{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ebca6bf2-b349-5887-bcc4-8c342975a557",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-codec-http2@4.1.63.Final-tuxcare.3",
      "type": "library",
      "group": "io.netty",
      "name": "netty-codec-http2",
      "version": "4.1.63.Final-tuxcare.3",
      "purl": "pkg:maven/io.netty/netty-codec-http2@4.1.63.Final-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:65543b5b-498a-534a-a0a5-8d47ff81b39f",
      "id": "CVE-2021-37136",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37136 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3da8245-e022-5bed-a027-a7c2f464697a",
      "id": "CVE-2021-37137",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37137 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32c580a8-cf2e-5a0c-a0fd-94d95a130e02",
      "id": "CVE-2021-43797",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43797 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28da2666-f4c9-524b-b08f-d8c0a8e8febb",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24823 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:981562d9-49dc-5449-96e2-0827120e68cf",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41881 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d0c38cc-72b1-528f-a0f2-5bfeb26b9001",
      "id": "CVE-2022-41915",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41915 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bd4837b-00d6-5cbc-af72-343b70e14e4c",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34462 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c4fef74-e99a-5e63-b66e-9889558ebf61",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9b0fe4d-7a36-571b-9355-25659dc961ef",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-codec-http2 4.1.63.Final-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb4a07e2-461c-594c-9579-5966c57f35c3",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-29025 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe6f7f5d-87fe-55ab-8178-0ad57a3befe4",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47535 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8d11514-00fe-5a5d-8966-eb0c1b77766c",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24970 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4e4036e-4fc3-5476-8bc9-111e3b1319d2",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-25193 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a30d1346-0976-5848-8516-596602ce6ae2",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55163 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:411a0732-fe4c-5a36-ad5b-64e55d080c5f",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58056 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1dbc4680-4f56-5eeb-a86f-0fef6977fff8",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58057 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5acd5d7-84bf-58f8-b209-7c43626a84db",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59419 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99350c71-c013-52e9-b80c-5d1b55dff564",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67735 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efde47a1-ad95-5827-a751-c4a91c66fc8b",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b552e08-4f60-55fa-a48b-f1c3d9f7c4de",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:907d0657-a24b-5603-8e2f-f8f753f29b96",
      "id": "CVE-2026-41417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41417 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7a9cfbf-9352-52ac-ae46-ba031ff58265",
      "id": "CVE-2026-42577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42577 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0026f377-1f3e-5b94-b0aa-2837f4dd1104",
      "id": "CVE-2026-42578",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42578 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:219a3f74-1ec8-5fda-9c07-17003feb4b9d",
      "id": "CVE-2026-42579",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42579 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de8f7c7f-644c-5630-9b9a-07f433b2d8c6",
      "id": "CVE-2026-42580",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42580 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53ae7b6e-b768-5f4a-8f7b-07134a7fe2cb",
      "id": "CVE-2026-42581",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42581 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94b1bc5b-98c2-5f40-804e-040ef2dff6b4",
      "id": "CVE-2026-42584",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42584 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aeebef32-0d0e-52ba-9df0-b1c669e26eff",
      "id": "CVE-2026-42585",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42585 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a54bb2ad-d889-58d6-9e12-6c2dd6dc4fc5",
      "id": "CVE-2026-42586",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42586 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96a0fb3d-7fb6-50d6-900d-fbcaf72e6aa3",
      "id": "CVE-2026-42587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42587 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca8f36be-0860-5b58-9fd6-944bd06059bc",
      "id": "CVE-2026-44248",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44248 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c73ddac-156b-54d4-aec6-ade7c2a71cee",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.63.Final-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.63.Final-tuxcare.3"
    }
  ]
}