{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d4e07393-f869-5534-8c55-05a9f0a874ad",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat",
      "version": "9.0.50-tuxcare.15",
      "purl": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:12762bcb-e85b-5276-b525-3e67162a48d1",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-11996 does not affect version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat. Version 9.0.50 is not vulnerable. Summary: The target repository contains a functionally equivalent fix for CVE-2020-11996. While the implementation differs from the provided patch, it addresses the same performance issue using a more efficient approach with ConcurrentNavigableMap.subMap(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfe9691b-5922-5c3c-8ac4-9d9b8b214ddc",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:111e4f8c-596f-504e-929e-073012cc230d",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat. Version 9.0.50 is not vulnerable. Summary: Target repository already has the fix for CVE-2020-13943 applied. The maxConcurrentStreams check is correctly located in headersEnd() method, not in headersStart(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52f9db3c-f683-500c-9a7b-8ad5ac128d42",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-9484 does not affect version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat. Fix already present in baseline since 9.0.35. Verified in java/org/apache/catalina/session/FileStore.java:303 \u2014 canonicalFile.toPath().startsWith(storageDir.getCanonicalFile().toPath()) containment check is in place. Advisory range 9.0.0.M1-9.0.34; 9.0.90 is well past the fix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0246dd2-1960-5f23-be3c-d4c72d32a8e7",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a38e11da-0c5e-555c-8cf8-ea11a50c513e",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3e17cca-36ac-561f-93a1-5a3eb82f2965",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc6459b8-d760-516c-b246-316e0d4a3412",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08abcc4c-0be1-55af-b2e7-99e9ca6214c0",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee9a9363-1ada-5e56-b8b9-8885443b25b8",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-34305 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47381280-7aca-57e3-8c61-6547f8368b2c",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21dac25a-45f8-51fe-b7d6-30e156903aee",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:883ddb10-36bc-5adf-bea9-afca001dc19e",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-24998 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55674c39-ca08-5908-a533-5c54d5a78526",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aceee8b3-1aa3-5731-b1be-4c507f1745b3",
      "id": "CVE-2023-28709",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28709 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1fee3c1-b131-54a8-ac90-34936bca3b04",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10dfdc6d-b098-522d-8d8a-6e6189fe8b94",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42795 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d324b17-de02-5b85-9b1e-8946bd0b836c",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2c7adbf-2851-52da-b825-3c7a6ad5309d",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:234568a2-1b99-5260-9c51-d3064aa1bbe6",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-46589 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:605fbb09-13cc-544c-affd-e7a1544f8bb1",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53e7b7c5-244f-5c23-aeb5-626716d7a87c",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3696835-2db6-59c4-9814-6c923d9ca9af",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c1da34c-fa98-540d-be80-eb83973ae1a2",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ecbbfce7-802c-5a45-a027-96c67c34bc26",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76db6dfa-39ea-571e-a797-f032b6710128",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e086252-71ae-589e-96c9-877e9e7d81fa",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a42d834f-b368-5188-aa1f-e26ba23083e8",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b53efbe-b5cf-5759-94fd-1c56343cb41c",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a2313a9-2bd7-52b9-991b-1dddbd5b63b3",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-31650 does not affect version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat. 9.0.50 predates HTTP/2 RFC 9218 PRIORITY_UPDATE frame support (added in 9.0.76). Advisory range per NVD/Snyk/GHSA is 9.0.76-9.0.102. Code inspection confirms: Http2Parser.processFramePriorityUpdate method and priority parsing in Stream.emitHeader do not exist in this baseline. Vulnerable code path is absent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7ce5afc-5a94-5223-81f5-86af5606f9ac",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc6773bf-d718-54f5-a102-1b332eb921b1",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ef3e6b6-4dd9-596c-9ad4-138af5efcf66",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f22b2950-60f8-5460-85d9-c2d69a4f2f3b",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24a79987-84ca-5d6a-9889-22e5ad790c76",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:466432d9-4a98-5427-92df-b4e7a9e5e6ef",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce6dbe44-44a0-5a19-8bea-ab0d04a9635a",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0c6fba6-7aee-52f7-8a5c-9a3a529b2899",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:849a5190-db5e-5702-96f3-bb67ef228d40",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc657979-fbd5-552c-89e0-a2ccc04849cb",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a004066e-aa5a-54a0-9e41-2368caf1e046",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e10a465-68cb-5447-bb61-c664e6db9c52",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d03dad7-4e8e-513f-99a9-75e3cf3978db",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cedd09e0-73c0-52a9-b8b8-a9a0e3b5d3cd",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de716b4d-1e77-5c93-ae93-182b36f9a3ca",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c776217-43b5-515e-9ceb-e29e53adbfc6",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86bd339d-92b5-58bb-ace6-e13bb28e375a",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1bf71dc-0ebc-5a8c-a215-4c54a47f54d4",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b91c9e7a-2416-5582-92ce-658499a199f6",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c05d3a70-9a52-5b6c-aa75-b688ae0eb41a",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1e7f90c-0e87-5d9b-b022-5ed860cc5696",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34486 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:068bde89-72c8-52f7-8bb5-d0000244636d",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e39e2784-101f-52c6-887c-52b434c2136c",
      "id": "CVE-2026-41284",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41284 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a473164-daa0-5c3c-a16a-5e1990c8aadb",
      "id": "CVE-2026-41293",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41293 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3153605c-a06b-53f8-8d09-8aaac60d9834",
      "id": "CVE-2026-42498",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42498 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bad2b4a-d122-57e3-aebc-21d96f45718b",
      "id": "CVE-2026-43512",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43512 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf812d18-2a08-56ee-8e19-503c579af1e8",
      "id": "CVE-2026-43513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43513 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e23f5b67-2395-54d6-aa84-52442aa2dbb0",
      "id": "CVE-2026-43514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43514 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2225fb4-499f-5167-a7e5-041b53dc7d59",
      "id": "CVE-2026-43515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43515 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.15"
    }
  ]
}