{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:6668e1c7-dbeb-58d9-a6cc-8cbb1ddd1345",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4",
      "type": "library",
      "group": "io.netty",
      "name": "netty-codec-stomp",
      "version": "4.1.92.Final-tuxcare.4",
      "purl": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:52928251-9622-5389-a15d-44ca15f01cc3",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34462 is fixed in version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec7bd96f-3ebb-5996-909b-1e67da10617f",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af7e20f9-c23e-530f-a354-d623a8346805",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-codec-stomp 4.1.92.Final-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e03003ec-7c6b-5c18-98ca-a9c5d3e67a5c",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-29025 is fixed in version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a07d2e91-8826-5eb9-bae8-a9e4e53ec478",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47535 is fixed in version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a44a4791-f3d2-54e2-bcb4-a053fbc52237",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24970 is fixed in version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1569ca5-3042-5286-ad3c-4467bbd3dde1",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-25193 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3355303-ecc7-5517-96c1-d62442884cde",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55163 is fixed in version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ffc5294c-017a-5379-993b-f2d08b148526",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58056 is fixed in version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ddaf0113-4801-50b5-a468-9f1b26981a52",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58057 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2e9d4e7-7c4d-5b41-a924-3232d05e131e",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59419 is fixed in version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72f2c9e3-8956-5417-982c-419cb2f6a753",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-67735 is fixed in version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:940d8837-6041-56d9-9bdc-5ef297717f09",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33870 is fixed in version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1208ec7c-f2e1-50e6-bf1b-3d5e5b3db9ee",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06539b66-cef4-505e-a382-ffac4beabd8d",
      "id": "CVE-2026-41417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41417 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36e0aac2-15f8-53e7-8bee-4e5cfe1d9ff1",
      "id": "CVE-2026-42577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42577 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d30746c2-c91d-55e1-b583-fd68318a5490",
      "id": "CVE-2026-42578",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42578 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28b6519f-bb1e-5142-b228-9f0452f6733d",
      "id": "CVE-2026-42579",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42579 is fixed in version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:948260fa-c68f-5938-a7b1-87f3d3b6e2f6",
      "id": "CVE-2026-42580",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42580 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f617570-f3e8-56c8-a568-58ab0d5e45b1",
      "id": "CVE-2026-42581",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42581 is fixed in version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b75d294-eaa0-55d0-9999-01c1c67488b5",
      "id": "CVE-2026-42583",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42583 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2904c2f-34fb-582e-a188-bb2fc9818bc4",
      "id": "CVE-2026-42584",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42584 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8605b45-3f0d-56ec-b110-faf52cd4c56a",
      "id": "CVE-2026-42585",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42585 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be951019-2557-5973-9420-d0e9ef410865",
      "id": "CVE-2026-42586",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42586 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e86d7358-58c4-5bf7-8d24-cf8740fcb8ec",
      "id": "CVE-2026-42587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42587 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88d2aa3d-e5ad-5c91-b723-cf730de04b38",
      "id": "CVE-2026-44248",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44248 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:026d51d4-5275-5b69-a188-4b9633e9ba9f",
      "id": "CVE-2026-44249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44249 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c858905-65c5-5ef2-8f48-29e12fe0f0b9",
      "id": "CVE-2026-44250",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44250 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0005f5f9-f6a7-59e1-ac8c-64c1b6bb5236",
      "id": "CVE-2026-44890",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44890 is fixed in version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2e4eab1-0c4e-5194-b6c3-12ad03d5cce0",
      "id": "CVE-2026-44891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44891 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4b5e6ef-fb0f-5017-8ee1-7a57fc204814",
      "id": "CVE-2026-44893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44893 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e4765c0-c3b5-57df-830e-b0a65dfbc813",
      "id": "CVE-2026-45416",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45416 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d599db5-c9e7-5345-a89a-2743f701c8da",
      "id": "CVE-2026-45536",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45536 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb208fc6-0590-54b5-a4a8-7f15ff6df744",
