{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e1aac240-1fe8-5b7b-b73f-53757da8afc5",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-tribes",
      "version": "9.0.50-tuxcare.13",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:e89b781c-e0d3-5a22-bab6-e0ec7c05a175",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-11996 does not affect version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes. Version 9.0.50 is not vulnerable. Summary: The target repository contains a functionally equivalent fix for CVE-2020-11996. While the implementation differs from the provided patch, it addresses the same performance issue using a more efficient approach with ConcurrentNavigableMap.subMap(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae913ce7-a72f-516b-8dd7-25db76747aaa",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f865bcf8-ba15-5d92-a9f8-c18038412427",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes. Version 9.0.50 is not vulnerable. Summary: Target repository already has the fix for CVE-2020-13943 applied. The maxConcurrentStreams check is correctly located in headersEnd() method, not in headersStart(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd5d49f1-dfe1-5a78-8921-d7823e1a848d",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-9484 does not affect version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes. Fix already present in baseline since 9.0.35. Verified in java/org/apache/catalina/session/FileStore.java:303 \u2014 canonicalFile.toPath().startsWith(storageDir.getCanonicalFile().toPath()) containment check is in place. Advisory range 9.0.0.M1-9.0.34; 9.0.90 is well past the fix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ec40b90-2037-5cff-80fc-3251ab13975d",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3dea6aa0-8df1-527f-81c2-75932fcab311",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3af2f863-a6f2-59e6-83b4-74327e9b603d",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01c94121-4971-52a5-8d9d-b11159beb0fe",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40cf3101-5fa8-5286-ba9c-7653a6de9696",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2721195a-46b7-5f9f-b4d9-45494c60cf04",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3d04d5d-cc1c-5cc0-93ce-cebc9e997cc0",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e545203-ee05-5bd9-ad89-741f80427a4e",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b28cdb4b-7485-58f4-b28c-d5bcf1fb2d4a",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-24998 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07211f3b-eb86-59ff-95df-ef1e7e18ee62",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:798b9ca6-b817-5875-a2d6-b70c7cdd96c6",
      "id": "CVE-2023-28709",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28709 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:502448f2-3c61-5c08-b476-be7bc9beb1b6",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:171ce769-67ac-5e50-b2d3-b1998a70678d",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42795 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:095c357b-1870-5de6-a162-5a8fed73caf9",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15335e87-098d-5736-bb89-8aca350242fb",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:114dbdee-86bd-5a08-a668-865127c53497",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-46589 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b03ad4b5-3abf-59d4-b3a7-ea9f1d5617c5",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28b87200-4373-5feb-bc6c-97f4c1fa2159",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63382ff1-8c98-5156-bf3e-44f9ee68bb66",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71ec1525-f668-543b-8969-83c27a97a331",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20990fa3-7e13-5d2d-aa66-a5793253e6e3",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ffffaa6c-5c32-5890-af63-e7f103a20c14",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c81d4f9-3c1d-5ad4-9531-f2b74ab7fcf7",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:246bcaf0-d32a-5a60-a87f-8cae6616c8c8",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99bdec0e-fc5a-50e6-a1a4-d0a670878f17",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42f03fb4-50fc-5cb4-ad3c-02f3ff318315",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-31650 does not affect version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes. 9.0.50 predates HTTP/2 RFC 9218 PRIORITY_UPDATE frame support (added in 9.0.76). Advisory range per NVD/Snyk/GHSA is 9.0.76-9.0.102. Code inspection confirms: Http2Parser.processFramePriorityUpdate method and priority parsing in Stream.emitHeader do not exist in this baseline. Vulnerable code path is absent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7fed0d6-24e5-5c26-97a6-0be5f06fc15a",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42f47470-c275-5557-9e80-cc518997ee54",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:779831ae-7600-5d4d-a40c-e492540cb24b",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4ebae29-6674-552c-bff9-27d516134b26",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48989 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c275e43-a998-57ab-9176-0656fe6be391",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8aac4b6c-9ae1-5cda-b740-ecf091971ac9",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fa3af1c-7364-57c6-ad66-060accf74752",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee312d5a-cb07-58b4-b741-720f7bb996c4",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfdadbda-9439-56df-b927-b787b276f652",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0dcad17-8519-5255-8088-ea6b705cc620",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e60296f-27eb-56ad-8379-f3d78c02d2fd",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e28f94e4-9937-592f-b38c-92c5c27b42a6",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17298798-8a4f-510e-a177-a8050bd286d7",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6bfd83cf-4b55-5e88-960d-c63d29f3e1a0",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0258edfb-1dff-5da3-b8b2-d50a868df0ba",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:630394cc-8212-5a2c-a7ff-fd2298c51ad0",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40a57df7-cb7d-52ee-8451-27402559d006",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81c94a47-87df-56bd-b14b-2f250f005079",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d96c219-4016-55c8-ae84-6d09835bb9b8",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:106053f6-86f0-5263-93da-7ca156481186",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad8a65bb-57f5-53e7-997e-e435de923301",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34486 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d42d581e-fd08-5316-ba4d-63e349f920ec",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88e4d9ca-85c6-57f8-9bab-968cea34d8e3",
      "id": "CVE-2026-41284",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41284 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27e0f938-93c5-5847-9efb-04289735df8d",
      "id": "CVE-2026-41293",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41293 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7273dd8f-1df8-5b3c-b5d7-08efd5de67bb",
      "id": "CVE-2026-42498",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42498 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77af32fa-c429-56bd-8ddb-7c70fd20e422",
      "id": "CVE-2026-43512",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43512 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b7f3353-22d1-5fe9-b2d5-eae8e75845ad",
      "id": "CVE-2026-43513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43513 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49d7bf68-7764-5be9-9e55-2244747aab12",
      "id": "CVE-2026-43514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43514 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7aba75f5-6ac3-54b4-9b93-72d0bf746ef9",
      "id": "CVE-2026-43515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43515 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.13"
    }
  ]
}