{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:37946804-ef36-55d6-8e4c-558c2b1df4b8",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-api",
      "version": "9.0.50-tuxcare.14",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:19176104-050b-5a5e-9f1f-8f524af2be61",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-11996 does not affect version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api. Version 9.0.50 is not vulnerable. Summary: The target repository contains a functionally equivalent fix for CVE-2020-11996. While the implementation differs from the provided patch, it addresses the same performance issue using a more efficient approach with ConcurrentNavigableMap.subMap(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f55f1600-8b7e-50de-9c4b-df63d20f2d6f",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70f53dba-b1f4-50ce-9272-0c47d6620a0b",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api. Version 9.0.50 is not vulnerable. Summary: Target repository already has the fix for CVE-2020-13943 applied. The maxConcurrentStreams check is correctly located in headersEnd() method, not in headersStart(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bcfb74fa-1be7-57ba-be08-a4ac15f37405",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-9484 does not affect version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api. Fix already present in baseline since 9.0.35. Verified in java/org/apache/catalina/session/FileStore.java:303 \u2014 canonicalFile.toPath().startsWith(storageDir.getCanonicalFile().toPath()) containment check is in place. Advisory range 9.0.0.M1-9.0.34; 9.0.90 is well past the fix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbe1a604-fbff-5190-8c1e-706267c73fd2",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c3b36fc-e06e-5716-83c5-07a945b2fd25",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92daeb15-ab82-5bde-b112-05d75f86b2f2",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e326f6e-aa91-5946-9c2c-8589a346f8f1",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:050567ec-2b5a-591d-bf3a-32eb34d874b5",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb62faf4-9373-50e8-8bc0-df2aafe8f950",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8967b64a-afb9-50f3-a90f-a62b29dd19c4",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25589c72-bbd1-564d-b446-6b3459171ff0",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69f51f61-fa65-53c6-9725-43325db2c70e",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-24998 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:321ef6e4-8992-5a79-842e-8805dab445c6",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a688f7d-1643-5e64-8077-8cb3f5616c99",
      "id": "CVE-2023-28709",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28709 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53c6337b-3b85-56d7-afaa-4f10177dcb36",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50582108-6673-5ec9-916b-cd0ae9f6c6cf",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42795 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df59e458-e1bc-59c4-b9cf-5747eb6b256f",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5090a858-9b80-5dd3-848e-0607cdc262fa",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c60fc05-cb4b-53b5-8393-5848b7518f2d",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-46589 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22285966-d387-55b6-891f-2f626d3df8e0",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e6c97c1-423f-558f-9fc2-fbc1d34fdc98",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30849e22-2f01-5542-ba2d-40121a5ea1e6",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1ed0b9c-8f0a-5d5e-b01d-a1027d9d6df2",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c81c930-4453-5d55-bcba-d76c2b40b625",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4c31d03-db45-55ad-80fa-24d8d3c11c69",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83729d8f-c43a-59dc-83a5-08948de3ae2e",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0760344-7191-5e83-8306-12b180ff71b6",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:375fa043-b8c0-52be-b7fb-dad2e882fdeb",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa0f5f20-6044-5a67-83ab-f2a041535274",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-31650 does not affect version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api. 9.0.50 predates HTTP/2 RFC 9218 PRIORITY_UPDATE frame support (added in 9.0.76). Advisory range per NVD/Snyk/GHSA is 9.0.76-9.0.102. Code inspection confirms: Http2Parser.processFramePriorityUpdate method and priority parsing in Stream.emitHeader do not exist in this baseline. Vulnerable code path is absent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:961a2a34-d98c-582c-8a9e-95808295bcd4",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:469e3245-2881-5482-b515-8d1d63975ce9",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1fb92e5c-c517-5951-be02-56bddea943fe",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6841d04b-ce45-5f55-8f2a-84d561866120",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c893fc15-b927-5268-95a4-97317bfbdcc7",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20686d5a-1f53-5a0a-89a4-6f229c05f512",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df0575fc-4395-55a2-ac22-a04126af890f",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e266aa3-427a-5fe9-a3d0-63a448250c2c",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e4db01a-1354-550d-8ffa-0620673e27da",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e338d36e-1a39-5c0d-8c8c-0747795392d8",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:177edfad-9d14-5f7e-a595-8c6efbc1c228",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1560f54c-22d4-5cba-a952-4da653560065",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cde7f8f8-8a91-5bf7-95c0-a2525c5941cb",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:720a7b21-5212-51ec-8303-843fa512feef",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23382e88-9f76-5d05-8d09-56dab570219d",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92fbbe18-d311-5ffa-9bbe-c8f184f9b266",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a990af00-189e-5ea1-a27d-8e42f521191f",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74ac8a8a-e9dc-59cd-bfb3-cb77775337fc",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e174668f-96ac-59a4-a7da-f35b381923e0",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a3ba279-5bc9-5487-96eb-266a6474f061",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f767dcb9-25b0-5faa-baf4-50318858c954",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34486 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c752088-91b0-52a6-9e15-55705a85c581",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:920c552b-4f75-5a60-a968-2c418199b565",
      "id": "CVE-2026-41284",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41284 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d150cc82-066b-5e4b-8d4b-521783072ed3",
      "id": "CVE-2026-41293",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41293 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9eac1e40-2a56-5cba-9e15-6831baef263c",
      "id": "CVE-2026-42498",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42498 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc30b5ce-125c-5470-8b92-0b84af9a0d90",
      "id": "CVE-2026-43512",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43512 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae9986f8-ab89-5b05-a13b-a8a8a3361f46",
      "id": "CVE-2026-43513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43513 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00f6bf17-c82a-54bb-b585-b0dbbd1bdd3c",
      "id": "CVE-2026-43514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43514 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bff28afb-0c6f-5f2c-845e-c8573954e6c7",
      "id": "CVE-2026-43515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43515 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.14"
    }
  ]
}