{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:91c3c647-5e57-5466-bc33-19423609e2bf",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4",
      "type": "library",
      "group": "io.netty",
      "name": "netty-testsuite-osgi",
      "version": "4.1.75.Final-tuxcare.4",
      "purl": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:163497bd-4f03-58ab-9b35-30b2b9d2d461",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24823 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8cbad96-f2e9-5ec7-896c-ed95f8db50ad",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41881 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf6097d5-808e-594e-bc1b-8df6897659b7",
      "id": "CVE-2022-41915",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-41915 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83a4fcdb-43b9-5953-9522-46129c6961ed",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34462 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:343ecf54-379e-5d74-834b-6a64cdfff1a0",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb95c16c-8e05-5630-88fe-ab07e2d128e3",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-testsuite-osgi 4.1.75.Final-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94bbf696-0f6d-5528-b25f-66c696eeb67f",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-29025 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a95d6e2b-c105-5c98-ace5-868222c34995",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47535 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a85fa9e7-555b-54f0-b150-16112b390960",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24970 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef458886-49a8-5e76-9c01-39bdbfc249cd",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-25193 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ecbb80a-1fa1-5e80-93d8-a047116e42dc",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55163 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c16d103a-8a16-52da-aa44-c12cecfe7f6d",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58056 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:035cc7bc-67e5-50f9-9e68-06d60e46070a",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58057 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ab0aace-da7d-53f4-8b7f-c9728f515c2f",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59419 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:584b0cb4-8827-56f4-8149-24b9c0ba8664",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67735 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d8a5a2d-6110-57a3-a16f-9846b1671860",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:080cc74a-1de2-591a-80a8-a4b9ebbc7120",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4ac1b09-2a59-5ea5-8ed5-e6cc14e4a796",
      "id": "CVE-2026-41417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41417 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:535eda63-161f-5c88-a4f8-d573b3e9a733",
      "id": "CVE-2026-42577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42577 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c08e650-2dc0-55ab-b9c2-e0ab6dd5feb4",
      "id": "CVE-2026-42578",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42578 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d34d2fe-e92f-5cce-a19f-5e4b8d658ca5",
      "id": "CVE-2026-42579",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42579 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3b4cdda-7cf4-57d3-bdcc-7097ef0e675a",
      "id": "CVE-2026-42580",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42580 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a96458e4-85bb-5150-9701-8409907ffcf9",
      "id": "CVE-2026-42581",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42581 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b80c2325-b54f-5e25-aff0-cfc2e2c0679e",
      "id": "CVE-2026-42583",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42583 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:285691cc-d14b-5d34-8cfa-9137e2db81c2",
      "id": "CVE-2026-42584",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42584 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ce3c138-1779-5de3-b9b1-c609cd16136d",
      "id": "CVE-2026-42585",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42585 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a148c5df-cb16-584f-bdb1-b9bec94be8c2",
      "id": "CVE-2026-42586",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42586 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b9c0be6-5cbc-53d2-a531-bea1dc7e6d3e",
      "id": "CVE-2026-42587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42587 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71c52df6-3a6e-56c3-8796-97748b333c98",
      "id": "CVE-2026-44248",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44248 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13265df6-4a27-507f-ac45-bafb4750edd8",
      "id": "CVE-2026-44249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44249 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f089156f-6573-51c8-89a2-18ace64b4033",
      "id": "CVE-2026-44250",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44250 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9066a2b1-5c43-571a-b647-779cac9f8200",
      "id": "CVE-2026-44890",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44890 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c892a44-1f32-564c-ad5a-5cec37a377d5",
      "id": "CVE-2026-44891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44891 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbb348bd-57d4-54ec-b16d-640ea1267aec",
      "id": "CVE-2026-44893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44893 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5f5d18e-4ba3-5e79-abca-742bfb3a7dc1",
      "id": "CVE-2026-45416",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45416 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aee70709-2088-5154-927a-c46a85c15368",
      "id": "CVE-2026-45536",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45536 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b276fadc-fdc5-5f66-a8f9-22b5f2ca8d3c",
      "id": "CVE-2026-45673",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45673 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fafff162-3c88-55e2-b95d-46d5fe68ad8f",
      "id": "CVE-2026-45674",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45674 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d42c3097-6ac4-5f80-98fe-17b291d10992",
