{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:900f27b9-aa97-586d-8590-9e7e952d289d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/io.netty/netty-codec-http@4.1.52.Final-tuxcare.2",
      "type": "library",
      "group": "io.netty",
      "name": "netty-codec-http",
      "version": "4.1.52.Final-tuxcare.2",
      "purl": "pkg:maven/io.netty/netty-codec-http@4.1.52.Final-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:2ccd65e4-acc1-5fa1-bfc2-3487fb701e73",
      "id": "CVE-2021-21290",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-21290 is fixed in version 4.1.52.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.52.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f44544f9-72ad-5b08-bd1e-c1747fe5300c",
      "id": "CVE-2021-21295",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-21295 is fixed in version 4.1.52.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.52.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f893be4c-d55d-5c54-aa0c-49e1bb86dc4b",
      "id": "CVE-2021-21409",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-21409 is fixed in version 4.1.52.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.52.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f915aac3-c3c7-56f8-86d9-7227fbea8ab5",
      "id": "CVE-2021-37136",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37136 is fixed in version 4.1.52.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.52.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f22cafac-9fa9-55c4-8d73-7e79c2ef5592",
      "id": "CVE-2021-37137",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-37137 is fixed in version 4.1.52.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.52.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5852aebf-69c5-5fe8-9548-77a85524f3b9",
      "id": "CVE-2021-43797",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43797 is fixed in version 4.1.52.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.52.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02b7934d-de2c-51fa-8996-6c15bdd4316e",
      "id": "CVE-2022-24823",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24823 is fixed in version 4.1.52.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.52.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2378014e-2859-5fe7-b3c8-b746853c9b54",
      "id": "CVE-2022-41881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41881 is fixed in version 4.1.52.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.52.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6647ee39-241d-5b1a-849f-7baa52bfce01",
      "id": "CVE-2023-34462",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34462 is fixed in version 4.1.52.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.52.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e137f53-6a62-51f1-b20e-40cb903e7cc1",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 4.1.52.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.52.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9fc0a210-6149-5dbc-b913-4c037fa4f64d",
      "id": "CVE-2023-4586",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-4586 is a false positive for io.netty:netty-codec-http 4.1.52.Final-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.52.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe32cc45-b4ce-568c-9765-afb53c750732",
      "id": "CVE-2024-29025",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-29025 is fixed in version 4.1.52.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.52.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a1e728a-5789-5a49-ab67-86e1e891d8ca",
      "id": "CVE-2024-47535",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47535 is fixed in version 4.1.52.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.52.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60280789-aea8-52b4-b90d-21085d84a564",
      "id": "CVE-2025-24970",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24970 affects version 4.1.52.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.52.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a744f6b-db0c-542c-bc46-77466debd1c6",
      "id": "CVE-2025-25193",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-25193 affects version 4.1.52.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.52.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:264b91e4-45b8-5bed-a2eb-4f1ce277edc6",
      "id": "CVE-2025-55163",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55163 affects version 4.1.52.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.52.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57ab8502-fb4d-5c16-a9d8-45faa987ed61",
      "id": "CVE-2025-58056",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58056 is fixed in version 4.1.52.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.52.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01b13154-ed76-5702-9eaf-edf896a2128b",
      "id": "CVE-2025-58057",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58057 is fixed in version 4.1.52.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.52.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48e9ba67-de98-5bf2-b670-8647e9d5a6c8",
      "id": "CVE-2025-59419",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59419 is fixed in version 4.1.52.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.52.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2e8bc44-ecf6-579c-8a9b-2cedc7d2b18d",
      "id": "CVE-2025-67735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-67735 is fixed in version 4.1.52.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.52.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eea761f8-87b9-56b2-9005-92e55441dafe",
      "id": "CVE-2026-33870",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33870 affects version 4.1.52.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.52.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e3b3388-a93a-57b7-a3c0-a24e4a292915",
      "id": "CVE-2026-33871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33871 affects version 4.1.52.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.52.Final-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:352847b4-710f-55d5-a317-591ce2f686f6",
      "id": "GHSA-xpw8-rcwv-8f8p",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-xpw8-rcwv-8f8p is fixed in version 4.1.52.Final-tuxcare.2 of io.netty:netty-codec-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/io.netty/netty-codec-http@4.1.52.Final-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/io.netty/netty-codec-http@4.1.52.Final-tuxcare.2"
    }
  ]
}