{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ff3aa7cd-3f42-5109-84ff-d97f1c5a6395",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3",
      "type": "library",
      "group": "io.netty",
      "name": "netty-handler",
      "version": "4.1.63.Final-tuxcare.3",
      "purl": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:d286c314-894c-5b8c-a131-783ee65f522b",
      "id": "CVE-2021-37136",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37136 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ab7f83b-c835-5588-8b6d-80fdfb95c8e7",
      "id": "CVE-2021-37137",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37137 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3a6c904-6d32-563a-a4c6-0f4d08569d52",
      "id": "CVE-2021-43797",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43797 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de698abe-7abd-5fd2-b489-457a9c147e9d",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24823 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2393bbd-fef0-59d2-b3ed-9eaa599de0c5",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41881 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28f52cf2-8140-5e36-9f93-52589cdf748a",
      "id": "CVE-2022-41915",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41915 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7869f586-16f6-5379-ab88-90c7f5df2b18",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34462 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e37b770-f3d0-5c71-a92a-7ba1a8d37b2c",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de2e3338-94bd-5f1a-924c-af360f294605",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-handler 4.1.63.Final-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d2ede90-a90a-5ea2-b4d1-548f2b886d38",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-29025 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c40774a8-76ae-5851-b12e-d03e906c228c",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47535 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abae78d7-23ce-5213-9ca5-dd411afb3661",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24970 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5679325d-68ba-5503-82b5-41ee62a292b3",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-25193 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b77a0dc-f22a-58ad-a868-1ad420274cea",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55163 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4aa5489b-a47b-5755-bb65-03c92c74f6aa",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58056 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ccfe5529-27af-51a2-b505-45d9ac8ef1bb",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58057 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40b60610-b84f-5cdb-917d-493768cb9be2",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59419 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd1c0ed7-24aa-549d-ae76-7e6b34c98b3f",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67735 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72d62811-b5f7-5e6d-9231-7879a2c3cb65",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:789d57d5-40f0-5d2a-ae47-28bab12d5063",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37803ea1-a763-53aa-9a09-7e50294301f8",
      "id": "CVE-2026-41417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41417 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e8cba71-249e-55bc-b5c8-6179e5ff2f55",
      "id": "CVE-2026-42577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42577 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f44706b2-6c70-5eb0-8ba6-3f9b0bb3dee5",
      "id": "CVE-2026-42578",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42578 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f8bc74e-705f-5e66-92bf-cab940bdedd0",
      "id": "CVE-2026-42579",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42579 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f39dbedb-7493-584c-bf96-1c52c3207a2a",
      "id": "CVE-2026-42580",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42580 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5bf29eb-c617-58c8-a914-459ef05df78c",
      "id": "CVE-2026-42581",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42581 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb0a8994-ff94-532d-92f0-f9b385af82ae",
      "id": "CVE-2026-42583",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42583 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d96ce7b2-3f25-5ae9-af3d-04525295ae32",
      "id": "CVE-2026-42584",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42584 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4b279c2-1935-55fa-9607-9f7a9d40a1bb",
      "id": "CVE-2026-42585",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42585 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa7c3adf-fb48-5f28-b488-675657a3f680",
      "id": "CVE-2026-42586",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42586 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:585d0bb6-72a6-5510-9183-c35608acf6e6",
      "id": "CVE-2026-42587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42587 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0bb3eee7-62b4-5776-b37b-497c1f7fa07c",
      "id": "CVE-2026-44248",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44248 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a0c3387-96db-5a21-971e-160f2d67dd48",
      "id": "CVE-2026-44249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44249 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97a3c6da-88f1-5fe4-8723-b6ef25202941",
      "id": "CVE-2026-44250",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44250 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:477b6a71-8b77-5596-9f1c-e0e9eccab503",
      "id": "CVE-2026-44890",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44890 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fec833ca-4335-5874-988f-58eee57459e4",
      "id": "CVE-2026-44891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44891 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9896bf2f-58c4-59fa-806e-6db0d7285691",
