{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:24c0cde8-2b7e-5ce9-9614-39a0dab07718",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.48.Final-tuxcare.1",
      "type": "library",
      "group": "io.netty",
      "name": "netty-codec-smtp",
      "version": "4.1.48.Final-tuxcare.1",
      "purl": "pkg:maven/io.netty/netty-codec-smtp@4.1.48.Final-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:ffcbaf43-d3f5-50dc-ad05-770449803b70",
      "id": "CVE-2021-21290",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-21290 is fixed in version 4.1.48.Final-tuxcare.1 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.48.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff34177b-0a6b-5317-9e59-8ac7bbb51824",
      "id": "CVE-2021-21295",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-21295 affects version 4.1.48.Final-tuxcare.1 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.48.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4128d6a9-a089-5758-a7e9-b187d648f4a1",
      "id": "CVE-2021-21409",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-21409 affects version 4.1.48.Final-tuxcare.1 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.48.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0215298-05cf-5090-8a5a-96893a2ce414",
      "id": "CVE-2021-37136",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-37136 affects version 4.1.48.Final-tuxcare.1 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.48.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96bee73f-cccb-5d4b-9ba2-87f046d778d5",
      "id": "CVE-2021-37137",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37137 is fixed in version 4.1.48.Final-tuxcare.1 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.48.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e609313-c559-5112-8800-6c22c425c7a6",
      "id": "CVE-2021-43797",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-43797 affects version 4.1.48.Final-tuxcare.1 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.48.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8696d913-2111-5d9d-a4ae-a845e13c25ad",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-24823 affects version 4.1.48.Final-tuxcare.1 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.48.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13f5b905-0340-5483-9b6c-3d3ddf6401a6",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-41881 affects version 4.1.48.Final-tuxcare.1 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.48.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:407da3cb-2073-5283-91ab-da52babdff23",
      "id": "CVE-2022-41915",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-41915 affects version 4.1.48.Final-tuxcare.1 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.48.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b70b979d-94b9-5cc1-9c6b-63c3143e0f94",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-34462 affects version 4.1.48.Final-tuxcare.1 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.48.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed28c94d-42bc-5e58-97fa-924354e8da42",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 4.1.48.Final-tuxcare.1 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.48.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6867e70-bd11-59b4-812c-cdb58ed0516c",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-codec-smtp 4.1.48.Final-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.48.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:366bf711-b444-5dcb-8b1d-5e3e1be071bc",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-29025 affects version 4.1.48.Final-tuxcare.1 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.48.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:833803c8-002a-5d23-921f-3a1f4265f470",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-47535 affects version 4.1.48.Final-tuxcare.1 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.48.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22505332-a856-58fd-83e1-f79ae7cc6264",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24970 is fixed in version 4.1.48.Final-tuxcare.1 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.48.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d4ba55c-564d-5fe9-af5f-bacf84427017",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-25193 affects version 4.1.48.Final-tuxcare.1 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.48.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec039b8c-29b7-5bf0-b02d-d36e98da902e",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55163 affects version 4.1.48.Final-tuxcare.1 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.48.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8b75c86-dccf-5ac2-826f-d3d7f70e3e77",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58056 affects version 4.1.48.Final-tuxcare.1 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.48.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a6f5f09-c4d2-53ad-8b74-53848f5bfa4f",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58057 affects version 4.1.48.Final-tuxcare.1 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.48.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:996eb121-affd-528a-bc83-0a82c5e2f54f",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59419 affects version 4.1.48.Final-tuxcare.1 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.48.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ceab79f-4213-5166-b9d9-803193252cb8",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-67735 is fixed in version 4.1.48.Final-tuxcare.1 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.48.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1deef44-dcc7-57d3-98ae-59b191e94842",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.48.Final-tuxcare.1 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.48.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32cb70e2-ae84-5a6b-8acd-2942747f00cc",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.48.Final-tuxcare.1 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.48.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d5baffe-b65f-5fee-9f09-38f2fb1dc7ec",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p affects version 4.1.48.Final-tuxcare.1 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.48.Final-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.48.Final-tuxcare.1"
    }
  ]
}