{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:8de4b4e8-2c17-51d3-9acd-003ab3c57794",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1",
      "type": "library",
      "group": "io.netty",
      "name": "netty-codec-mqtt",
      "version": "4.1.49.Final-tuxcare.1",
      "purl": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:521bf018-c935-5d40-a6e9-7b732eddf91c",
      "id": "CVE-2021-21290",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-21290 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9eb7c4aa-97df-5f0b-af95-8e568f73b391",
      "id": "CVE-2021-21295",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-21295 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2831daae-ba03-5692-ae4b-16d19160edbd",
      "id": "CVE-2021-21409",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-21409 is fixed in version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26211e63-e962-5aec-845b-b21f741f7313",
      "id": "CVE-2021-37136",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37136 is fixed in version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7577dd5-806d-5a68-933b-4b29f3dfbf98",
      "id": "CVE-2021-37137",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37137 is fixed in version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:175777fa-ddaa-58a8-81cf-ea26c6e0360b",
      "id": "CVE-2021-43797",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43797 is fixed in version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b769fc5b-2557-5c7b-9b67-d4f9a2ca2c70",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24823 is fixed in version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce16b6c1-1e31-50df-aa32-d08256352502",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-41881 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f158ad9e-d947-5a10-bf43-008af1be8b32",
      "id": "CVE-2022-41915",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-41915 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8370610-b2ef-5722-9fdf-b1012ae2b5af",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34462 is fixed in version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d93d68c-91fc-5628-aca9-0b629aecd2ed",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96ec54b1-1136-5e50-9fd9-a5565f7efdd6",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-codec-mqtt 4.1.49.Final-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:649b39dd-f88b-5af1-ba92-00cc59e71732",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-29025 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7270f2ef-c92b-5bc2-be59-d5fb0a2497c4",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-47535 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a1eeb29-74b3-5490-9782-8d3297820465",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24970 is fixed in version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64af8639-ed3b-56b5-94a0-3f92d466674d",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-25193 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15f6affc-5810-5fb8-a57c-08dc75bcca27",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55163 is fixed in version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43ac2fe3-bfbe-52a7-9ebb-b5363bcfd268",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58056 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51f82061-5b4d-5ec4-a6a3-01e5997e3db5",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58057 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c88a5e83-1d2a-5a09-abd6-64657b124a99",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59419 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa4f6bba-75a5-52cd-b91e-108d4d4c7f60",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67735 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a039fa4a-6aaa-55ba-bdeb-e5a6f9343952",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07a79bf4-e3ec-56d0-b611-57f1f5419569",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6cda7ba-e041-56fc-9730-83c9ce015e37",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p affects version 4.1.49.Final-tuxcare.1 of io.netty:netty-codec-mqtt."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-codec-mqtt@4.1.49.Final-tuxcare.1"
    }
  ]
}