{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4b53732d-ab7c-5004-842c-e2a684575f67",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-tribes",
      "version": "9.0.50-tuxcare.14",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:c44f7541-eea7-5119-b9f6-a0506a4cdd05",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-11996 does not affect version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes. Version 9.0.50 is not vulnerable. Summary: The target repository contains a functionally equivalent fix for CVE-2020-11996. While the implementation differs from the provided patch, it addresses the same performance issue using a more efficient approach with ConcurrentNavigableMap.subMap(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b97c556-3585-5f05-8839-9dcd81e4a103",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d133243c-853d-5b12-80a5-64d4caebcd49",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes. Version 9.0.50 is not vulnerable. Summary: Target repository already has the fix for CVE-2020-13943 applied. The maxConcurrentStreams check is correctly located in headersEnd() method, not in headersStart(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cce7eef6-378c-52ce-bbf1-50805f05cf4c",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-9484 does not affect version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes. Fix already present in baseline since 9.0.35. Verified in java/org/apache/catalina/session/FileStore.java:303 \u2014 canonicalFile.toPath().startsWith(storageDir.getCanonicalFile().toPath()) containment check is in place. Advisory range 9.0.0.M1-9.0.34; 9.0.90 is well past the fix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8150e7b-ee60-58ba-b703-7ef9ce035ec5",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a717260a-01b1-5b3d-ba51-cd2ff9efbb39",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a235b55-6828-59e4-8eac-cefec09bbe01",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50a9b507-495e-5c53-8739-ef0472101e8d",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:788a32fe-beef-599b-9717-80c6f2623a5f",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0369deae-4ced-5784-84e0-9d0764907a6a",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26c0ddec-f0be-5867-a95d-dbcdfa26993f",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70184da2-5ba0-546a-9344-0af5a700a06a",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ba83d8e-f09b-551c-a3b8-13bf5e1f3ab3",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-24998 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5ccab39-e2a9-5a7b-ad4f-4c7910f0e788",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aecc9934-9912-50c0-9247-9be4be811c93",
      "id": "CVE-2023-28709",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28709 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:621a39a2-ccfe-5c6e-97c1-96c1c76642c3",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64e717ee-1e06-5cb9-9321-84fb5f91d584",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42795 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20a7d837-1877-5043-b0dd-36357c8afe72",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1428f999-312f-5baf-a19b-b437bf8be732",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:add44cab-61b2-53a9-a63f-5b9639a82a20",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-46589 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9220d325-f7ad-570a-8827-0ee298f24bbb",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50d41489-5aca-5e2a-a17d-b74610485ef6",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64fa3b55-17cf-5b85-84d5-5ca42f5e00f7",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8619a7ff-b4e2-5a80-a24e-191f98926382",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce6ed2bb-d85b-59b8-8b54-5362ca4765ae",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f11e50d9-d349-59af-a94e-20769a8a31e4",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfbcfcf5-8719-584b-93f4-7d68975ed5b0",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18e6eff1-ac50-5b2a-8169-6621559a279c",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b470ca5-4f64-597e-81c0-9f5544c27d64",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0ca890a-8920-5dec-8b80-7f65f0ce1ff3",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-31650 does not affect version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes. 9.0.50 predates HTTP/2 RFC 9218 PRIORITY_UPDATE frame support (added in 9.0.76). Advisory range per NVD/Snyk/GHSA is 9.0.76-9.0.102. Code inspection confirms: Http2Parser.processFramePriorityUpdate method and priority parsing in Stream.emitHeader do not exist in this baseline. Vulnerable code path is absent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56fc58a7-76f3-5b3d-bef5-9dce5dad1c3b",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fc40e5d-d0b5-5b17-995b-e0628a6b3f74",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1872682-5d2e-568f-abef-28afca81ff99",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d9abf17-c91b-56f6-8e02-9cc568d01938",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7c8d374-6984-582d-bec0-bb8ba1ca8942",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c5079ce-5acc-5b7f-b78e-c3d1cc019e7c",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c011ac6-cef5-5ea8-86f5-078d8a1e7bdb",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:028bf7cb-191c-5114-a5d7-40770eb6a308",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9cf1662-053e-5988-ad5e-2a66aa93e9c2",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4878e7a6-b0fe-5844-8500-76c2d5f26b26",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75d0bf98-0b2f-5f83-b253-8e7cfd94fee7",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:432aec2c-42a7-53fd-8360-ce46277bb2f9",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a892572-fb69-535d-bdd1-7608122900db",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:872b9b31-4a9c-5ff2-997f-448226477b84",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7dff0a05-b003-59db-be4c-95941b7b7a7d",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1d3be7b-35e8-5683-8be7-102c0bb9a0a3",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:866b32ea-3930-50fa-afba-c355d98bf971",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99cff2f7-345a-504a-91a9-05ef4134fa08",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de3a49e3-5fd4-5198-aa4e-8663fb0f4e38",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90cea0e5-9611-5dec-8ace-fe44a56a63e3",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ce1fca1-512b-5c63-8060-e479e174caec",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34486 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:780fe0cf-9ca3-559f-922d-6987dcea0ebc",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9fa6f24f-efc1-5951-a6e4-81d47a7a3ea6",
      "id": "CVE-2026-41284",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41284 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:737f0ca3-e2ef-546b-b48a-d3e44b89520d",
      "id": "CVE-2026-41293",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41293 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7134dcd-0d5b-5a61-a157-a7b46b5ba9b7",
      "id": "CVE-2026-42498",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42498 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:998f38fb-6d20-5cb0-94c7-575015bf8071",
      "id": "CVE-2026-43512",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43512 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:363a926e-e4d4-53d4-aa2f-584778ec3410",
      "id": "CVE-2026-43513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43513 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5dfa741-c8aa-50ae-90e3-129a7017ba6d",
      "id": "CVE-2026-43514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43514 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a967504-4a37-5347-b930-e2d7f8370d6c",
      "id": "CVE-2026-43515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43515 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.50-tuxcare.14"
    }
  ]
}