{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:fc46c1d1-94d6-582e-b3ff-e979b7be0f4c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.63.Final-tuxcare.3",
      "type": "library",
      "group": "io.netty",
      "name": "netty-codec-smtp",
      "version": "4.1.63.Final-tuxcare.3",
      "purl": "pkg:maven/io.netty/netty-codec-smtp@4.1.63.Final-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:36bbf6fd-a828-5314-a2ea-3df434fad76d",
      "id": "CVE-2021-37136",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37136 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c581dc3e-a954-5a42-ab5e-4b33d4150438",
      "id": "CVE-2021-37137",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37137 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3dd6406-5aa9-56ff-bfcf-70d109257942",
      "id": "CVE-2021-43797",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43797 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02a04f28-1f4a-5d03-99d8-8a612423a55f",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24823 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b827799-7f41-517a-9aa2-704dfe35561e",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41881 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7966cab0-9b9e-5989-af5b-b2b0a4933485",
      "id": "CVE-2022-41915",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41915 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b790bfa5-ded9-54a3-b430-385769202420",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34462 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f073b050-73da-5663-88c3-22e46ceb9da1",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7643f831-cfa0-54e6-9a19-66ded72a1c25",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-codec-smtp 4.1.63.Final-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6141d40f-fa51-512b-84e0-8930025f06a0",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-29025 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f2cd433-34bc-519d-bcc7-8e813e10d775",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47535 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bf6ec5a-0a02-5396-a31c-7b950ab04aa8",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24970 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a9df619-063d-5b43-9bdf-f522c98f4957",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-25193 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ee86abf-44b6-5aa5-9d81-cfbd42e643bb",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55163 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1338f518-46ec-5fbd-ab5f-0da08c285da3",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58056 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30475fa2-a084-52ad-8275-789defe0a9cc",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58057 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e003f253-4048-551f-9298-9913395f66d4",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59419 is fixed in version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26879a2d-b019-5d73-8dab-dd88f95894ac",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67735 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac1265fc-7cdc-5c61-afc6-e2593f40435f",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7dc6a60-82fa-511c-91b0-0353d29c42be",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.63.Final-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95b1b159-3a68-5476-b775-e605d7fc5786",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p affects version 4.1.63.Final-tuxcare.3 of io.netty:netty-codec-smtp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.63.Final-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-codec-smtp@4.1.63.Final-tuxcare.3"
    }
  ]
}