{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:970995bf-aea8-50e8-aac8-1bce23cffe0b",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-util-scan",
      "version": "9.0.50-tuxcare.13",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:5f67144d-6f20-525b-9f00-a9d43b29ce86",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-11996 does not affect version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan. Version 9.0.50 is not vulnerable. Summary: The target repository contains a functionally equivalent fix for CVE-2020-11996. While the implementation differs from the provided patch, it addresses the same performance issue using a more efficient approach with ConcurrentNavigableMap.subMap(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c23c95c-5828-5907-9d94-49bd8df22f73",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fdc7af02-7d42-509b-9c10-2e0ad60917e9",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan. Version 9.0.50 is not vulnerable. Summary: Target repository already has the fix for CVE-2020-13943 applied. The maxConcurrentStreams check is correctly located in headersEnd() method, not in headersStart(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa98e0eb-ddf4-50f1-994b-7b85c2f48636",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-9484 does not affect version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan. Fix already present in baseline since 9.0.35. Verified in java/org/apache/catalina/session/FileStore.java:303 \u2014 canonicalFile.toPath().startsWith(storageDir.getCanonicalFile().toPath()) containment check is in place. Advisory range 9.0.0.M1-9.0.34; 9.0.90 is well past the fix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76a1ca81-3aa2-5400-b808-f57af129bb2f",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:316c7564-5547-5539-a16b-9f0dc270427d",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5538de8-13cd-5234-a026-65228414c3f0",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f79c384-b79b-5c02-94d2-49b5058bb943",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1ce5378-a99e-5890-a892-42e51ca89176",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4b11036-dab5-5c69-9146-7110dd7ef0f0",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:266e04ee-b2df-54f6-92e3-4a6a616f53a0",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95754da0-5ce9-5066-80b1-045d5ea67660",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ed75611-6ca2-53f3-87fa-943a7542b639",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-24998 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:482d7d82-2d4d-5bc8-b9e4-121a026f8b28",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60875727-7498-54b1-9c2c-a0a252dea4b5",
      "id": "CVE-2023-28709",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28709 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d65497b-31c3-5ad8-863f-fc04906f61f0",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fdb60e11-1341-58c2-86c5-1fd421085e0f",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42795 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:674ac6e8-5824-55ea-819b-0539faef39af",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66628757-bef3-5b18-99d3-c0c587282109",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c15a1f0e-a76b-587f-8b98-10f41ece9f50",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-46589 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bae473b-a414-5e7b-9535-3a0ecc133349",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bba3de35-e822-5c58-902e-db5e15536dc9",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7ad468f-0f19-5c27-8951-343a1f1ad3eb",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:976f1484-db9d-5648-abd9-92bc1a5a3acc",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:320e4b43-804b-555f-8da0-bd4ea8083b24",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:038c9369-ac94-56d3-befd-28b5f59f4bc3",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76710284-7d0e-5948-a69b-22f689f9f049",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f985ce1e-3a9f-59f0-95ea-47047489f842",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efacd76d-1de6-559b-9aff-48bffd732554",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5251af8c-56ad-5a34-aeca-531c53cd6631",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-31650 does not affect version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan. 9.0.50 predates HTTP/2 RFC 9218 PRIORITY_UPDATE frame support (added in 9.0.76). Advisory range per NVD/Snyk/GHSA is 9.0.76-9.0.102. Code inspection confirms: Http2Parser.processFramePriorityUpdate method and priority parsing in Stream.emitHeader do not exist in this baseline. Vulnerable code path is absent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b676f24d-c99d-515d-a9c6-9d97bd6c9927",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afc3c547-6306-5148-b54d-57d3dbaf837c",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3dca3da8-8449-5d96-9b50-26dbd24ad7f8",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f54ea875-7d9e-5c54-bd19-9da44be0efd0",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48989 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d5a12a5-1897-5144-9bae-9148ba948a06",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dad9934d-09d7-5622-af81-eb3d63f44eb8",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9214f595-7534-574b-b4b6-bea468a46b01",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6fd0bcd-17b2-53f2-91ad-87813af3c180",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e6d354e-0217-5153-b3f1-7997b451115c",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:516c9c22-9f38-5b3d-811a-9d52472aac5e",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e489308-cb65-527c-89ca-757369ee94d9",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:971eb158-52dc-5e4e-9527-a586dd9e2ee7",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4971a428-d96a-55f0-bc52-ff1aad3a511f",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21d85595-7342-5813-8c47-b1ce6a44d771",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ff8f8e5-28f3-5b2c-9ab9-6828bcb263cb",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c533d20-dd84-5630-94bb-0a243d579efd",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21ef0c4f-fe6b-538e-a272-0f034bc0a9f0",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11149612-3155-5ad0-a797-d7c1981fa369",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfa45538-ad32-5e12-bf44-ebf76ee4ffa7",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a587854-4510-53d9-826a-bce6e12caa4d",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf8f6c94-74cc-5e93-881c-848963111db9",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34486 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19267f33-439c-5785-abc6-b630ee82f055",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b5e40a7-d139-5272-8eb4-714790c3e19a",
      "id": "CVE-2026-41284",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41284 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:797a0345-f21e-599c-9a1f-d1826653cdfd",
      "id": "CVE-2026-41293",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41293 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65cce119-af11-5973-afe5-8da36975424f",
      "id": "CVE-2026-42498",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42498 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2da5a7c-3d3c-57f6-9035-10458f1b229b",
      "id": "CVE-2026-43512",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43512 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db4b9447-f783-5a4c-a953-c6faac02e57b",
      "id": "CVE-2026-43513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43513 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9610222-c009-5669-a98b-f6737d401acf",
      "id": "CVE-2026-43514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43514 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb9df239-5f57-5dc0-a366-76ee41da60a9",
      "id": "CVE-2026-43515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43515 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.50-tuxcare.13"
    }
  ]
}