{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f1b0cfcd-f1b8-5670-bd74-64f3a513aa52",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3",
      "type": "library",
      "group": "io.netty",
      "name": "netty-codec-haproxy",
      "version": "4.1.63.Final-tuxcare.3",
      "purl": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:9e90c773-9af1-5ec2-9795-9530591735d7",
      "id": "CVE-2021-37136",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37136 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d53c93c-817f-5720-9e9c-bfcd49c22d46",
      "id": "CVE-2021-37137",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37137 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:637704ae-5c9c-5f60-b3d4-8182bc2b34a2",
      "id": "CVE-2021-43797",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43797 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:676a8ee8-830d-5cc4-a152-3e5dbbb08a1c",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24823 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eabefc96-2d78-5d07-a68c-9d950320082f",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41881 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f33f89c4-3716-5792-9776-9c662acb09a4",
      "id": "CVE-2022-41915",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41915 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78e73909-371c-54c9-8245-b302e313982b",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34462 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebf7e9fd-fd28-57bd-bf5f-db7d6ef92517",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9d6e8ff-d563-55ea-91bb-03200f34bcf3",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-codec-haproxy 4.1.63.Final-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63d3b501-1fc5-5799-9932-a1717e361779",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-29025 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55a85acd-1b1a-5a24-8cde-bdbfcb25443d",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47535 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca89b358-44f0-5adc-a834-6f4d6bd4115c",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24970 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a0966a0-b50c-5b65-b4d0-825cea78d30b",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-25193 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f9960e0-9268-5e23-bfae-e81a47b0321b",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55163 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1406574-d8de-5395-9812-86a0bd09feda",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58056 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:170adb15-6c1e-5f1d-b1ab-443caf695d20",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58057 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18ba867e-152e-5cd9-9342-aea2c45c7ae5",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59419 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:000c6f7e-01a0-5eaf-8a0d-3a3d62351396",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67735 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:810f5b2f-a4f0-5fc8-a74e-1661e88d7860",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46e56444-0ffb-5137-b34e-e3ff578f1f07",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4dab924-9845-51f9-993b-216ab65c9815",
      "id": "CVE-2026-41417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41417 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70f1cb7c-6d29-5b7a-96d1-7fbd1a8a25be",
      "id": "CVE-2026-42577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42577 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6d79197-64a8-5a53-a859-801e83b2c26e",
      "id": "CVE-2026-42578",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42578 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47867f52-b962-511a-98af-0fdbc870713d",
      "id": "CVE-2026-42579",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42579 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31e183c0-db6e-55f4-a132-1a615a118604",
      "id": "CVE-2026-42580",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42580 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a3a7381-5852-5995-9f2b-6b8e49b4f9dd",
      "id": "CVE-2026-42581",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42581 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcf145a6-6442-5111-b71e-a5b8fb1a35bd",
      "id": "CVE-2026-42583",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42583 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e10a5e92-c156-552c-999e-5d6af0089940",
      "id": "CVE-2026-42584",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42584 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ccd226eb-3503-52b5-8d75-edaa893f3e32",
      "id": "CVE-2026-42585",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42585 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc9a1e98-d124-518c-bc6a-7f93a763dbba",
      "id": "CVE-2026-42586",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42586 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bd1fe06-fc15-5660-846a-3404127636aa",
      "id": "CVE-2026-42587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42587 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57383a5e-5ea3-55df-ac64-f426bf1b30e1",
      "id": "CVE-2026-44248",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44248 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26aea67a-ddcf-55d0-9a25-9e4aa667cfdb",
      "id": "CVE-2026-44249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44249 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:586669d7-dc4f-5bc0-a150-0d1890d53100",
      "id": "CVE-2026-44250",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44250 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a1ae336-93b0-5f5e-a360-757522adedf6",
      "id": "CVE-2026-44890",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44890 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3872e44f-ee4c-5b34-beef-1a4dd29c941e",
      "id": "CVE-2026-44891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44891 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4c3ba40-d168-5c9c-a7b0-7fda07349792",
