{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:49bc0e3d-53ba-528d-8306-85912268593f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-servlet-api",
      "version": "9.0.50-tuxcare.13",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:7be182be-e9af-5617-9220-dadaec6244f8",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-11996 does not affect version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api. Version 9.0.50 is not vulnerable. Summary: The target repository contains a functionally equivalent fix for CVE-2020-11996. While the implementation differs from the provided patch, it addresses the same performance issue using a more efficient approach with ConcurrentNavigableMap.subMap(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e174b761-6dd4-532a-8235-1ff4fdd77a09",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bec9e94-8e18-5da8-983c-c55d65d6ac2f",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api. Version 9.0.50 is not vulnerable. Summary: Target repository already has the fix for CVE-2020-13943 applied. The maxConcurrentStreams check is correctly located in headersEnd() method, not in headersStart(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:666ecd76-73ae-51ec-864a-1fd75074f354",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-9484 does not affect version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api. Fix already present in baseline since 9.0.35. Verified in java/org/apache/catalina/session/FileStore.java:303 \u2014 canonicalFile.toPath().startsWith(storageDir.getCanonicalFile().toPath()) containment check is in place. Advisory range 9.0.0.M1-9.0.34; 9.0.90 is well past the fix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30818f01-34e9-553b-a6d8-ef8a2fec735f",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be0f1ca1-45f7-536f-a3b0-e61dc183a82d",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e539bbcd-c750-575e-a822-ab9e430e638a",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed951191-b989-5509-b268-f16881c86ca2",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:287788ea-0e65-5f9f-8722-8e097df8ea4a",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b101809f-6dd8-5236-84d7-b5b6f3c863f8",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:faa58f22-5f6d-5c13-bc1f-160d6cdff717",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:677411d5-17d9-5188-bfad-dfde5dcc8200",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c09b56d4-ed87-5d1a-a05c-d089a58ac65b",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-24998 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:411a46e3-82bb-5c32-9035-75bd9cc2e9d4",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d02eace-0a10-584e-a16a-c9fa6ca0031f",
      "id": "CVE-2023-28709",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28709 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fb52c61-fba0-5478-8d1a-4448a37fb911",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a53b73e-815a-5672-a0ea-34c1be841a52",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42795 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3931b9e2-060d-53aa-a749-2300ff63c17c",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f36288d0-f507-58fd-965d-a27378db0ce9",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02b034ea-d0f1-5bdf-8eab-6c4122c1ab02",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-46589 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e71c973-35ab-55f5-b4a8-562f8b78be0b",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6229f5cb-d4f5-5579-af18-b2f0c08eb87a",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2ca04d0-a9b7-538e-9dd5-9ae74b5bcc06",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8894da06-2680-5560-a97a-809bef7d9c98",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6062375f-a382-5da1-bd40-60fcc4dbed88",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e9b9730-d7fe-5f48-b43f-333265bece6c",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a6ac684-b1b2-59ca-af28-30be16a69926",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93ad93d4-ad96-5753-8ea4-7e82a11730fd",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:070fe0bc-5580-5182-9930-9b446e56c091",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f3314ee-2414-5e98-84f1-de3a8f07fd5c",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-31650 does not affect version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api. 9.0.50 predates HTTP/2 RFC 9218 PRIORITY_UPDATE frame support (added in 9.0.76). Advisory range per NVD/Snyk/GHSA is 9.0.76-9.0.102. Code inspection confirms: Http2Parser.processFramePriorityUpdate method and priority parsing in Stream.emitHeader do not exist in this baseline. Vulnerable code path is absent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:248f755b-d5b9-5955-b84e-b8db08351074",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73dd9ca6-08cd-5daa-abb1-812990de13f2",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f0576b0-6957-5bb1-8fb5-c956c826fa59",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2ab5d52-9904-5a39-9438-126429f06f8d",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48989 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa93a0c2-cfe3-5038-bf04-90d27d5ca6e3",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e19ec38-8fc2-524f-aa24-6510b69288cf",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10d34934-c3d8-5330-9fdb-6242414824e7",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff4b5e7c-5497-5cf6-8e58-f876f3c21f93",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab4fd1d1-73ff-5077-954c-204c61cff3ff",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d115c3de-9ba2-5264-ae1b-5bdaaa1d47e4",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1d7711e-98e5-5ced-9844-10ee35b5d644",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79a0e6ff-f9d5-5cd0-b58e-3de0f313e29e",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfe24aa6-cfd4-5724-90ec-676b919a30d5",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28e3e15b-4857-56ea-ae6f-c9e485d7d265",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91a649aa-ae56-5df6-9fce-ba09bf1ad9b3",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1f87c54-7387-550d-99c5-47397d251a3e",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ccce8361-47c7-5c35-8ca8-0e6a9d5de253",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5c1290e-87d6-5868-997b-f1fb6ab7ff8c",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef1c89a7-77a4-5350-b233-720b3dcd1905",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:483a4b5c-3da3-5f52-abac-e2de1547cdf4",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1427f02-840e-5d27-98c9-eeb126a39354",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34486 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f2577c8-83a6-5c64-ab79-839de6f4422b",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:483e5a1c-a0c6-5c39-ac3e-e8c2bd748e23",
      "id": "CVE-2026-41284",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41284 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc19e347-b90f-52a6-b2ca-4c9eef8823a7",
      "id": "CVE-2026-41293",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41293 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99bb7a01-32d3-58e1-a86c-e91ef25b8bac",
      "id": "CVE-2026-42498",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42498 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bae51c1-4fdc-543e-8171-6a0aa726f5d6",
      "id": "CVE-2026-43512",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43512 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15859e9f-8919-5903-b246-e3aa4595049d",
      "id": "CVE-2026-43513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43513 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1814ffc-32d4-5cd4-b817-e51d2be86d2a",
      "id": "CVE-2026-43514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43514 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da385f96-5657-576a-926a-2f99c3c5076f",
      "id": "CVE-2026-43515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43515 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.50-tuxcare.13"
    }
  ]
}