{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:10bca0b5-8faa-596c-aa9a-5dbd4da61beb",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-i18n-es",
      "version": "9.0.50-tuxcare.14",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:54324115-7297-5fb9-919c-e41f81b01e1a",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-11996 does not affect version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es. Version 9.0.50 is not vulnerable. Summary: The target repository contains a functionally equivalent fix for CVE-2020-11996. While the implementation differs from the provided patch, it addresses the same performance issue using a more efficient approach with ConcurrentNavigableMap.subMap(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d0e1ce8-cc20-5768-be9e-0db1158f1b1e",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0a649dc-eda7-5c70-8c94-8bfee7ee6ac2",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es. Version 9.0.50 is not vulnerable. Summary: Target repository already has the fix for CVE-2020-13943 applied. The maxConcurrentStreams check is correctly located in headersEnd() method, not in headersStart(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d250c4f-018a-5791-b6b2-e3ce276884fb",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-9484 does not affect version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es. Fix already present in baseline since 9.0.35. Verified in java/org/apache/catalina/session/FileStore.java:303 \u2014 canonicalFile.toPath().startsWith(storageDir.getCanonicalFile().toPath()) containment check is in place. Advisory range 9.0.0.M1-9.0.34; 9.0.90 is well past the fix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbef0178-0daa-52ff-a86f-727c279309df",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5852bfc0-50a8-5e24-97f5-8ab43e9211cd",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:387306b1-c02e-5a3c-af20-5aff20b4a78e",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a320d2d2-f47e-59e5-9e72-1a2a88a79478",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60ea0b93-5325-5f26-85c4-f836dafd28e0",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac532b87-3a62-5102-b0b8-4049e921fff6",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36738e38-62ec-5a7a-a40c-8c93b251b092",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b355673-3257-5c11-8a35-ff9ca4db3a4d",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ca99886-bfaa-5051-8e18-5ad4d3a4e6b5",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-24998 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc5c088f-e94d-5a28-9e24-d5e09b17d4bf",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9eb01ab-38b4-56bb-a127-05d94f07df00",
      "id": "CVE-2023-28709",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28709 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73601817-6c28-56cc-bbdf-87dc8325c96f",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24d90881-1af2-5891-8919-2cf6f2bf0ab0",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42795 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4756046-efea-527f-aaf3-42af63c1536a",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a996e16e-b815-5bb4-9b29-f3a77d8c1b51",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f26a8a97-a837-5d46-9e54-42db6a56b115",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-46589 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50c2b730-5054-5b6a-9e83-1aed66d4d743",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:884e69bd-fc2e-5181-8b35-db68fa011b04",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9ef64c1-d3d6-5f63-bc8f-42527e56b73e",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:404b7a36-e08b-55c6-ac55-0942f7a89984",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3ae1558-3a33-5b8e-a0d0-cbc2634dc075",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c7877ac-840c-5207-bb71-0f9716ed5a33",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a89255a2-64cb-5cd0-aeea-3b824ef678bf",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:071bdf60-f0ad-54fb-bcf0-c9ebe498960b",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad031e5c-574e-5779-93b1-56ca985a4a7f",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b98742d-247d-56df-b9f4-23c646ec8693",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-31650 does not affect version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es. 9.0.50 predates HTTP/2 RFC 9218 PRIORITY_UPDATE frame support (added in 9.0.76). Advisory range per NVD/Snyk/GHSA is 9.0.76-9.0.102. Code inspection confirms: Http2Parser.processFramePriorityUpdate method and priority parsing in Stream.emitHeader do not exist in this baseline. Vulnerable code path is absent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93f2811a-07fd-51a5-8821-5aba5b435624",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fae2409b-f3d1-5e70-891e-be373d7f7605",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff4c152d-9ff2-537a-980b-79963a35929f",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab42fd4a-c915-54ca-a03b-36c3df0c816e",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e857fffc-3f6a-5ca0-bc47-722f97b4c42d",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cec86f97-835f-50dd-8fa9-d074d8b8ac56",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66415719-44f6-5024-b6ab-a0be91fed552",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a06b1fe7-e313-5214-bd3c-40bb2c324926",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78bee0d0-ce5d-5974-946a-1bf0f402abee",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7cb87c30-1fcf-5424-b87b-d64bcbfa613d",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f8bafbf-483e-5125-bb77-577d711e08ae",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b08a605e-6fb3-5d02-ac69-011e5ed5e494",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d5d38f3-c921-5379-baba-763d178dba81",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d2c9e5f-a387-5349-bbf1-6ab8d3dabfa5",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:682927a8-ed43-5bcb-8f2a-7c1cd0ad844b",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b0142f2-fa68-573e-a11e-9770e529d323",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:037ae19f-adea-51af-bb49-c28c9888d876",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ad7ca66-313c-532b-9a44-1b0a170a41c1",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e153f93e-9eed-5939-9bca-802d18bacddf",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fe00d22-a777-5c99-9308-320e4d858f44",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87853ce3-f458-5e6c-abbf-7facd7aa20f2",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34486 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81a61ed1-d4c1-594d-8ae9-98896f6edda1",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1f3a4d9-6d7a-5aae-962e-c7dd372f903d",
      "id": "CVE-2026-41284",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41284 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49bf0beb-28ce-5172-9efb-62d62d041408",
      "id": "CVE-2026-41293",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41293 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4e2302d-6197-5c91-9024-d0b530429e5b",
      "id": "CVE-2026-42498",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42498 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d0d1f9e-ee0d-5c8c-9635-4368747a78ab",
      "id": "CVE-2026-43512",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43512 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fe9893e-251a-59f5-bfc7-fe4cf3c3a905",
      "id": "CVE-2026-43513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43513 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab8475db-6147-5717-bbc2-98440492a30f",
      "id": "CVE-2026-43514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43514 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6dab5f9a-b76e-5645-928b-09af3292301f",
      "id": "CVE-2026-43515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43515 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.50-tuxcare.14"
    }
  ]
}