{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:01f29dba-e768-541d-8091-751cf8304923",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat",
      "version": "9.0.50-tuxcare.11",
      "purl": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:eeb5115e-15f1-5905-ba42-e0c8ea984200",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-11996 does not affect version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat. Version 9.0.50 is not vulnerable. Summary: The target repository contains a functionally equivalent fix for CVE-2020-11996. While the implementation differs from the provided patch, it addresses the same performance issue using a more efficient approach with ConcurrentNavigableMap.subMap(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f9ffcc3-99c0-5000-902c-5d9dd7e6a7f4",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1d5b9e7-761b-57aa-90ec-022e954e66b2",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat. Version 9.0.50 is not vulnerable. Summary: Target repository already has the fix for CVE-2020-13943 applied. The maxConcurrentStreams check is correctly located in headersEnd() method, not in headersStart(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d05304f5-dd0a-58c7-9145-69f8ec40c28b",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-9484 does not affect version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat. Fix already present in baseline since 9.0.35. Verified in java/org/apache/catalina/session/FileStore.java:303 \u2014 canonicalFile.toPath().startsWith(storageDir.getCanonicalFile().toPath()) containment check is in place. Advisory range 9.0.0.M1-9.0.34; 9.0.90 is well past the fix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:537e4799-5a1f-5c4c-96da-2cece72a49c8",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10c7db41-ec19-5f2d-a290-196b73a94a69",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3701743-dec5-542b-bd3e-da1f173629be",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f2da169-ba71-5e43-85f4-82ed749ec940",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6db2fe9f-0766-59a8-be8f-453bc4d18f19",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:437d3c76-d673-5b80-8db6-2e13502613c6",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78550a1b-bcc1-59c5-95c8-48b6d4880df0",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9cf9809-e752-5653-a45a-c9131613e7ce",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66db07f7-c44d-55fc-b544-d15503ed4490",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-24998 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16e33810-c4d5-5026-a6e1-1b59b7dc286c",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb547c02-fc22-5bf9-adbe-c45fdfbf67da",
      "id": "CVE-2023-28709",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28709 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8bccb52-3c91-5adf-ba43-01025e514bae",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5554eed3-d0f8-51a7-a47f-16e9eae91328",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42795 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0034c06c-38cf-5e02-bd2f-b65a423e7545",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d82855f8-3077-5027-8865-e422aaefc045",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3cfbd57f-5b8b-5ce8-b964-390ead3411a0",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-46589 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4489b0a0-2042-5682-93a2-afc15ed2407e",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69049ff8-cec3-588f-83df-155390370ff6",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b22de77e-845b-5615-a18b-09e132f953ef",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91905675-e626-516a-85e0-268bd98f90cc",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29f0622f-f181-52c0-a5bc-2b5aa2c04149",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abb89cea-6e2f-56b6-87f8-f707b80cded0",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7ede14c-ccab-5ac5-90c0-c69df3b57a6b",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6118c51-7c24-53b7-bb7d-96207984706c",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56337 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4509bdb0-c432-592e-ad84-8ef5c94a3dc1",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3c70dbc-d808-570e-9ee5-867a60e139c5",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-31650 does not affect version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat. 9.0.50 predates HTTP/2 RFC 9218 PRIORITY_UPDATE frame support (added in 9.0.76). Advisory range per NVD/Snyk/GHSA is 9.0.76-9.0.102. Code inspection confirms: Http2Parser.processFramePriorityUpdate method and priority parsing in Stream.emitHeader do not exist in this baseline. Vulnerable code path is absent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:556620be-43f6-5ca7-9012-686a62f8fc6c",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73c5f8bb-a8e6-522b-b8da-814f58e83dee",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d2bd0a4-ade2-55bc-9308-7fcef5212fcb",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:669a9b7f-b596-5c36-be26-a20ba1f35c51",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48989 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c837986f-6e3e-5f34-afaa-4c6d84fcc460",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:528e2333-cd6e-5bb7-bfd7-abc57462e18f",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fef518f3-5b7b-56db-9c33-d15dbba4ae5c",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b15db57-acf0-53e7-bd02-f4146e710b22",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2a854a2-6126-5287-b16c-9c7aabcecb26",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0b8d2da-a543-5a56-8824-5a8238d47e5c",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:796f500d-234b-53d2-939f-ecf903300abd",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4544439e-1115-5d61-b6b7-9a069dbcf555",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0df7615-e1b0-5725-b93f-d100e60a1c6d",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe2d4885-355e-55ff-8584-294c3ca98ce6",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ed98c17-ed51-56af-a666-e8352e4e3c70",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92c3ac66-75aa-5098-adcf-e0efa302ca6e",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e258797-88e4-55f0-b05f-fd26a06fb9c9",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74cb66ef-ecef-5cb9-bdfe-d13f9abbe4a0",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f326689f-7982-5d0f-a8dd-168918b4dd78",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0285e07-e594-5d8d-a005-9e59dd2935a4",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e357d92-44aa-52c1-8a71-717005d93e13",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34486 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ea42b31-9f9a-5d98-aa64-365a2c235614",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80ddceb7-dac8-5d88-985f-8c221f766f64",
      "id": "CVE-2026-41284",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41284 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:594c93ac-9c21-543a-b2e9-e4068cf13c63",
      "id": "CVE-2026-41293",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41293 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:427cc711-5a7c-511f-84fc-a3fad1ee75db",
      "id": "CVE-2026-42498",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42498 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fff87f15-73a7-568f-8001-f56c0eb8a0a0",
      "id": "CVE-2026-43512",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43512 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:992e8310-25c7-5fd5-a071-f913ca319438",
      "id": "CVE-2026-43513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43513 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04cbf544-13b1-53a4-8481-d9e5c79c3288",
      "id": "CVE-2026-43514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43514 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00a505a2-6892-5921-9bc9-1d4ace464323",
      "id": "CVE-2026-43515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43515 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.11"
    }
  ]
}