{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:2004b309-4665-58f9-bd1c-f9670c377080",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3",
      "type": "library",
      "group": "io.netty",
      "name": "netty-testsuite-http2",
      "version": "4.1.73.Final-tuxcare.3",
      "purl": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:4c36467e-7033-5d21-8b33-411f20aab71b",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24823 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d30281bb-3002-5a3d-ad1e-fba63d35f28e",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41881 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9dc42eef-5e7e-5273-ab1c-3acfb4a88175",
      "id": "CVE-2022-41915",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-41915 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d433fe9b-1c22-5f10-b86a-ec668017c4b7",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-34462 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95449290-cdbc-5a44-8aa4-95e7626c8a00",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93f8cb0c-eb31-5b64-9b29-350667e7e1b5",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-testsuite-http2 4.1.73.Final-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78e3e325-4f88-55f2-8520-03760fb0f597",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-29025 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a74b415-3ca1-54e9-aeee-0b3fb7191a85",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47535 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d67de338-1d12-5e53-a7e8-a6ddd32044c0",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24970 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90e04dc1-1f6c-55a2-81f1-ca6e1f88417d",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-25193 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04ff9ec8-89e6-57df-b364-ac4e1d387588",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55163 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3078aeee-a4ed-5e50-8212-d023c7638443",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58056 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:862be64f-70a4-5dee-9bdb-eb2051b23159",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58057 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e654662-e35a-5a9a-ac59-67ff9dfc572c",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59419 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c91752d-551e-58f5-aad7-41e8c7e764d4",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67735 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c2086ee-2b7a-5d60-b84b-dff270ea79e4",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33f34184-1423-5df4-bccf-9f97ef0bd72b",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6816d698-33fd-580f-9949-5bbc8a377986",
      "id": "CVE-2026-41417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41417 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98befc3f-bff5-5172-93f9-992ce74b0bc0",
      "id": "CVE-2026-42577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42577 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2617955-ce16-53e4-bc91-351970486607",
      "id": "CVE-2026-42578",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42578 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7cb90099-1012-50ec-ad03-7e513783b202",
      "id": "CVE-2026-42579",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42579 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27bff1c6-d90a-5b4d-883b-4e60495315dd",
      "id": "CVE-2026-42580",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42580 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36ecdcc6-fe4c-5729-8440-3d119f3f5180",
      "id": "CVE-2026-42581",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42581 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58518bb1-70d7-5d1f-9c69-603b35f692d6",
      "id": "CVE-2026-42583",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42583 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9afe0fa-0a8e-5f6d-9a71-cd09c287ffde",
      "id": "CVE-2026-42584",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42584 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e92e54ff-c8c0-530f-a3b5-2f18a040cabe",
      "id": "CVE-2026-42585",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42585 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25cd0b02-c971-5f6a-beae-c83a03017f14",
      "id": "CVE-2026-42586",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42586 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74c01a8b-f342-5574-b74a-fc161bac21ed",
      "id": "CVE-2026-42587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42587 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e6789b6-e2d3-5f05-9891-f7d2bd32a424",
      "id": "CVE-2026-44248",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44248 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd82d8cb-5a98-53b8-9985-eb308d2170fb",
      "id": "CVE-2026-44249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44249 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7971e377-4c88-5129-bc0f-3e55814719b6",
      "id": "CVE-2026-44250",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44250 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f265d54d-8ff3-59d8-80d6-07e82d1f6a84",
      "id": "CVE-2026-44890",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44890 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34d001fc-d6db-59d8-a612-39e558f1d71d",
      "id": "CVE-2026-44891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44891 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8c9574c-3c4c-5f85-b585-4bb452ff0831",
      "id": "CVE-2026-44893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44893 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df25cf73-880c-5dce-866f-9ebf972f3968",
      "id": "CVE-2026-45416",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45416 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd53ca86-fb7c-5774-ae8b-d889ab35bd22",
      "id": "CVE-2026-45536",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45536 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5f2a7f2-9fa3-5aff-988f-d9b71d7cea42",
      "id": "CVE-2026-45673",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45673 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21907f28-b2d9-5d10-b957-10fe9c364f9e",
