{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:0c360457-cc91-5b81-af7c-d9e0cafeb2b7",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-coyote",
      "version": "9.0.50-tuxcare.13",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:6f2c96c8-3d3c-50d4-b637-b5c40f031cd7",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-11996 does not affect version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote. Version 9.0.50 is not vulnerable. Summary: The target repository contains a functionally equivalent fix for CVE-2020-11996. While the implementation differs from the provided patch, it addresses the same performance issue using a more efficient approach with ConcurrentNavigableMap.subMap(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55644731-db40-591e-bfcc-19ef99cc70b7",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d508bcc-e62d-531f-9d59-c25254a47d45",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote. Version 9.0.50 is not vulnerable. Summary: Target repository already has the fix for CVE-2020-13943 applied. The maxConcurrentStreams check is correctly located in headersEnd() method, not in headersStart(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17c6408c-e947-5d18-b1a5-d203c7716173",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-9484 does not affect version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote. Fix already present in baseline since 9.0.35. Verified in java/org/apache/catalina/session/FileStore.java:303 \u2014 canonicalFile.toPath().startsWith(storageDir.getCanonicalFile().toPath()) containment check is in place. Advisory range 9.0.0.M1-9.0.34; 9.0.90 is well past the fix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2149ee3-2d85-5509-879e-274e3d590b5b",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3217e775-a811-5a16-a6bd-459c4214abbe",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc4e2876-06dc-59fe-bae2-abcb3a216419",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2d0a839-8b79-5203-8a74-5795d6b9ddb5",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf1c076c-1190-5936-8ad4-6a72b00555d4",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6de18687-9b84-5306-81ba-a1ce8d05d9fc",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7bc7af4-84aa-5441-966e-9315628c3466",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:832071ae-501f-5dea-8950-10ac9ab85c93",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0d20295-9f22-5674-8bc3-4aad4ffd2d1e",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-24998 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74b79b7a-fef5-5ead-bfcc-f702fd307f46",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fdd85877-7350-56b9-8804-92d4024f1e8c",
      "id": "CVE-2023-28709",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28709 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e746875-7613-5280-a09c-f9361cfffeda",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb27851d-3c6a-5871-9b6c-89f00e3c8abc",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42795 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13090483-cfff-5337-b05c-c45ae35fe10b",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c8d9a48-80ee-53be-b16d-65357abeb6fc",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06d34829-0d5d-5d1e-8ee6-36d7a486f760",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-46589 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a96780cf-2e96-56e6-8268-8bab06605f98",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92d0bddb-efc5-5a3f-8d30-48e397880dee",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ac76848-ec96-5cac-b04e-8c41514d41d6",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c62d16e1-2033-5e53-a6a0-86c118c4e1b3",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdaab2dc-b280-51e4-8eac-582ea4be4e3e",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:543aaadf-654d-5c4c-8764-359e89fbcff9",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d896ff6-5aeb-5689-9594-470a55c66ce4",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02a484c1-ea27-54db-85c1-2538091e4f58",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5dd505b1-930c-5601-ae79-608a3a0831c9",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:015b4d88-ffef-5e48-8729-74e4e56445b6",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-31650 does not affect version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote. 9.0.50 predates HTTP/2 RFC 9218 PRIORITY_UPDATE frame support (added in 9.0.76). Advisory range per NVD/Snyk/GHSA is 9.0.76-9.0.102. Code inspection confirms: Http2Parser.processFramePriorityUpdate method and priority parsing in Stream.emitHeader do not exist in this baseline. Vulnerable code path is absent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63013c63-7e77-545b-ba8a-607eb4468ddb",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ed29f36-bab1-5ef1-95ea-4d1fb861b5ac",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c848166-9da5-5cad-8357-01985b02519d",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2dbcfd27-1137-50e6-ba27-500094aa2c17",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48989 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25274319-1a17-5d3d-931b-d7bba62a9809",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:730ea2d8-20f6-5f00-a3e4-e00f90882629",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c58ad7cc-1fba-530a-a1ed-2e252463ab86",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b45b1425-0888-5b65-a74b-477356b9376e",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fc4e5bc-5c5a-5848-b9a9-605d86cc7f5d",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0d90da9-5615-59cb-8bf3-f50908fc233d",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6fa06fe-6503-5bfe-8559-46b83bf54ad9",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7b7956a-fe03-5f01-a3b3-5d36ef91e231",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b9dd0c8-5359-5644-b9ed-f9273f1b338d",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62e72bdc-3bac-59e0-8320-aa528773cb50",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5dbf49b-8c0f-5eeb-b104-6b1c6dec05c1",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4105f9a3-55b1-54c8-ae51-28b24ca1fc1e",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4538b0dd-dacf-5798-a672-df181164a51d",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d58bc60-2359-5102-a8a4-97a405938de2",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94a0966e-841d-5689-8c8c-0a484c218431",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37b61ade-b563-5a4e-81ac-c733ef8abb43",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9a6f5b6-0789-53c5-9e24-6fa452c65789",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34486 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a5dfff8-60e4-5fe0-a15b-0fd0a5f94238",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6e989bd-eb9e-5836-8558-67f06cf058a6",
      "id": "CVE-2026-41284",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41284 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c6d7e64-d5ad-5cc0-920f-6b27041e29dc",
      "id": "CVE-2026-41293",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41293 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b724e09-3ebf-5fc7-9a9b-e169438629d3",
      "id": "CVE-2026-42498",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42498 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4d9c8d0-2eca-5da0-8a21-4d44c6d543b9",
      "id": "CVE-2026-43512",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43512 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f33db1d2-7ba8-5847-b760-0143504414af",
      "id": "CVE-2026-43513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43513 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5cfcd24-7b17-5753-bb5e-eebe6196af84",
      "id": "CVE-2026-43514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43514 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c91cb067-d231-536b-99e1-738e3863c35b",
      "id": "CVE-2026-43515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43515 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-coyote."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.50-tuxcare.13"
    }
  ]
}