      "id": "CVE-2026-44893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44893 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c584d56-4f9d-52ff-87fb-2fa00728f212",
      "id": "CVE-2026-45416",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45416 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69f7e16f-e4ac-5991-bbc2-fa107e0448d2",
      "id": "CVE-2026-45536",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45536 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a00d3de-9614-5c48-b980-6d868de92922",
      "id": "CVE-2026-45673",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45673 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2250480-569c-56d5-bfb7-d46e39d5c9b4",
      "id": "CVE-2026-45674",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45674 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09df9034-eb57-5b76-bf6e-e665518ea3ba",
      "id": "CVE-2026-46340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46340 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c9a19b0-2d32-5175-86a7-a2c73eac37a3",
      "id": "CVE-2026-47244",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47244 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6ad70a9-d550-57d4-893a-a9fd471550ab",
      "id": "CVE-2026-47691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47691 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be518d28-de2f-558b-8c84-8b04346dfe48",
      "id": "CVE-2026-48006",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48006 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e5d5fb6-4144-583c-b1c4-428f3308e68f",
      "id": "CVE-2026-48043",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48043 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25a0907c-708e-544a-855e-a9ea59010a1a",
      "id": "CVE-2026-48059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48059 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d941808-618d-5dce-8e37-452b26b16ba1",
      "id": "CVE-2026-50010",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50010 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a027fe01-43c0-5b20-bfed-9405b7c02673",
      "id": "CVE-2026-50011",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50011 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:518013a7-f39d-58a8-806e-a0fc29fafe4c",
      "id": "CVE-2026-50020",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50020 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0d720aa-350d-5da7-9ba4-0199a9b0570c",
      "id": "CVE-2026-50560",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50560 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01e21e26-b80f-5daa-a9a6-f0bcbbf8b7ae",
      "id": "CVE-2026-55831",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55831 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a82e04c-28ee-5c08-ad08-6bca594de97c",
      "id": "CVE-2026-55833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55833 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:292ec0e0-8af5-5a8e-aa87-891d1732a9a1",
      "id": "CVE-2026-55851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55851 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92750157-2474-55ef-beb8-ffb4bf6c7641",
      "id": "CVE-2026-56745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56745 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be5ded44-3ea6-5e94-8426-2282e8322eb5",
      "id": "CVE-2026-56746",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-56746 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab5dc9d7-827b-5635-aab3-cbe8509bb221",
      "id": "CVE-2026-56817",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-56817 does not affect version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler. not_affected \u2014 The Netty codec-xml module contains XmlDecoder, which instantiates an Aalto XML parser without security configuration (line 38: new InputFactoryImpl() with no XXE protection). However, this is a library component that Netty itself does not use in its own production code. The vulnerability only manifests when downstream applications explicitly add XmlDecoder to their Netty channel pipelines. Per..."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7a9d306-6078-5540-9eb3-694f5f4caa6b",
      "id": "CVE-2026-59898",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59898 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d99fdfef-fcf6-5b15-adbe-efebe887d79c",
      "id": "CVE-2026-59899",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59899 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c6450e7-407a-5f8b-90f2-27a90c9220fe",
      "id": "CVE-2026-59900",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59900 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bed8bf8-fb0a-5a83-9c37-d6c5efc43fd8",
      "id": "CVE-2026-59901",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59901 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:307c549b-e4f9-50d9-956a-18b0b5aa07fa",
      "id": "CVE-2026-59919",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59919 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01a80588-0d82-54b5-af56-0ee24a7726eb",
      "id": "CVE-2026-59920",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59920 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f695de88-1544-51d9-ae90-404a78c10782",
      "id": "CVE-2026-59921",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59921 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e127844-1e2d-5e13-b91d-ee79b9852d07",
      "id": "GHSA-mfg7-5gfp-c4w3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mfg7-5gfp-c4w3 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e36207d7-5dc8-5b62-a630-2b134547ce10",
      "id": "GHSA-v74w-7mr3-4qg3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-v74w-7mr3-4qg3 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:647a1086-4597-56b4-894a-bf22b709eb75",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-handler."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-handler@4.1.63.Final-tuxcare.3"
    }
  ]
}