      "id": "CVE-2026-45674",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45674 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33a28fe8-b826-5e94-92ed-e1ba18608f52",
      "id": "CVE-2026-46340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46340 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f1631f5-c9d2-5660-bfc1-e865bdf63fdb",
      "id": "CVE-2026-47244",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47244 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:666431e5-84e6-587c-8d97-dd387a51017e",
      "id": "CVE-2026-47691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47691 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3742b78b-271d-55a6-9af2-68c91720ded6",
      "id": "CVE-2026-48006",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48006 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcc6368e-7f04-5846-900c-fffbce6951d6",
      "id": "CVE-2026-48043",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-48043 does not affect version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2. not_affected \u2014 Version 4.1.73 is not affected by CVE-2026-48043. The target uses a loop-based architecture with try-finally protection (introduced in 2016) that prevents the buffer leak described in the CVE. The vulnerable ChannelInboundHandlerAdapter pattern that the upstream patch fixes does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df48c084-5a55-5878-b419-098ee64993ab",
      "id": "CVE-2026-48059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48059 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53734fdd-1559-5ac3-a99f-b178f531b332",
      "id": "CVE-2026-50010",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50010 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31748fea-4165-5cd2-99af-91974dabfb42",
      "id": "CVE-2026-50011",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50011 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e050baf-9ed6-5e7c-9ff4-59dec693c209",
      "id": "CVE-2026-50020",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50020 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b324d9ba-690f-5ed5-aba1-df44276b094b",
      "id": "CVE-2026-50560",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50560 is fixed in version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2128b9d9-8591-5d15-97a5-930c09a29a0f",
      "id": "CVE-2026-55831",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55831 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:192c7af0-19a6-596e-b463-a35a8f5a64b8",
      "id": "CVE-2026-55833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55833 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:885fcd7e-3cbb-5107-bca8-469249d89ed6",
      "id": "CVE-2026-55851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55851 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5cfea14f-58a6-5859-8668-6c85c4d9918c",
      "id": "CVE-2026-56745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56745 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c41e6f0e-b87e-5674-996e-d43d3efa6e49",
      "id": "CVE-2026-56746",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56746 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60be8a2d-1c5c-5135-96cf-d6c7c6649528",
      "id": "CVE-2026-56817",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56817 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a34ea6b6-94f0-5b14-97ea-01fd431e8b43",
      "id": "CVE-2026-56818",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56818 does not affect version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2. not_affected \u2014 The target version 4.1.73.Final-tuxcare.2 is NOT AFFECTED by CVE-2026-56818. The vulnerable code pattern (configurable `maxElements` limit check without cleanup, contrasting with `maxNestedArrayDepth` limit check WITH cleanup) was introduced in version 4.1.135.Final through commits e51c64c964 and 728c98b8ec (dated 2026-06-01/02). The target version predates these features entirely and does not ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb476d0e-9b72-54c7-8e5a-a18b4c6d0372",
      "id": "CVE-2026-56819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56819 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d7dc4d7-5203-5a30-893f-070ec82838dc",
      "id": "CVE-2026-59898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59898 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17d8c1d9-6ca7-5ccb-9c30-54b5b90a13df",
      "id": "CVE-2026-59899",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59899 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3dd2e24-0d66-5bf1-8c03-7427fad45cdf",
      "id": "CVE-2026-59900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59900 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3f45240-11b0-5ebd-b65c-f13ad07f914a",
      "id": "CVE-2026-59901",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59901 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f2f3178-f755-566b-84ca-898b32970fca",
      "id": "CVE-2026-59919",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59919 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60ba7991-297e-57ab-ad80-e410245108d6",
      "id": "CVE-2026-59920",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59920 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61c0cdf1-546f-5437-b5dc-aeeb535a7af2",
      "id": "CVE-2026-59921",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59921 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:956b7333-b6cd-529e-b2e3-a267cd81fac0",
      "id": "CVE-2026-73507",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-73507 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43988c20-03df-5f76-8177-c49b83659890",
      "id": "CVE-2026-73508",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-73508 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0acfc96f-2c6c-5972-be0a-ae72bd16767f",
      "id": "GHSA-mfg7-5gfp-c4w3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mfg7-5gfp-c4w3 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d049fe1-79fd-5c31-b181-ed23eeab7bc5",
      "id": "GHSA-v74w-7mr3-4qg3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-v74w-7mr3-4qg3 affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32d92bbc-fa02-59d1-a7dc-f35aeb373f9b",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p affects version 4.1.73.Final-tuxcare.3 of io.netty:netty-testsuite-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-testsuite-http2@4.1.73.Final-tuxcare.3"
    }
  ]
}