{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:be3a1c26-e9d1-58fe-9db5-9d7c91a02c99",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-codec-http2@4.1.49.Final-tuxcare.1",
      "type": "library",
      "group": "io.netty",
      "name": "netty-codec-http2",
      "version": "4.1.49.Final-tuxcare.1",
      "purl": "pkg:maven/io.netty/netty-codec-http2@4.1.49.Final-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:33644053-c334-5597-bca6-a2a5cc5a2a4d",
      "id": "CVE-2021-21290",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-21290 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f621c618-8b22-55f2-b585-4df470cdb99f",
      "id": "CVE-2021-21295",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-21295 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99afdfc2-b0dd-5991-9043-5045f41e8be5",
      "id": "CVE-2021-21409",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-21409 is fixed in version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2c5410c-6007-5ea4-af8a-e13b91583eb3",
      "id": "CVE-2021-37136",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37136 is fixed in version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b33b29ac-6dc5-5242-b693-65c9cdfe771e",
      "id": "CVE-2021-37137",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37137 is fixed in version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f6db1a3-36ca-5a8e-9fc4-6de2500f998f",
      "id": "CVE-2021-43797",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43797 is fixed in version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a7d55e9-6171-5fde-82e6-df5cee1f860b",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24823 is fixed in version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02cb1a31-6467-5fa1-acfa-1ccc819b852c",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-41881 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d810f5bd-87b8-5961-ab61-80373676b353",
      "id": "CVE-2022-41915",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-41915 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e43759b1-4856-583a-9026-838fbb6dfec1",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34462 is fixed in version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cdd53b33-1e62-5a7b-8cdd-083844118b8d",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb70abcd-ea0e-5cab-b484-5a0a62967f65",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-codec-http2 4.1.49.Final-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7354f1ca-af29-52fb-a3f1-56cef3b8a51b",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-29025 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e69caf88-a52f-5470-9102-4d99fe07dbe5",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-47535 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b60091a1-be8c-5716-978b-f4861a1d994f",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24970 is fixed in version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1010746d-7928-56d2-bc6d-fe4870b07141",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-25193 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78f2ca82-9e65-59a7-9c9e-b657a5240a10",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55163 is fixed in version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be15af19-8c86-5374-9011-236441e55d29",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58056 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a31101c6-04e6-5685-917d-a43c878426bf",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58057 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b65800b-0092-5d44-8052-86ee29b9b18d",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59419 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72f34a51-7d0c-5013-8338-ab557515e066",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67735 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7b9323a-fab1-50f6-8d48-6875979c3f50",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b098693-c61a-589a-b7ea-645d605c55b7",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3cb837a9-67b3-5d6b-abcd-14a4bbc99127",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.49.Final-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.49.Final-tuxcare.1"
    }
  ]
}