{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3ad2b8ef-9783-50c6-b000-51cb2e614087",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1",
      "type": "library",
      "group": "io.netty",
      "name": "netty-codec-http2",
      "version": "4.1.60.Final-tuxcare.1",
      "purl": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:089774b5-a101-573b-84fc-d9e4849f7407",
      "id": "CVE-2021-21409",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-21409 is fixed in version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:309c6518-d156-5e84-85f7-5e90eaeea3c1",
      "id": "CVE-2021-37136",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37136 is fixed in version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7939adf7-d8b1-58c6-932d-d86c5996ce69",
      "id": "CVE-2021-37137",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37137 is fixed in version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21d8f1c6-270e-513b-97f0-3068ae3c25c4",
      "id": "CVE-2021-43797",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43797 is fixed in version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bff4b202-d9e5-57de-a769-36c9a3b3ebc4",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24823 is fixed in version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3358f3ad-5a91-55c6-9ed0-a18a2e7c6eb1",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41881 is fixed in version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b2ed131-9bf1-5a07-83d1-8759aca616aa",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34462 is fixed in version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f09deb50-8d0c-5775-a1e0-3b3695301237",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7929bebd-a266-5e65-9429-25f38737a473",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-codec-http2 4.1.60.Final-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a266524e-a149-5613-8dc9-0326bd297181",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-29025 is fixed in version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10571f10-773c-5753-a501-cd21edce868f",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47535 is fixed in version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9334e2d9-3d38-56e0-9510-15ac6497ae49",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24970 is fixed in version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68374c80-8b0c-5917-a90d-df5aa76ee2a8",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-25193 affects version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87a82b67-f32a-50a8-978d-f89c75828443",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55163 is fixed in version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ec13f90-be9e-5ff9-989b-9a25aa24b859",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58056 affects version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6866104-9ebf-5bf0-adc7-5c3eeebb2738",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58057 affects version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d012e3b9-d55d-5148-aef0-1c5a28db8b21",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59419 is fixed in version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:edc23fea-4243-530d-a0fa-400255dbc2fa",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-67735 is fixed in version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c541043-6bef-5b1f-9254-4983fda2b2d9",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72287f9b-0eee-5474-826e-1fdef7d9460c",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40d3f3dc-9884-5a55-9e7e-2a02ab474548",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p is fixed in version 4.1.60.Final-tuxcare.1 of io.netty:netty-codec-http2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-codec-http2@4.1.60.Final-tuxcare.1"
    }
  ]
}