{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:07663e50-2df3-5f8d-9c1f-37e9196eb81f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.1",
      "type": "library",
      "group": "io.netty",
      "name": "netty-codec-http",
      "version": "4.1.63.Final-tuxcare.1",
      "purl": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:fbda1bb5-30ae-5fd3-82df-6c5f4110132b",
      "id": "CVE-2021-37136",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37136 is fixed in version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d9287f8-d4e7-5064-bc7b-1239db8a18cd",
      "id": "CVE-2021-37137",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-37137 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2929339-847a-5787-aac8-a2646b5766fb",
      "id": "CVE-2021-43797",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-43797 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df3a4570-052c-5c86-8b54-2c62ced746f1",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-24823 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f432e8b9-4b29-59b8-9b68-adaace7fee7e",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-41881 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce6f25b3-d26c-59d6-8c68-5cc41d5bbb3a",
      "id": "CVE-2022-41915",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-41915 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6197d5d4-1eaa-53f9-824d-b113f8ee7187",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-34462 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58d78a2f-457f-547e-92f2-3a762b90338f",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7049c8ea-2f5c-5663-a8b0-ce54552cee22",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-codec-http 4.1.63.Final-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd014f92-ad96-5136-b514-e55c9dd5d41e",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-29025 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4adabf6d-e40c-50cb-b107-6a6ef7135945",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-47535 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebe060a8-0741-5f3e-9e70-9528a6d591e1",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24970 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25c576f1-eb6b-5754-8cee-bb1a0155f198",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-25193 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:220e9e1d-8c28-5a53-9103-0709b4a59b81",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55163 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1661ec99-ef31-51a8-92fe-bac6d3d18347",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58056 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04ce11d5-3cc0-5312-a8e1-b7da518653ff",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58057 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3395a97a-39d9-55c6-a711-4e923438d6a2",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59419 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5663ba8-68f0-500f-b099-2c2ab3255815",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67735 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb1220ba-ab5d-5032-8a60-26e78b0a7e8c",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a03d859f-4972-5d6f-a6af-17724119774c",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7166ed0-551b-538a-bdae-16f778c3c4a6",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-codec-http@4.1.63.Final-tuxcare.1"
    }
  ]
}