{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:1d8abddb-192c-5479-b2c4-c437bed176b9",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9",
      "type": "library",
      "group": "org.apache.tika",
      "name": "tika-httpclient-commons",
      "version": "2.9.4-tuxcare.9",
      "purl": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:fc84dd62-0001-5cb8-80b1-a1757166675f",
      "id": "CVE-2012-6612",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2012-6612 does not affect version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons. Version 2.9.4 is not affected by CVE-2012-6612: the security fix is already present in the target branch. Momus prerequisite check: \"All 7 patch commits already exist in target branch\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40a9dc2b-175b-53a1-acfe-02d60393af28",
      "id": "CVE-2013-6397",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6397 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d83970c1-e33f-5f10-84b9-c8c88d26c832",
      "id": "CVE-2013-6407",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2013-6407 does not affect version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons. Version 2.9.4 is not affected by CVE-2013-6407: the security fix is already present in the target branch. Momus prerequisite check: \"All 4 patch commits already exist in target branch\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1e32e6f-b50c-5231-a245-c09e582f14e4",
      "id": "CVE-2013-6408",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6408 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1a356fb-be47-56b2-b343-d0d3d7463b00",
      "id": "CVE-2015-3414",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-3414 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9bf0dc2-f2a9-56b1-9e7e-5413c9fdf753",
      "id": "CVE-2015-3415",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-3415 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab357600-faa5-58aa-a47f-7abded68d241",
      "id": "CVE-2015-3416",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-3416 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db11fea6-1a5e-54c6-99d2-5e7e497bef88",
      "id": "CVE-2015-3717",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-3717 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3cb5cde7-4951-54b4-a3ae-f51b57a161df",
      "id": "CVE-2015-5895",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-5895 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41b40e06-1f51-574d-b155-10398ba9d89c",
      "id": "CVE-2015-6607",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-6607 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:735e20c4-b20e-5862-9d90-10dcba35a644",
      "id": "CVE-2015-8795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-8795 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d08d6da-d2e1-5634-9cb4-7d0fc602484a",
      "id": "CVE-2015-8796",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-8796 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6738ec30-2a27-5953-be02-e25c8f4378eb",
      "id": "CVE-2015-8797",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-8797 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdd42c2b-b373-586e-a415-dcfbeb1c8af3",
      "id": "CVE-2016-6153",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-6153 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:218f08e3-156e-5ced-8947-0169e7a19712",
      "id": "CVE-2017-10989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-10989 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4a19da0-4c53-5c26-a137-b4107dd2c1a0",
      "id": "CVE-2017-3163",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-3163 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:934919ee-d6ec-593e-a6d7-f521cbe68749",
      "id": "CVE-2017-3164",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-3164 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a1dbe5a-e689-5f54-81b3-0cc51a8c14ec",
      "id": "CVE-2018-11802",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2018-11802 does not affect version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons. Version 2.9.4 is not affected by CVE-2018-11802: the security fix is already present in the target branch. Momus prerequisite check: \"Patches already applied: 302f22aff7a836868b270038e1d66002a2004869\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a81bbafd-8c0b-5797-8a5e-4e42c23964da",
      "id": "CVE-2018-1308",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-1308 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63dcaff7-58b3-5a7b-9e23-de356a3e6729",
      "id": "CVE-2018-20346",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-20346 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bd47d17-843c-50d4-8266-127b05a1701b",
      "id": "CVE-2018-20505",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-20505 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19892f97-978b-5198-b836-44a04b311d01",
      "id": "CVE-2018-20506",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-20506 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2ba5e73-0038-58ff-b404-16395cf908c1",
      "id": "CVE-2018-8740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-8740 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:755973a0-0e45-56dd-b2ab-ccfe233e2301",
      "id": "CVE-2019-0193",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2019-0193 does not affect version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons. Version 2.9.4 is not affected by CVE-2019-0193: the security fix is already present in the target branch. Momus prerequisite check: \"Patches already applied: 1b81d200e8ffb882276264618c9004ba4bf72ecb\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93484884-bd17-51bc-b1f2-e97aea0e8421",
      "id": "CVE-2019-19645",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-19645 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de86f006-8a56-50f1-9cb6-f65428a6d676",
      "id": "CVE-2019-19646",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-19646 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd3f881b-130d-5009-94ca-8ad61e0e4872",
      "id": "CVE-2020-11655",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11655 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fea24f6c-37cb-567d-9328-f56daca14c90",
      "id": "CVE-2020-11656",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11656 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08bfb8e9-7050-5abf-ad97-76e5cdf5e2cf",
      "id": "CVE-2020-13434",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13434 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b64e835-5360-5add-883f-4c8ee8784ac3",
      "id": "CVE-2020-13435",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13435 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:215ed40b-6474-5022-8d70-94bfbf73044a",
      "id": "CVE-2020-13630",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13630 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e6dc355-b361-544c-a4e9-69c8bebc40a4",
      "id": "CVE-2020-13631",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13631 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7582800a-a5af-56f0-9495-44988ff09ab9",
      "id": "CVE-2020-13632",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13632 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d83baea-82d1-5059-9870-33ab2033515d",
      "id": "CVE-2020-13941",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13941 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e85066d1-b284-5de3-90d1-364e8eab93b7",
      "id": "CVE-2020-15358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-15358 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:300f88b4-be0d-510e-b09b-48e1e3c95a4e",
      "id": "CVE-2021-27905",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-27905 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50a60b49-2df6-5e62-bc20-2b8e46080fe0",
      "id": "CVE-2021-29262",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-29262 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8d44c02-0b97-507c-8107-9752c66cc2db",
      "id": "CVE-2021-29943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-29943 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:991acade-2151-532b-8e57-86351ff397d8",
      "id": "CVE-2021-44548",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-44548 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:886fc29b-3bb3-57e5-8e31-4999ca6de7e9",
      "id": "CVE-2022-35737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-35737 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6cb0594-4dcd-51ec-9002-390126756cac",
      "id": "CVE-2023-34610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34610 is fixed in version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:611a15f5-a742-5951-bc90-b09e7f125814",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:303f6129-7016-507c-9ca0-fc5654a04e58",
      "id": "CVE-2023-7104",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-7104 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b438cee-1f93-5f89-b9e8-4bb20f840c82",
      "id": "CVE-2024-31141",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-31141 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10c58b42-998c-5ea7-bf09-807d9a89ac13",
      "id": "CVE-2024-56128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56128 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5cb01b8-6f10-53e1-aa66-f4b2ac257b18",
      "id": "CVE-2025-27819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27819 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bccac49a-8ecc-5076-83d6-e9933e811b61",
      "id": "CVE-2025-54988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-54988 is fixed in version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcc49c82-c8ec-5c1a-bf28-73853d7059df",
      "id": "CVE-2025-66516",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66516 is fixed in version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b361480e-7a5f-59ce-86a1-9c5dd4970d44",
      "id": "CVE-2026-66755",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-66755 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-httpclient-commons."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tika/tika-httpclient-commons@2.9.4-tuxcare.9"
    }
  ]
}