{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:7cd69cd7-eec2-52ea-b7f6-0a4cc36c06af",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-tarball@4.1.63.Final-tuxcare.1",
      "type": "library",
      "group": "io.netty",
      "name": "netty-tarball",
      "version": "4.1.63.Final-tuxcare.1",
      "purl": "pkg:maven/io.netty/netty-tarball@4.1.63.Final-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:45daa4a9-a25c-5b1d-85e8-e637e24eabc4",
      "id": "CVE-2021-37136",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37136 is fixed in version 4.1.63.Final-tuxcare.1 of io.netty:netty-tarball."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-tarball@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d156997-49dd-574d-b9c5-40595e1c4f88",
      "id": "CVE-2021-37137",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-37137 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-tarball."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-tarball@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:982087c9-b911-59fa-aadd-caac7fefa762",
      "id": "CVE-2021-43797",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-43797 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-tarball."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-tarball@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:837a7dc8-1d7f-566a-87c6-08f02738b2e4",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-24823 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-tarball."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-tarball@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7df3eb60-4d63-5721-8609-e11b7016af7d",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-41881 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-tarball."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-tarball@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b881b469-2b61-5f8f-a852-f80b5c4b57f3",
      "id": "CVE-2022-41915",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-41915 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-tarball."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-tarball@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2079f121-4ddc-57d9-99b7-f8a86014f639",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-34462 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-tarball."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-tarball@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fda563aa-9c18-5a13-bdc1-4c1fc07fbe70",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-tarball."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-tarball@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39c58650-b990-5380-9724-17e1405d3596",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-tarball 4.1.63.Final-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-tarball@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42e8bc6f-a60a-52c7-bf61-42b88d373422",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-29025 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-tarball."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-tarball@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3249a3cf-7844-5811-a8f5-71eea5f9abec",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-47535 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-tarball."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-tarball@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa58e0dd-2bed-5afe-8794-41e492463169",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24970 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-tarball."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-tarball@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5933142b-fe20-57de-b63a-3b7f77a4cc49",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-25193 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-tarball."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-tarball@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fa0a335-1083-5d24-bcfb-e85f952fe372",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55163 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-tarball."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-tarball@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1f049c7-fc71-59f6-89c4-e6a1207753ab",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58056 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-tarball."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-tarball@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04418c1a-de97-5510-b26e-46bc6c41de6e",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-58057 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-tarball."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-tarball@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40d0396b-7502-5e29-a9d0-16aff4a66a54",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59419 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-tarball."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-tarball@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29a9760a-b6f4-5af3-bc4a-6f209d9212d3",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67735 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-tarball."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-tarball@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d557a2d9-6319-5a2b-b47f-644b3a2a7272",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-tarball."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-tarball@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b1c31db-d3a2-5f50-96a2-7615c6604416",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-tarball."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-tarball@4.1.63.Final-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6d7fbf7-ceff-5798-bbf3-86eac39eb8a1",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p affects version 4.1.63.Final-tuxcare.1 of io.netty:netty-tarball."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-tarball@4.1.63.Final-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-tarball@4.1.63.Final-tuxcare.1"
    }
  ]
}