      "id": "CVE-2026-46340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46340 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b18213ca-31f3-5123-b3ae-b1e3cde81b51",
      "id": "CVE-2026-47244",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47244 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11ec6115-923d-5702-abfd-45e3ef0d587f",
      "id": "CVE-2026-47691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47691 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11c04df3-c9d4-5a6a-8f9c-671e5d253fd5",
      "id": "CVE-2026-48006",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48006 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13d0037b-3722-5c1f-ba2a-74e58457b3a5",
      "id": "CVE-2026-48043",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-48043 does not affect version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi. already_fixed \u2014 The target repository (Netty 4.1.75.Final-tuxcare.1) already contains equivalent protection against CVE-2026-48043. While the upstream patch targets a newer architecture with a ChannelInboundHandlerAdapter tail handler (introduced in CVE-2025-58057 refactoring), the target's older architecture implements the same defensive pattern: a try-finally block ensuring ByteBuf.release() is called uncond..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:613b9248-09b4-5c6f-a494-9fb572159db8",
      "id": "CVE-2026-48059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48059 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1338493f-1575-5e22-97a7-ebe20cca0778",
      "id": "CVE-2026-50010",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50010 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a5556a7-f289-5575-ab19-e772f76ae2e7",
      "id": "CVE-2026-50011",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50011 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d30135b0-f9a9-569f-9b10-2de66633f0ee",
      "id": "CVE-2026-50020",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50020 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61419212-ba67-5e53-9937-9777da7fdaa0",
      "id": "CVE-2026-50560",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50560 is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fea414ae-3c88-586f-9b7d-d6596c968289",
      "id": "CVE-2026-55831",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55831 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:602a5d91-5ebd-5616-9c63-be57f6656d03",
      "id": "CVE-2026-55833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55833 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7313dce7-f7b5-5e9d-ad04-c2921e85defc",
      "id": "CVE-2026-55851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55851 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6125eea0-3dbd-5c17-8bf7-71823b104aa4",
      "id": "CVE-2026-56745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56745 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32336b16-1bb5-58c7-a798-00e77b2b84d8",
      "id": "CVE-2026-56746",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56746 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24cef365-32cb-5e8a-892c-e19abd31c7ff",
      "id": "CVE-2026-56817",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56817 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df0c42c7-fa34-5182-b89c-9fe93e22b35a",
      "id": "CVE-2026-56818",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56818 does not affect version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi. not_affected \u2014 The target version 4.1.75.Final (released March 2022) predates the introduction of the vulnerable feature by over 4 years. CVE-2026-56818 describes incomplete cleanup when the `maxElements` limit is exceeded in RedisArrayAggregator. However, the `maxElements` configuration parameter and associated exception handling were introduced in June 2026 (commits e51c64c964 and 728c98b8ec), neither of wh..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9ba2e5d-faf2-53f2-b6fe-4343e49f397b",
      "id": "CVE-2026-56819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56819 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14ffe8d3-fd4f-5e68-8ad2-f9492baef0d0",
      "id": "CVE-2026-59898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59898 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a050ec28-76df-5adc-a889-bdc69582ce95",
      "id": "CVE-2026-59899",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59899 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f54c6f35-9354-55c9-9fa9-c17f7388fb74",
      "id": "CVE-2026-59900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59900 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d395697b-453b-5b2e-b837-514ef3831ac9",
      "id": "CVE-2026-59901",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59901 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0e8b101-4f34-5b1c-9593-1fd558705e3f",
      "id": "CVE-2026-59919",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59919 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4882eb7-3365-582c-86e9-e59a249854f2",
      "id": "CVE-2026-59920",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59920 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7049e663-2073-5a06-b66d-5cb8611cb507",
      "id": "CVE-2026-59921",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59921 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:954e1792-2227-5f4f-8e3d-1ac3d3ac147c",
      "id": "CVE-2026-73507",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-73507 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63f57d01-0210-56bb-b56b-2411d998bbfd",
      "id": "CVE-2026-73508",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-73508 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ede33a4-c652-567a-8168-82b7bc188e4a",
      "id": "GHSA-mfg7-5gfp-c4w3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mfg7-5gfp-c4w3 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:537f44a7-d7fd-5799-b7f3-a5fd9bd3693a",
      "id": "GHSA-v74w-7mr3-4qg3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-v74w-7mr3-4qg3 affects version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72ababf1-053c-5612-b42e-668afb9fe573",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p is fixed in version 4.1.75.Final-tuxcare.4 of io.netty:netty-testsuite-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-testsuite-osgi@4.1.75.Final-tuxcare.4"
    }
  ]
}