{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e32f142d-ad4e-5127-b931-fb702fdb7721",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-codec-xml@4.1.58.Final-tuxcare.1",
      "type": "library",
      "group": "io.netty",
      "name": "netty-codec-xml",
      "version": "4.1.58.Final-tuxcare.1",
      "purl": "pkg:maven/io.netty/netty-codec-xml@4.1.58.Final-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:34506bad-d2fa-5ad3-8655-587405989f1a",
      "id": "CVE-2021-21290",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-21290 is fixed in version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-xml."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-xml@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0d8cb37-421f-56b6-b421-d843726d88b9",
      "id": "CVE-2021-21295",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-21295 is fixed in version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-xml."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-xml@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3590220-200e-5c22-90b0-13cc12bed1e4",
      "id": "CVE-2021-21409",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-21409 affects version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-xml."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-xml@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebd6ca07-770e-58ec-a87f-16ae7b051a64",
      "id": "CVE-2021-37136",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37136 is fixed in version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-xml."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-xml@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0018a71d-f856-5eab-b7df-98239e817c58",
      "id": "CVE-2021-37137",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37137 is fixed in version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-xml."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-xml@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ba1df6b-e967-59bf-9da9-1ff961dddd1f",
      "id": "CVE-2021-43797",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-43797 affects version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-xml."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-xml@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23ffd8c5-d8d4-5c7e-b8e7-2a9c477320f4",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24823 is fixed in version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-xml."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-xml@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a77f1bf-0b61-5dd1-afc6-6bbf0161667e",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41881 is fixed in version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-xml."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-xml@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:210afd76-c5be-5c1c-9cf4-8bf3dc87f391",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34462 is fixed in version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-xml."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-xml@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b3c9de2-ac0a-5799-b8c6-4ec3572358ad",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-xml."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-xml@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:626e4758-79be-598f-a1c5-e6d46e906cca",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-codec-xml 4.1.58.Final-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-xml@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13138d98-e13b-5d4b-b884-76929410bead",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-29025 affects version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-xml."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-xml@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41aafb02-704c-5b37-829a-3ab1c24d7a8b",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-47535 affects version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-xml."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-xml@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31422c04-2e39-5fd1-ad9c-01301d925785",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24970 is fixed in version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-xml."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-xml@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d01062b9-83a3-548b-9907-aba7103abd2b",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-25193 affects version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-xml."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-xml@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76cd71cc-2834-5ceb-beca-3b51dda5645a",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55163 affects version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-xml."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-xml@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2c50cf6-46f3-51c1-b429-4bc66b44c71b",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58056 affects version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-xml."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-xml@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86bdc724-4739-533b-a9d6-3342edd4cc30",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58057 affects version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-xml."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-xml@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b285e7c1-d71c-56b2-b2ba-85b7033d2c65",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59419 is fixed in version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-xml."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-xml@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ec93d7b-2919-586b-b452-f97e7a8b85a8",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67735 affects version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-xml."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-xml@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:418c8787-558e-5f6c-89e4-9152639743e0",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-xml."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-xml@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e646e89f-15be-5759-95bb-f040191f5f2a",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-xml."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-xml@4.1.58.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06ce0a77-b255-5429-b4f4-266df2b842e7",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p affects version 4.1.58.Final-tuxcare.1 of io.netty:netty-codec-xml."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-xml@4.1.58.Final-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-codec-xml@4.1.58.Final-tuxcare.1"
    }
  ]
}