{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:cddca47a-a7f6-57da-991d-4007298e8c5c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8",
      "type": "library",
      "group": "org.apache.tika",
      "name": "tika-httpclient-commons",
      "version": "2.9.4-tuxcare.8",
      "purl": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:ea459d25-8c7c-5f9f-8ed1-c499ba7637b4",
      "id": "CVE-2012-6612",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2012-6612 does not affect version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons. Version 2.9.4 is not affected by CVE-2012-6612: the security fix is already present in the target branch. Momus prerequisite check: \"All 7 patch commits already exist in target branch\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97c77b18-f9ac-5e31-bb74-25df1c628f95",
      "id": "CVE-2013-6397",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6397 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89940e5b-a07b-5bfa-ada8-b06ec2b68186",
      "id": "CVE-2013-6407",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2013-6407 does not affect version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons. Version 2.9.4 is not affected by CVE-2013-6407: the security fix is already present in the target branch. Momus prerequisite check: \"All 4 patch commits already exist in target branch\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b15f38db-c281-5ad8-8c2f-06442494dca1",
      "id": "CVE-2013-6408",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6408 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57c9bd5a-f0fe-5638-8cbc-f6fd94acd82d",
      "id": "CVE-2015-3414",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-3414 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09c12756-9d85-545f-8da6-0ac11a5801a9",
      "id": "CVE-2015-3415",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-3415 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa9dde76-50b5-5441-b3b2-761915c08bae",
      "id": "CVE-2015-3416",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-3416 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ff00a9d-4b0a-5ef8-b95c-9d68784d001f",
      "id": "CVE-2015-3717",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-3717 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e98b27c-a7de-5ea6-8d6d-5f54f603ed60",
      "id": "CVE-2015-5895",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-5895 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e61656e7-dfb3-5a8c-8e26-fdf1fc7775af",
      "id": "CVE-2015-6607",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-6607 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85955a84-6576-5d20-b9ee-92ea73b59e04",
      "id": "CVE-2015-8795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-8795 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f269379-836b-59d2-a12f-b3261c4d032f",
      "id": "CVE-2015-8796",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-8796 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d06844b9-cbc7-50c0-9613-962f4c3ce3e8",
      "id": "CVE-2015-8797",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-8797 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:416c0b31-01d9-5253-8f93-089e19e123a8",
      "id": "CVE-2016-6153",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-6153 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:968cede8-0425-53a4-a1b7-b4e886b47c7b",
      "id": "CVE-2017-10989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-10989 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4131d7b6-844e-565c-9f31-02956f743972",
      "id": "CVE-2017-3163",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-3163 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7d20dcf-0aa3-5c53-a3e3-d21ae8991dfe",
      "id": "CVE-2017-3164",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-3164 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c5bf51b-4278-5001-a3a8-2e24d8b13324",
      "id": "CVE-2018-11802",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2018-11802 does not affect version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons. Version 2.9.4 is not affected by CVE-2018-11802: the security fix is already present in the target branch. Momus prerequisite check: \"Patches already applied: 302f22aff7a836868b270038e1d66002a2004869\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d48ba340-3f4a-51be-86b9-8549b491c3e6",
      "id": "CVE-2018-1308",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-1308 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb3665e5-38d4-5b3b-b55a-1393445bbe9e",
      "id": "CVE-2018-20346",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-20346 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a16e7250-e55a-5d62-bb51-02e9007c6532",
      "id": "CVE-2018-20505",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-20505 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:765897ab-a334-5c36-8f18-f045413b382c",
      "id": "CVE-2018-20506",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-20506 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c3aa5e4-ec97-50d9-aca1-3b094cb30f84",
      "id": "CVE-2018-8740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-8740 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:757e6e18-6ece-5746-978f-59b55af089d1",
      "id": "CVE-2019-0193",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2019-0193 does not affect version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons. Version 2.9.4 is not affected by CVE-2019-0193: the security fix is already present in the target branch. Momus prerequisite check: \"Patches already applied: 1b81d200e8ffb882276264618c9004ba4bf72ecb\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:282beb6d-f90f-5d96-9283-1b0da8deda60",
      "id": "CVE-2019-19645",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-19645 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62932312-3dbd-5af0-898f-1f61ced82001",
      "id": "CVE-2019-19646",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-19646 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4571377d-e738-5e56-a64a-565c54f641ed",
      "id": "CVE-2020-11655",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11655 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fea21dd-c119-545f-aab6-457265514f0d",
      "id": "CVE-2020-11656",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11656 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:508de24d-8067-5e54-b43a-3ed50aef0762",
      "id": "CVE-2020-13434",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13434 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72eec78f-5ede-5039-8d6d-d8fe9c1cc88f",
      "id": "CVE-2020-13435",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13435 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ea27360-ec82-5ba1-a9bb-ae8bd998ad0c",
      "id": "CVE-2020-13630",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13630 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d33a20e1-ea5c-57d7-b3c5-658d7d355294",
      "id": "CVE-2020-13631",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13631 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c37a826-6577-5788-a678-cd8dc49e31a4",
      "id": "CVE-2020-13632",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13632 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb476e44-64a2-5f7f-bbb0-c898d833adb6",
      "id": "CVE-2020-13941",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13941 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04469938-c93c-57d9-a2cd-de5115e1f7c5",
      "id": "CVE-2020-15358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-15358 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27416645-ff96-579e-90b9-400a7e678204",
      "id": "CVE-2021-27905",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-27905 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8f4b533-1592-58ea-a57f-87b941acd41f",
      "id": "CVE-2021-29262",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-29262 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb5498b8-cf25-5fdc-ab6f-bc340e08d61c",
      "id": "CVE-2021-29943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-29943 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b814ef0a-d587-59a0-bcce-787cff8d99da",
      "id": "CVE-2021-44548",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-44548 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:484742cd-b438-51d6-92d9-d137a0b89206",
      "id": "CVE-2022-35737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-35737 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd1fe5a6-28bb-506b-b1e5-f010726a02e4",
      "id": "CVE-2023-34610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34610 is fixed in version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35a81a65-2e44-58d7-89d1-77d2092e3620",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db18c262-d3a9-55a7-aa00-f1c07cb096f5",
      "id": "CVE-2023-7104",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-7104 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:337a359e-dbf9-5102-a6da-ab9d2a15e1a9",
      "id": "CVE-2024-31141",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-31141 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57ddad75-78b2-5b24-a8a6-d5ba5c786064",
      "id": "CVE-2024-56128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56128 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:faf2f42a-c37a-5802-8f7d-f9ca5bcf3120",
      "id": "CVE-2025-27819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27819 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:862acefc-e3e9-52fc-a55e-253c08bbe518",
      "id": "CVE-2025-54988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-54988 is fixed in version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b3e7228-d979-5864-a8fd-b790c368986a",
      "id": "CVE-2025-66516",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66516 is fixed in version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4600ba5a-5963-5842-b77f-14729a6b9818",
      "id": "CVE-2026-66755",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-66755 affects version 2.9.4-tuxcare.8 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.8"
    }
  ]
}