{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:24b891e0-2256-5320-8c47-730a84d11412",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8",
      "type": "library",
      "group": "org.apache.tika",
      "name": "tika-fetcher-http",
      "version": "2.9.4-tuxcare.8",
      "purl": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:bdf5891f-82fa-5e5a-95af-e4864c261be9",
      "id": "CVE-2012-6612",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2012-6612 does not affect version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http. Version 2.9.4 is not affected by CVE-2012-6612: the security fix is already present in the target branch. Momus prerequisite check: \"All 7 patch commits already exist in target branch\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10c676d7-bc62-5c02-bd21-7746a21118f8",
      "id": "CVE-2013-6397",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6397 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d354240-38eb-55a5-86c1-648513d47aa8",
      "id": "CVE-2013-6407",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2013-6407 does not affect version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http. Version 2.9.4 is not affected by CVE-2013-6407: the security fix is already present in the target branch. Momus prerequisite check: \"All 4 patch commits already exist in target branch\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8495c09-b081-5410-8b89-37ad70a49c91",
      "id": "CVE-2013-6408",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6408 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37dc6627-586e-5932-8056-b80bb3b00964",
      "id": "CVE-2015-3414",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-3414 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa4a6119-0f0c-564f-af6f-eec64d21256e",
      "id": "CVE-2015-3415",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-3415 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:185e04cc-72d9-5f0f-8e86-18c4a445e94b",
      "id": "CVE-2015-3416",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-3416 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ba5e52c-84e6-5c00-98ae-d144984bd951",
      "id": "CVE-2015-3717",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-3717 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5e8950f-1822-570b-8d23-907cfc8a0bd0",
      "id": "CVE-2015-5895",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-5895 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:078ba766-ff81-52ba-943e-76a4544d7b33",
      "id": "CVE-2015-6607",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-6607 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2b5dc47-731b-5ecf-ae45-8018bda4e65d",
      "id": "CVE-2015-8795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-8795 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e532ad9b-cfcc-5428-9d39-8f95561fed9a",
      "id": "CVE-2015-8796",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-8796 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ab8e346-94c3-5b5d-8455-b9cfd1446d00",
      "id": "CVE-2015-8797",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-8797 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0d46f3a-4c6c-52cd-812d-6460cc25f0c4",
      "id": "CVE-2016-6153",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-6153 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d22a69cc-e657-5c99-9bd2-33c27d3009da",
      "id": "CVE-2017-10989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-10989 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74affa0e-2f03-531a-b1dd-1452e94ff062",
      "id": "CVE-2017-3163",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-3163 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2818c6f6-dd6b-549d-ada6-b87cfad7f910",
      "id": "CVE-2017-3164",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-3164 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:935dac3c-2f23-5368-9abd-c02f42145ea6",
      "id": "CVE-2018-11802",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2018-11802 does not affect version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http. Version 2.9.4 is not affected by CVE-2018-11802: the security fix is already present in the target branch. Momus prerequisite check: \"Patches already applied: 302f22aff7a836868b270038e1d66002a2004869\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1666e3eb-ee56-581e-947a-cff55df891b3",
      "id": "CVE-2018-1308",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-1308 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab454dc3-cd70-5d6d-a06f-3b61d496e1fa",
      "id": "CVE-2018-20346",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-20346 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b69064a-db32-5cb6-b1a9-9457ce15a448",
      "id": "CVE-2018-20505",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-20505 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6444dd9a-0bed-50fd-aba0-fe203b286415",
      "id": "CVE-2018-20506",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-20506 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11fb7855-20f0-51d5-baae-a7840b3a097e",
      "id": "CVE-2018-8740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-8740 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:baf038ba-9022-556a-8bbb-9130202cf9eb",
      "id": "CVE-2019-0193",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2019-0193 does not affect version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http. Version 2.9.4 is not affected by CVE-2019-0193: the security fix is already present in the target branch. Momus prerequisite check: \"Patches already applied: 1b81d200e8ffb882276264618c9004ba4bf72ecb\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ed5e59d-e99b-5893-92fb-662bbe73e692",
      "id": "CVE-2019-19645",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-19645 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33e22037-4aea-5ed7-bcd1-35af81b8565d",
      "id": "CVE-2019-19646",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-19646 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d594507-55b3-5dff-8388-385b3c3b46cf",
      "id": "CVE-2020-11655",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11655 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14171a5f-2a86-555b-bad0-a486659dc95b",
      "id": "CVE-2020-11656",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11656 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75cb1342-730d-5c32-b953-bfbf101b704a",
      "id": "CVE-2020-13434",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13434 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bff0c24b-d91d-5a5b-99d0-cc20283cc3ad",
      "id": "CVE-2020-13435",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13435 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:235bff2f-708f-56e0-a1c6-6afa77b720d8",
      "id": "CVE-2020-13630",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13630 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56592602-263b-5478-bbd1-83ee3a4bfaa7",
      "id": "CVE-2020-13631",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13631 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4204bbf5-38a0-5466-9f16-aac92f3a7549",
      "id": "CVE-2020-13632",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13632 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eeeeb826-edf5-54dd-977f-a6726576b052",
      "id": "CVE-2020-13941",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13941 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05569fb1-bf5e-5830-9a83-7058df408143",
      "id": "CVE-2020-15358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-15358 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f287dfc3-9155-5125-89c4-159eee997b67",
      "id": "CVE-2021-27905",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-27905 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87a152a9-2865-5514-a48b-41ef26bb1847",
      "id": "CVE-2021-29262",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-29262 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b67ff0d-e56c-587c-8803-b6a3d4642748",
      "id": "CVE-2021-29943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-29943 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10071ddc-e23c-5425-acd5-9a254a9f5c94",
      "id": "CVE-2021-44548",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-44548 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:708cbb54-6363-5e38-8bdd-d83f75a74634",
      "id": "CVE-2022-35737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-35737 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1242673-e293-5ca9-8e79-371fb20d7ad5",
      "id": "CVE-2023-34610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34610 is fixed in version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5900a03a-9344-5efc-952d-e18c7af07f06",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:078bb668-93af-5338-afbb-1af79a62190b",
      "id": "CVE-2023-7104",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-7104 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff9b9e11-a76c-5f39-9c79-539aa1718d67",
      "id": "CVE-2024-31141",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-31141 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33605cf7-667b-58c3-b038-f80c9349c37c",
      "id": "CVE-2024-56128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56128 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6104f5c-ea9a-5667-a81d-0c0b326d04aa",
      "id": "CVE-2025-27819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27819 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9d86723-1476-5b37-9b35-ea936c47e352",
      "id": "CVE-2025-54988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-54988 is fixed in version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a4d8bc9-7037-53bf-9e60-14050ba04887",
      "id": "CVE-2025-66516",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66516 is fixed in version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9ab0abc-ab2d-5ea2-a2c0-5470a0d4aad0",
      "id": "CVE-2026-66755",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-66755 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-fetcher-http."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tika/tika-fetcher-http@2.9.4-tuxcare.8"
    }
  ]
}