{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:68e605a2-8657-57a5-800f-72bea78902f3",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-codec-http2@4.1.58.Final-tuxcare.2",
      "type": "library",
      "group": "io.netty",
      "name": "netty-codec-http2",
      "version": "4.1.58.Final-tuxcare.2",
      "purl": "pkg:maven/io.netty/netty-codec-http2@4.1.58.Final-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:362283b6-1ee2-5682-8fe6-eed495207db7",
      "id": "CVE-2021-21290",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-21290 is fixed in version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48e8f9b6-23f4-5490-b3c6-83ca3b8369a4",
      "id": "CVE-2021-21295",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-21295 is fixed in version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07a4ceb8-8235-59fb-8e69-de64514f48bb",
      "id": "CVE-2021-21409",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-21409 affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39430f7f-ef19-5a19-a555-9c8eb2139882",
      "id": "CVE-2021-37136",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37136 is fixed in version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69ea7cd3-5791-52cc-a7d0-5676666b999a",
      "id": "CVE-2021-43797",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-43797 affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8bfb1ce-3116-549a-bc6b-b2a3ede4556b",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24823 is fixed in version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8edcdabe-e384-51e0-85b3-fe69a0773339",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41881 is fixed in version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4d65cad-22b1-53bf-b207-bea1eb4b5a9d",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34462 is fixed in version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3201fbcc-3725-560b-aa4e-c164e172eb68",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67f44d12-8259-5261-8a58-36c7f46eaab8",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-codec-http2 4.1.58.Final-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f725e183-1715-5f79-b834-d3ec8c380cc4",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-29025 affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32dd0047-8e43-5223-a29f-e48e341451e7",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47535 is fixed in version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6cb8a216-46bb-56d2-9491-37d5f1c87aa2",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24970 is fixed in version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9264c4cf-c1cd-57c8-91a9-0a64a64ba8fe",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-25193 affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09742744-d2ee-51a1-93da-6b0be7925a73",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55163 affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:869af8db-1446-5cb9-87eb-d740ce45f03e",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58056 affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:062c3422-fe2e-55bd-9cd6-63eb57accc29",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58057 affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35d41b3f-3d8a-5186-9da3-63eed47ccab2",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59419 is fixed in version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8638544e-b305-5a61-993d-a9e3c048efdf",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67735 affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4609939-5616-557c-bee3-a6b90c844544",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5686d7dc-ef2c-596a-8f5f-34d9778e58f1",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:397e0d7a-ad11-50e7-a725-7b21fba5520d",
      "id": "CVE-2026-41417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41417 affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17c93135-57c4-5676-9fd2-f66481ba589a",
      "id": "CVE-2026-42577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42577 affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3eefe42-fbf2-5d69-851f-19350e14b9a0",
      "id": "CVE-2026-42578",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42578 affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eed16dd2-6eaa-5aae-980f-2df902818d20",
      "id": "CVE-2026-42579",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42579 affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92925789-8629-5c17-be01-9427de1e757a",
      "id": "CVE-2026-42580",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42580 affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:549a4856-05f5-5aa1-b8b5-3b1d592613cb",
      "id": "CVE-2026-42581",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42581 affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d18a34a-503b-539c-bceb-fac3b69fa364",
      "id": "CVE-2026-42584",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42584 affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af7a38a8-feac-50dd-83c3-b8ca0de06933",
      "id": "CVE-2026-42585",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42585 affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b4f066c-668d-5e4a-a768-fa944b75dc5b",
      "id": "CVE-2026-42586",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42586 affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5d71bcc-f372-5df1-8c86-a9d56103780c",
      "id": "CVE-2026-42587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42587 affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfe1116a-bfb2-5af3-aac2-edeb66691b62",
      "id": "CVE-2026-44248",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44248 affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.58.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:851ea4a2-3dd5-52f9-bbac-e57c6a2bcc77",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p affects version 4.1.58.Final-tuxcare.2 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.58.Final-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.58.Final-tuxcare.2"
    }
  ]
}