{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:990cde90-5fba-59be-9cde-f2ebd6209a43",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.2",
      "type": "library",
      "group": "io.netty",
      "name": "netty-codec-http",
      "version": "4.1.58.Final-tuxcare.2",
      "purl": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:89e31f91-3a2e-5cd8-8046-0c34899f9583",
      "id": "CVE-2021-21290",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-21290 is fixed in version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6214d0a-b3d0-599b-8173-03a87f7ae69a",
      "id": "CVE-2021-21295",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-21295 is fixed in version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efec2d33-5f62-5e38-b6a8-4a01669d581b",
      "id": "CVE-2021-21409",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-21409 affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec692b90-33b9-509e-b2c3-4036e08a6473",
      "id": "CVE-2021-37136",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37136 is fixed in version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79fad968-f079-5318-aae4-729bcf2d7548",
      "id": "CVE-2021-43797",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-43797 affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ee879ab-42e5-51c9-af75-3d355b79ff4f",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24823 is fixed in version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b60a749c-2cf3-5172-a7f8-a4d371762e76",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41881 is fixed in version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:100c9c8f-26d7-5092-98c2-6b4eb72195ba",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34462 is fixed in version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f03a916-9306-5665-a01f-63dc5ae92d5e",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4acde42b-5896-54d7-9751-47e8461ac2fe",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-codec-http 4.1.58.Final-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b05c7f5b-5860-5c63-ad37-8e856a04af2d",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-29025 affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a7e3531-f9ee-5557-a91b-7adba54e426f",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47535 is fixed in version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3218cc58-97fb-5adc-beb1-9de6f712126c",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24970 is fixed in version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59633db5-cb48-5fa0-aff2-e23c84938da4",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-25193 affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9032223-aa75-5ecd-a3eb-d14652faad02",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55163 affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70709644-d636-5b3e-8572-ac7d52bf06d0",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58056 affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a866afab-27a8-5b74-ae91-df0e6e71d8d5",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58057 affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09faa7c6-a5c7-5420-a7a9-20b31be6bf51",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59419 is fixed in version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb3b938a-12ac-5b21-a573-ed32c6c7ee93",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67735 affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:241fa71e-927d-58a9-9d42-8cf339684224",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e46de12e-6940-5599-ba3a-a811781c24a2",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfb7168b-c571-528c-ae71-0fd98a972806",
      "id": "CVE-2026-41417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41417 affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c4ca97c-f98d-5fee-a8cc-c91e57a0904e",
      "id": "CVE-2026-42577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42577 affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c65c739-e695-5a8e-a3c4-3a031f4b9cff",
      "id": "CVE-2026-42578",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42578 affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08d7839b-89e9-543e-9491-fda0cd295c83",
      "id": "CVE-2026-42579",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42579 affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4624f720-d5c3-58ab-ba96-9628fbd4de0a",
      "id": "CVE-2026-42580",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42580 affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e42cc56-e5f7-5144-a2be-431ee7892fa2",
      "id": "CVE-2026-42581",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42581 affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8fef6e8-125a-5a83-89bf-77c93880e0c9",
      "id": "CVE-2026-42584",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42584 affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21145c1f-5e6f-5791-a381-e3e2286c8a26",
      "id": "CVE-2026-42585",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42585 affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b4e7f50-344a-5a99-84ac-5d68a3ace9e0",
      "id": "CVE-2026-42586",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42586 affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13144648-25d5-535f-829a-4be2818f7785",
      "id": "CVE-2026-42587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42587 affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88a90765-bbc3-5901-94a4-f4c65f295afe",
      "id": "CVE-2026-44248",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44248 affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa2bf5ae-a861-552c-9ab2-fcbc699a420c",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.2"
    }
  ]
}