{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f2cb6526-438c-5df0-8ec7-275727096c42",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.1",
      "type": "library",
      "group": "io.netty",
      "name": "netty-codec-http",
      "version": "4.1.58.Final-tuxcare.1",
      "purl": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:5dc104bc-d5e9-5bf6-80d2-75ec6d083f23",
      "id": "CVE-2021-21290",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-21290 is fixed in version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6510f815-d718-5d7c-8ad1-f843544f0863",
      "id": "CVE-2021-21295",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-21295 is fixed in version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ec70699-7f77-5391-a686-57c3a8fad039",
      "id": "CVE-2021-21409",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-21409 affects version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6852c0ac-353a-5d6d-b013-348c466e1182",
      "id": "CVE-2021-37136",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37136 is fixed in version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7c85ecd-da7c-56c4-b8b0-b53f79a6efe8",
      "id": "CVE-2021-37137",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37137 is fixed in version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb28045f-861d-5e5e-bcb6-c16ede950bc4",
      "id": "CVE-2021-43797",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-43797 affects version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2640ef08-da8a-5b32-867c-bbc0977d6e15",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24823 is fixed in version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d395ec82-49ae-54e0-a653-5deb56505937",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41881 is fixed in version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0664e9f8-71d3-5bcb-a74c-f90d47846084",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34462 is fixed in version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70ed9930-7938-53b1-974b-7a630c376905",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4f6b9fc-2a0f-504f-867c-68239f1c149a",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-codec-http 4.1.58.Final-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd011753-59cd-5c80-b464-c78f0c1236df",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-29025 affects version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20b29ba7-819c-5205-afa2-05ea83dca257",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-47535 affects version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af07da27-24d6-5989-99d9-71ba8646a3c1",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24970 is fixed in version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7211228a-face-5fa7-85b9-1d04652055e5",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-25193 affects version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:453e05dc-b73a-5456-af3a-dcaa76897eba",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55163 affects version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:579ff737-9052-5269-95c7-302d3df09675",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58056 affects version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:291ad32f-c469-5ca0-9279-b76a77adcc27",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58057 affects version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5af3e934-f67e-53ec-9af1-9d21b5259435",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59419 is fixed in version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aafc444a-3484-5586-8b8e-41e58dd8fa71",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67735 affects version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99c89acd-4acc-5b7f-b832-f33e78a675e3",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51c077f7-513e-5806-ada6-88ebe5e6fdc6",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c794281c-c28f-56cc-a73c-afca48855333",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p affects version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-codec-http@4.1.58.Final-tuxcare.1"
    }
  ]
}