandlerAdapter tail handler (introduced in CVE-2025-58057 refactoring), the target's older architecture implements the same defensive pattern: a try-finally block ensuring ByteBuf.release() is called uncond..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e9553d0-4084-5546-b5ce-cd45282a5f74",
      "id": "CVE-2026-48059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48059 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40c84dc8-8d72-5225-9770-b258c9c76313",
      "id": "CVE-2026-50010",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50010 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ce4ee75-799c-58bc-b6ed-58ad9eee464b",
      "id": "CVE-2026-50011",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50011 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:838ca13d-abe1-55d6-94b6-92551f5aecee",
      "id": "CVE-2026-50020",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50020 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dff55903-5676-54be-8841-b952dbe8dd90",
      "id": "CVE-2026-50560",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50560 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9db48c0f-301a-5c6f-930e-a1e6f30fe44f",
      "id": "CVE-2026-55831",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55831 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70f0272c-8f77-5054-b114-7e22d61707e9",
      "id": "CVE-2026-55833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55833 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fa8f2cc-21bf-578a-83df-197f3ffadecb",
      "id": "CVE-2026-55851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55851 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06c9b594-e2a8-57ce-af18-22c05b5303dc",
      "id": "CVE-2026-56745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56745 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50fa036e-2b6a-5408-bf0e-cbd07429b0b0",
      "id": "CVE-2026-56746",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56746 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a76f493-50a4-5979-8ba0-45449292a51c",
      "id": "CVE-2026-56817",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56817 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1badc600-2d86-55fb-afbb-57912c6e6098",
      "id": "CVE-2026-56818",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56818 does not affect version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler. not_affected \u2014 The target version 4.1.75.Final (released March 2022) predates the introduction of the vulnerable feature by over 4 years. CVE-2026-56818 describes incomplete cleanup when the `maxElements` limit is exceeded in RedisArrayAggregator. However, the `maxElements` configuration parameter and associated exception handling were introduced in June 2026 (commits e51c64c964 and 728c98b8ec), neither of wh..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f105f27-b4be-505f-b3f7-65619dd7861f",
      "id": "CVE-2026-56819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56819 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a1421f7-fc88-5ef4-8153-6e9b265e9e5c",
      "id": "CVE-2026-59898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59898 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe418def-54ff-588e-81d3-5cbd0607fe85",
      "id": "CVE-2026-59899",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59899 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89231dbd-6309-59f0-9e4c-fcb6ba232b4c",
      "id": "CVE-2026-59900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59900 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f230d719-6ee0-5ff8-94b2-354d7f8c7f0a",
      "id": "CVE-2026-59901",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59901 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f4c92b6-4146-5cf3-aa89-327baa358bbb",
      "id": "CVE-2026-59919",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59919 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4461fd50-988b-58e6-b930-6a3738d539c6",
      "id": "CVE-2026-59920",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59920 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2673e1d0-666a-5de4-8988-e7d52b37a6f9",
      "id": "CVE-2026-59921",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59921 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89c844e3-9cee-5bcc-86a1-8e7bb60a0045",
      "id": "GHSA-mfg7-5gfp-c4w3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mfg7-5gfp-c4w3 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58338b51-4317-5511-9468-21a860853705",
      "id": "GHSA-v74w-7mr3-4qg3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-v74w-7mr3-4qg3 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:485c66d1-451a-5ec2-ab32-8ddbb1a776ab",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-handler@4.1.75.Final-tuxcare.4"
    }
  ]
}