{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:13eda5cd-7f4d-556a-a5f5-932195a110d6",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-coyote",
      "version": "9.0.50-tuxcare.11",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:4ecbdae8-d5e0-5513-89c5-776f2919e215",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-11996 does not affect version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote. Version 9.0.50 is not vulnerable. Summary: The target repository contains a functionally equivalent fix for CVE-2020-11996. While the implementation differs from the provided patch, it addresses the same performance issue using a more efficient approach with ConcurrentNavigableMap.subMap(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60872e40-e5e4-5e22-8cf6-d20591650b38",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abe14f3b-a8a4-58cc-bc35-04c6642e5896",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote. Version 9.0.50 is not vulnerable. Summary: Target repository already has the fix for CVE-2020-13943 applied. The maxConcurrentStreams check is correctly located in headersEnd() method, not in headersStart(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c749742a-c50c-583e-8df9-97e36c3f6370",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-9484 does not affect version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote. Fix already present in baseline since 9.0.35. Verified in java/org/apache/catalina/session/FileStore.java:303 \u2014 canonicalFile.toPath().startsWith(storageDir.getCanonicalFile().toPath()) containment check is in place. Advisory range 9.0.0.M1-9.0.34; 9.0.90 is well past the fix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d86d1e9c-9f6c-57cf-9aef-656a58685321",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5b849c6-46ac-5dc7-8d48-fb6ceb0fed80",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7be86bb5-2693-5340-9833-b9dc6e61ec2e",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c4da4bc-4688-541a-b81f-2c8e45ca951f",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a977547-80ce-5a2f-beb4-b4063819d4bf",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2f82961-5e08-57f2-b2f2-aa3728742e8d",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31886d16-22b3-544b-9403-ba24c688afb5",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd883dc1-2d81-5b0f-920c-c4c3be31129b",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52c8c67a-9ef3-5991-8636-62efdd058664",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-24998 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4bf367a-c3c0-534d-91ae-6c5cb71dcc77",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c75eff72-e46a-5584-aa8a-59b1feacd5fe",
      "id": "CVE-2023-28709",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28709 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2392b774-f910-5666-9309-89859e8d182a",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13651146-a983-52c3-9d1c-4790aee77f7a",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42795 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee9842b9-d7b7-5401-ad89-fd44ed59a48d",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11a26154-92ef-5019-8403-32a904ccefc6",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f06efc22-4e12-586a-bc59-1b213462590f",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-46589 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:973973cd-fabe-5823-924f-0d265af271d5",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:921b088f-fc6f-52ac-b306-b7217c3c8261",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc05ba61-abe2-56b1-8ddf-62a8b51614bf",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21b6adac-826a-502a-a4fe-bdfe447cf761",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99e48139-8b2b-5e21-9cbf-1991a612c6b3",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c90f6338-da93-5291-90a3-609de2b3d2cd",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a2d6a91-7d70-5e80-ba51-2502c9585b56",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ffbd0bb-248b-590e-b583-690efc58f443",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56337 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4272bae4-9382-5d51-a36c-ac17336b169e",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a8ebb5a-a2a8-5c48-96ec-abb03776b5c1",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-31650 does not affect version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote. 9.0.50 predates HTTP/2 RFC 9218 PRIORITY_UPDATE frame support (added in 9.0.76). Advisory range per NVD/Snyk/GHSA is 9.0.76-9.0.102. Code inspection confirms: Http2Parser.processFramePriorityUpdate method and priority parsing in Stream.emitHeader do not exist in this baseline. Vulnerable code path is absent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f90915e3-985e-5ae8-9093-7c43440a28e2",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01816341-4bcd-5a52-8a80-56384668d03a",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:881400ba-70ac-5d94-8b48-dd5fba017311",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0e3b44d-2da2-5b92-bd6b-af8b5be44b6e",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48989 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:754d1072-95b7-560f-be0a-d288b8d34121",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bce49021-979d-5d40-a840-1050e8fea0e3",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e13a562-dab2-568b-b021-0512a788fbf1",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82d3b5d0-e1b3-5dec-82a1-1bb9151a7b91",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3fc8345-92b7-55ce-b3f9-e5d9367f356f",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ff898a8-bfcf-5019-88cb-712a61ac5c8c",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df0abfeb-7db1-5976-9e1d-bf5d0903e372",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b37e1fa4-50fe-5ba3-87b3-cacde02104da",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9238557f-0afb-51b9-bc70-7d3bc4cc682d",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afcf5339-20b7-5cf4-a0b1-a6caf23f93f8",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d15e642-3cf0-53a6-b653-010315db0396",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb38e1c6-652f-5bee-8d57-1672008a7f66",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6311342a-0607-58d4-9ff7-d083fb41057d",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ba44dd2-a9d4-5576-9d98-e3e9975729d2",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb973b60-030e-5c2c-a201-a4c381682f51",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:271bbcb8-404d-5dbf-8fb4-84471c68b3e4",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92ae02bd-f849-5c97-b662-f421621ef6b6",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34486 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a7d2e0f-fe16-5d88-ae17-8ee390f32006",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bcb83364-8bba-5924-8a0b-4f50ed96bf48",
      "id": "CVE-2026-41284",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41284 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10a1cb67-7b3c-57ba-8cf0-2e7579e0cd7e",
      "id": "CVE-2026-41293",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41293 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:285de101-bab6-54cf-94b9-75edfa1450c4",
      "id": "CVE-2026-42498",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42498 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90279e36-9a3a-551f-a717-62c6282e2126",
      "id": "CVE-2026-43512",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43512 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8a6e545-475d-5fd5-9749-fedff6332f5f",
      "id": "CVE-2026-43513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43513 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61d87620-b36c-579a-9d82-a8feb3e7b44f",
      "id": "CVE-2026-43514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43514 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a36d452-f398-59fb-9da1-349cfd528d5c",
      "id": "CVE-2026-43515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43515 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.11"
    }
  ]
}