{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ddf45c4b-0bd3-5f78-a86d-a21c2a5df16b",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9",
      "type": "library",
      "group": "org.apache.tika",
      "name": "tika-serialization",
      "version": "2.9.4-tuxcare.9",
      "purl": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:3010c318-966f-5e12-a535-c05f0373dcfa",
      "id": "CVE-2012-6612",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2012-6612 does not affect version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization. Version 2.9.4 is not affected by CVE-2012-6612: the security fix is already present in the target branch. Momus prerequisite check: \"All 7 patch commits already exist in target branch\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:409467b0-f60c-500b-ae59-a88b5aec36db",
      "id": "CVE-2013-6397",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6397 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12ab7818-9255-5ced-81a2-9e0e436af603",
      "id": "CVE-2013-6407",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2013-6407 does not affect version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization. Version 2.9.4 is not affected by CVE-2013-6407: the security fix is already present in the target branch. Momus prerequisite check: \"All 4 patch commits already exist in target branch\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73fe107e-02d0-5998-8726-be8359954f35",
      "id": "CVE-2013-6408",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6408 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2a97f01-c664-5db3-bd92-888086bd82f5",
      "id": "CVE-2015-3414",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-3414 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a4a9e65-4408-5a71-9042-58f0c3b93b1c",
      "id": "CVE-2015-3415",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-3415 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4df9d4e-cde5-5418-aad1-73d334169573",
      "id": "CVE-2015-3416",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-3416 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0446b67b-abca-5897-abe8-e86a8b7b9509",
      "id": "CVE-2015-3717",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-3717 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86d06900-e30a-55e7-8db0-8a880610ed96",
      "id": "CVE-2015-5895",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-5895 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf5f9ef5-a929-5c11-8ba0-beaee151adc7",
      "id": "CVE-2015-6607",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-6607 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe55ac86-b87f-5e9c-a9fd-4b3932ff175d",
      "id": "CVE-2015-8795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-8795 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4755215f-85a2-522c-93de-46d1183a57ee",
      "id": "CVE-2015-8796",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-8796 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5152eaff-b725-5ec4-83f9-05fbfb17e174",
      "id": "CVE-2015-8797",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-8797 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8c887d7-fdf1-55b4-9613-9ad6c114ebd1",
      "id": "CVE-2016-6153",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-6153 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:114b7611-a352-5308-84e5-397cfddfcb12",
      "id": "CVE-2017-10989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-10989 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08b4e9d2-7e32-51c9-afc7-2801dc49613a",
      "id": "CVE-2017-3163",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-3163 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9520e94-0b81-54de-8199-922a7e339d15",
      "id": "CVE-2017-3164",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-3164 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e8ae4e9-3e99-5663-861b-c47d94f45fde",
      "id": "CVE-2018-11802",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2018-11802 does not affect version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization. Version 2.9.4 is not affected by CVE-2018-11802: the security fix is already present in the target branch. Momus prerequisite check: \"Patches already applied: 302f22aff7a836868b270038e1d66002a2004869\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e9075db-6c68-5408-9cb5-ee4aa813bff0",
      "id": "CVE-2018-1308",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-1308 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6c1d1c5-4849-55d8-ac71-079f75a0f617",
      "id": "CVE-2018-20346",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-20346 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62b7d69d-15a4-5843-ac75-208a1335f798",
      "id": "CVE-2018-20505",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-20505 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f71453e-0699-5ae5-9046-b6fd67a1707c",
      "id": "CVE-2018-20506",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-20506 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f6c3a96-97ff-5859-995d-c3520d8e213d",
      "id": "CVE-2018-8740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-8740 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:117d6b2d-e91c-5571-9817-465399e3fa26",
      "id": "CVE-2019-0193",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2019-0193 does not affect version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization. Version 2.9.4 is not affected by CVE-2019-0193: the security fix is already present in the target branch. Momus prerequisite check: \"Patches already applied: 1b81d200e8ffb882276264618c9004ba4bf72ecb\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84b171c5-58fb-5962-8231-1aa384ae66f5",
      "id": "CVE-2019-19645",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-19645 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ddd3afa-2bdb-5c56-a97d-22e40eb80d44",
      "id": "CVE-2019-19646",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-19646 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1576aae-f2ba-5208-89ef-5f9cd2304b70",
      "id": "CVE-2020-11655",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11655 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba45d7a9-276a-5f17-8fc1-a2e4200185b9",
      "id": "CVE-2020-11656",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11656 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3bb0024-0d8f-520a-b4de-6c8489bbd891",
      "id": "CVE-2020-13434",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13434 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01d9d346-9ca3-5cd0-ab2d-cd5c5d3a1e9f",
      "id": "CVE-2020-13435",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13435 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba6217a3-2906-5653-ab40-4b4c48b714c5",
      "id": "CVE-2020-13630",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13630 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0eff91a2-f5ee-5ddd-a222-9f544410373a",
      "id": "CVE-2020-13631",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13631 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a444625-e8e5-5f63-9487-17d6cade6002",
      "id": "CVE-2020-13632",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13632 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:029f4c43-def7-5b1a-b295-0b258ede992a",
      "id": "CVE-2020-13941",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13941 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ce877ad-3ac4-588c-a9ba-afe3202f01e7",
      "id": "CVE-2020-15358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-15358 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b85b154e-f268-5c0c-928c-6d70deb5fba4",
      "id": "CVE-2021-27905",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-27905 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb8500c4-1f63-5648-965b-c8f878853b57",
      "id": "CVE-2021-29262",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-29262 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0c595d8-d069-519a-9b82-39816f84603c",
      "id": "CVE-2021-29943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-29943 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de0d7787-79ab-5a93-83dc-f7bb9add2bea",
      "id": "CVE-2021-44548",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-44548 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4d89f95-de7f-5029-a5be-ac905f4fa885",
      "id": "CVE-2022-35737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-35737 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7ae5358-32e5-5d73-b110-021fe299de7a",
      "id": "CVE-2023-34610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34610 is fixed in version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:185c6a39-d64f-5b82-a67c-cee1ddb18649",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be479ba1-bd60-5623-8191-d599b85014a9",
      "id": "CVE-2023-7104",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-7104 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e371e4b-7ec0-5eac-8dde-ccd91a911a90",
      "id": "CVE-2024-31141",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-31141 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6228bdc-2474-500b-9cd5-c21a148faf68",
      "id": "CVE-2024-56128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56128 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1128e25-926e-598d-9c46-4a27f2c8d96c",
      "id": "CVE-2025-27819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27819 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f3438f2-ab89-5e5f-803f-e12b3cb13c62",
      "id": "CVE-2025-54988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-54988 is fixed in version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1089a3bd-df1c-521e-aa0f-6259a5259561",
      "id": "CVE-2025-66516",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66516 is fixed in version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a186ef92-fa51-5221-8189-592236ef5330",
      "id": "CVE-2026-66755",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-66755 affects version 2.9.4-tuxcare.9 of org.apache.tika:tika-serialization."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tika/tika-serialization@2.9.4-tuxcare.9"
    }
  ]
}