{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:7af46234-ce97-5848-b6d1-dd2afb9077f7",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.3",
      "type": "library",
      "group": "io.netty",
      "name": "netty-codec-stomp",
      "version": "4.1.92.Final-tuxcare.3",
      "purl": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:38f2e33a-509b-53f1-adc1-4521bfbacbc6",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34462 is fixed in version 4.1.92.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f41a784-44ca-556b-b87b-1a2fb8a5d8d4",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 4.1.92.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5cf58db-fee9-551e-91c5-dfa35976aa2d",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-codec-stomp 4.1.92.Final-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9b9bb98-4c93-5f28-801c-c52fed6b5a93",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-29025 is fixed in version 4.1.92.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42f47062-2050-5883-8d3f-e265efee3564",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47535 is fixed in version 4.1.92.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69a4e750-b5aa-5b8a-90e5-0802bce9d641",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24970 is fixed in version 4.1.92.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:181fe62d-c01c-59ca-8ff4-c252e04dad64",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-25193 affects version 4.1.92.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0569854-4cba-5dc6-b20b-dbf7ba13c586",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55163 is fixed in version 4.1.92.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af367327-2508-5760-b2b8-a626f57da6d6",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58056 is fixed in version 4.1.92.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:544b2ecf-ce60-579e-bc1a-0739c8bf3e66",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58057 affects version 4.1.92.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ebfad20-09e8-5228-acf9-c9f7ad16d1d0",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59419 is fixed in version 4.1.92.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d8a7bd9-ac84-5f85-95ec-611406965e7d",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-67735 is fixed in version 4.1.92.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62792310-5098-5ddf-847e-1796a7599666",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33870 is fixed in version 4.1.92.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da32f679-d0bd-55e8-b62f-714815b54dd7",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.92.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4231eafe-1a03-5b6c-ad74-cf017b8ad0f4",
      "id": "CVE-2026-41417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41417 affects version 4.1.92.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fadf68ff-04ff-55e1-af8d-81eb190596b3",
      "id": "CVE-2026-42577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42577 affects version 4.1.92.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d617e2c-4a3a-5ed6-ac1a-7c9e9d77ece6",
      "id": "CVE-2026-42578",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42578 affects version 4.1.92.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a5e2121-67ba-5519-809d-1b1edcb3aac4",
      "id": "CVE-2026-42579",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42579 affects version 4.1.92.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfb4f968-572d-56a6-8cd1-c98064de5a18",
      "id": "CVE-2026-42580",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42580 affects version 4.1.92.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c641bea4-1ca8-55e8-afb4-95a1b667e460",
      "id": "CVE-2026-42581",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42581 affects version 4.1.92.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bf8415a-af1f-550c-bebe-58bf1c7b6624",
      "id": "CVE-2026-42584",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42584 affects version 4.1.92.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10630042-a2e0-5a0a-92d8-ea48c797611a",
      "id": "CVE-2026-42585",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42585 affects version 4.1.92.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65e3fdbc-4448-5bdc-aba5-848775da5b69",
      "id": "CVE-2026-42586",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42586 affects version 4.1.92.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2c6af46-df9e-58fe-b97b-e2cb3e1f6566",
      "id": "CVE-2026-42587",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42587 affects version 4.1.92.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:542d41dd-05ef-5532-82fb-c5b00bf32fa4",
      "id": "CVE-2026-44248",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44248 affects version 4.1.92.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7ac114b-fce2-5dbb-9fe7-7d1aa81dcba6",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p affects version 4.1.92.Final-tuxcare.3 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.92.Final-tuxcare.3"
    }
  ]
}