{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:760d1b42-da68-55f5-af16-eedd392251a4",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1",
      "type": "library",
      "group": "io.netty",
      "name": "netty-codec-http2",
      "version": "4.1.60.Final-tuxcare.1",
      "purl": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:089774b5-a101-573b-84fc-d9e4849f7407",
      "id": "CVE-2021-21409",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-21409 is fixed in version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:309c6518-d156-5e84-85f7-5e90eaeea3c1",
      "id": "CVE-2021-37136",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37136 is fixed in version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7939adf7-d8b1-58c6-932d-d86c5996ce69",
      "id": "CVE-2021-37137",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37137 is fixed in version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21d8f1c6-270e-513b-97f0-3068ae3c25c4",
      "id": "CVE-2021-43797",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43797 is fixed in version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bff4b202-d9e5-57de-a769-36c9a3b3ebc4",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24823 is fixed in version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3358f3ad-5a91-55c6-9ed0-a18a2e7c6eb1",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41881 is fixed in version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b2ed131-9bf1-5a07-83d1-8759aca616aa",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34462 is fixed in version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f09deb50-8d0c-5775-a1e0-3b3695301237",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7929bebd-a266-5e65-9429-25f38737a473",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-codec-http2 4.1.60.Final-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a266524e-a149-5613-8dc9-0326bd297181",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-29025 is fixed in version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10571f10-773c-5753-a501-cd21edce868f",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47535 is fixed in version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9334e2d9-3d38-56e0-9510-15ac6497ae49",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24970 is fixed in version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68374c80-8b0c-5917-a90d-df5aa76ee2a8",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-25193 affects version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87a82b67-f32a-50a8-978d-f89c75828443",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55163 is fixed in version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ec13f90-be9e-5ff9-989b-9a25aa24b859",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58056 affects version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6866104-9ebf-5bf0-adc7-5c3eeebb2738",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58057 affects version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d012e3b9-d55d-5148-aef0-1c5a28db8b21",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59419 is fixed in version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:edc23fea-4243-530d-a0fa-400255dbc2fa",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-67735 is fixed in version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c541043-6bef-5b1f-9254-4983fda2b2d9",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72287f9b-0eee-5474-826e-1fdef7d9460c",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9829de2e-d48d-575f-924a-ef081f77c96b",
      "id": "CVE-2026-41417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41417 affects version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e7b62d9-ca41-5132-a213-417dd2a69de4",
      "id": "CVE-2026-42577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42577 affects version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4417d675-a38d-58f9-852e-81fe473cde2a",
      "id": "CVE-2026-42578",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42578 affects version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f9581a6-a147-5ed0-aa7b-e641ea6c38b8",
      "id": "CVE-2026-42579",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42579 affects version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:176c2fd8-15ad-586b-b9f2-2ff8ea0d84f9",
      "id": "CVE-2026-42580",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42580 affects version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75c016c2-3bc5-506d-8ee3-0dd1b22ff738",
      "id": "CVE-2026-42581",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42581 affects version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5bec3971-bb66-57e7-921f-c5f17afd42d1",
      "id": "CVE-2026-42584",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42584 affects version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7604008a-4bc0-5778-a870-bb0334c000a4",
      "id": "CVE-2026-42585",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42585 affects version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8465908-a5ac-57cf-badf-e06ed0505766",
      "id": "CVE-2026-42586",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42586 affects version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5207e7d-8516-5ad4-aa93-a8c9cfa9e7f4",
      "id": "CVE-2026-42587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42587 affects version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aafda5d4-548a-5252-8ec9-a6d6d0150379",
      "id": "CVE-2026-44248",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44248 affects version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40d3f3dc-9884-5a55-9e7e-2a02ab474548",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p is fixed in version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
    }
  ]
}