{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:40755951-7200-54b6-8a69-3e19d61b6898",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.115.Final-tuxcare.1",
      "type": "library",
      "group": "io.netty",
      "name": "netty-codec-stomp",
      "version": "4.1.115.Final-tuxcare.1",
      "purl": "pkg:maven/io.netty/netty-codec-stomp@4.1.115.Final-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:7a5afd0a-5612-5d2d-bb50-1fbc41e8bb8c",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24970 is fixed in version 4.1.115.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.115.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de74b1da-d938-5073-b33b-3c26cfb315f1",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-25193 affects version 4.1.115.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.115.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:964e3c78-268e-563f-9b76-fa08086253a6",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55163 affects version 4.1.115.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.115.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:883410e3-c677-52e1-a9ca-cd15ddcdb77a",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58056 affects version 4.1.115.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.115.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5767ff6c-b00b-5290-a9aa-b9a8fa058a7b",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58057 affects version 4.1.115.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.115.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6936d1de-ec8d-5a0f-86e0-6fff6d86cb41",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59419 affects version 4.1.115.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.115.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31608678-8621-5b66-9d0c-b84b299c3400",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67735 affects version 4.1.115.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.115.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b04f542c-fbff-5cb4-8a57-ebdbe1fd95ff",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.115.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.115.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76b768d3-78aa-58bb-941d-b2a9d6b1ba35",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.115.Final-tuxcare.1 of io.netty:netty-codec-stomp."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.115.Final-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-codec-stomp@4.1.115.Final-tuxcare.1"
    }
  ]
}