      "id": "CVE-2026-45673",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45673 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7858792f-6eeb-5cc0-a60b-29156f37e71a",
      "id": "CVE-2026-45674",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45674 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91dc276e-e809-570f-85cf-12c2a1fd5135",
      "id": "CVE-2026-46340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46340 is fixed in version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c55f1030-5c49-57b3-b000-6bd85752d2cb",
      "id": "CVE-2026-47244",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47244 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04018d38-2b1c-59a1-91e9-0f89a8c3e11b",
      "id": "CVE-2026-47691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47691 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eaedb024-a227-5655-b1b7-734950b60edd",
      "id": "CVE-2026-48006",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48006 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b362fcf1-b6fd-55a9-981e-fcc48ebb8ddf",
      "id": "CVE-2026-48043",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-48043 does not affect version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp. not_affected \u2014 The target repository (Netty 4.1.92.Final-tuxcare.3) is not affected by CVE-2026-48043. The vulnerability exists in a newer architectural pattern (ChannelInboundHandlerAdapter-based decompression handling) that was introduced after version 4.1.92. The target uses an older architecture that processes HTTP/2 decompression directly in the onDataRead() method with existing try-finally protection."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89280508-6ca7-5b92-841a-e7daf044d2b8",
      "id": "CVE-2026-48059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48059 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:538ac0e9-82f0-5713-8881-a16a8303eb42",
      "id": "CVE-2026-50010",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50010 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fffe5c04-af61-52b5-ad08-6fc290cc62cf",
      "id": "CVE-2026-50011",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50011 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd2cdbe4-4a19-5f0a-8e28-abf5408628ea",
      "id": "CVE-2026-50020",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50020 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e739e89a-55e8-5b59-a07c-216dba6f120f",
      "id": "CVE-2026-50560",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50560 is fixed in version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:370b0507-7134-5176-8eec-dff62aa27cdb",
      "id": "CVE-2026-55831",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55831 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5658616-135c-51f0-97a0-9520db842268",
      "id": "CVE-2026-55833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55833 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76704ec1-99e8-544e-a671-dd7efe2a13d7",
      "id": "CVE-2026-55851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55851 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b64972b6-4834-566a-a15d-770ae83f2363",
      "id": "CVE-2026-56745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56745 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff70c310-bbf1-5de6-a1a0-9e8f57e62ea7",
      "id": "CVE-2026-56746",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56746 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e5774fc-3824-5060-a3f3-323c107452b6",
      "id": "CVE-2026-56817",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56817 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:287ab374-c577-5252-965c-7b4776d4828c",
      "id": "CVE-2026-56820",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56820 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f95aaf1-a715-5d47-931d-18655422a72c",
      "id": "CVE-2026-56821",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56821 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:672461ee-57bf-56e6-9b87-c252590575f1",
      "id": "CVE-2026-56822",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56822 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80118d30-1061-5f6a-bc0d-89dde1e6f79b",
      "id": "CVE-2026-59898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59898 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:611a07c0-d83f-5693-9099-3e52367839e1",
      "id": "CVE-2026-59899",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59899 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33954e04-1d0e-5df7-a329-f293ff03019a",
      "id": "CVE-2026-59900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59900 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a004f47f-7097-5011-9322-c90d78cce959",
      "id": "CVE-2026-59901",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59901 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e77f20d-0466-5945-9dbc-7e7584dcc78a",
      "id": "CVE-2026-59919",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59919 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6af4d4d-8dbe-539d-93d2-7c312bb54fbd",
      "id": "CVE-2026-59920",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59920 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:899fc637-c991-50cc-8c9e-1a7c8acf44e8",
      "id": "CVE-2026-59921",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59921 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43c91176-0705-57c8-b909-c662be07b613",
      "id": "GHSA-mfg7-5gfp-c4w3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mfg7-5gfp-c4w3 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fea1305c-f4de-581c-9660-d3b4e6b605b8",
      "id": "GHSA-v74w-7mr3-4qg3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-v74w-7mr3-4qg3 affects version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:022d9a24-8be3-5953-94b1-b132d9cefbdf",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p does not affect version 4.1.92.Final-tuxcare.4 of io.netty:netty-codec-stomp. The version is not vulnerable. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.4"
    }
  ]
}