      "id": "CVE-2026-44893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44893 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9620a772-1f24-56f2-84e0-3e7e4da27429",
      "id": "CVE-2026-45416",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45416 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f14ccfc-d6c3-573c-9b26-00f7ca51bb12",
      "id": "CVE-2026-45536",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45536 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7cca8e81-28e5-51bd-a83f-3e5e7ad14820",
      "id": "CVE-2026-45673",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45673 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b7774f3-a933-5186-ba60-019518075c96",
      "id": "CVE-2026-45674",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45674 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a56d96a8-5fab-5bcf-989b-c96d3202386c",
      "id": "CVE-2026-46340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46340 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36dceab8-8e8f-598b-87d2-7f7b66f60906",
      "id": "CVE-2026-47244",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47244 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1c52a11-2ac2-5c41-9069-8b10531029a2",
      "id": "CVE-2026-47691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47691 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8cd6805-154f-5c8e-ace9-3ed3ee82c17f",
      "id": "CVE-2026-48006",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48006 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50492524-8322-54be-b793-932a025f293c",
      "id": "CVE-2026-48043",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48043 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6513f1c1-c690-50fe-9225-b68e148a5f2d",
      "id": "CVE-2026-48059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48059 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32d6ddab-b5d2-5137-a08f-36a584f51781",
      "id": "CVE-2026-50010",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50010 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba4e3790-8dee-50d0-9b81-4ecaac887b38",
      "id": "CVE-2026-50011",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50011 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6259ee6a-5c88-5545-a48c-9790c0c90eeb",
      "id": "CVE-2026-50020",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50020 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:993509da-594f-5008-b3c5-bd46c673fb77",
      "id": "CVE-2026-50560",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50560 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a98bb31-8c15-53f1-a85f-af1762bb3427",
      "id": "CVE-2026-55831",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55831 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57ee03c1-c9b3-5980-a79d-62f0f0463476",
      "id": "CVE-2026-55833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55833 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6665196-35a1-52df-a944-1da6da862451",
      "id": "CVE-2026-55851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55851 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a711060-6bd0-5731-a9cd-93c3c6610b78",
      "id": "CVE-2026-56745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56745 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5599ac8-b433-5d1e-89f5-d3c78c5dd678",
      "id": "CVE-2026-56746",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56746 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efe7c533-4bf1-57d1-8fa8-f99a3eac8525",
      "id": "CVE-2026-56817",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56817 does not affect version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy. not_affected \u2014 The Netty codec-xml module contains XmlDecoder, which instantiates an Aalto XML parser without security configuration (line 38: new InputFactoryImpl() with no XXE protection). However, this is a library component that Netty itself does not use in its own production code. The vulnerability only manifests when downstream applications explicitly add XmlDecoder to their Netty channel pipelines. Per..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4d63041-4744-5e97-acbc-ed491063d1b2",
      "id": "CVE-2026-59898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59898 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d15b14af-2419-5d96-b014-51ef62c3f7f7",
      "id": "CVE-2026-59899",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59899 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fbc29e9-8aee-5b52-be84-2fe20144a322",
      "id": "CVE-2026-59900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59900 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d3b812e-05c8-58c6-a948-e64fb2a8ebc5",
      "id": "CVE-2026-59901",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59901 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7dcddda2-e44c-52eb-9684-4de8bc784197",
      "id": "CVE-2026-59919",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59919 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a49fb2ce-f0b0-51a4-8730-8f5b5b459143",
      "id": "CVE-2026-59920",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59920 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fdc0d71-a52e-5a42-9353-69beceb5aff5",
      "id": "CVE-2026-59921",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59921 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7ecd9a3-5985-522d-8bb2-a3df86ad3911",
      "id": "GHSA-mfg7-5gfp-c4w3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mfg7-5gfp-c4w3 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db86f1de-b954-5f5c-a4a5-4873e513411b",
      "id": "GHSA-v74w-7mr3-4qg3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-v74w-7mr3-4qg3 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2acc5d92-fe46-56b0-997c-fdb99b5e049b",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-haproxy."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-codec-haproxy@4.1.63.Final-tuxcare.3"
    }
  ]
}