{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:7170b48e-241d-5478-8fe9-c33c9b8967b9",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat",
      "version": "9.0.50-tuxcare.13",
      "purl": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:8de83e86-8b21-514b-8811-e7658ba38409",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-11996 does not affect version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat. Version 9.0.50 is not vulnerable. Summary: The target repository contains a functionally equivalent fix for CVE-2020-11996. While the implementation differs from the provided patch, it addresses the same performance issue using a more efficient approach with ConcurrentNavigableMap.subMap(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a630500-7865-5e44-a373-b2c0b522154b",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9af1cc88-9ca1-5b98-ad65-15cd6b69e448",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat. Version 9.0.50 is not vulnerable. Summary: Target repository already has the fix for CVE-2020-13943 applied. The maxConcurrentStreams check is correctly located in headersEnd() method, not in headersStart(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f72c0582-96cd-58c1-b9cb-c526027e9bc7",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-9484 does not affect version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat. Fix already present in baseline since 9.0.35. Verified in java/org/apache/catalina/session/FileStore.java:303 \u2014 canonicalFile.toPath().startsWith(storageDir.getCanonicalFile().toPath()) containment check is in place. Advisory range 9.0.0.M1-9.0.34; 9.0.90 is well past the fix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46f782f3-7a09-5bff-a554-0da077fc0a69",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37a71901-e87d-548f-b0f4-b363ae472b0a",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e6ca53f-501f-579e-92fc-a669b2dd208f",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae29f218-74d3-58a6-beca-33b4998e5b58",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9992dd28-6157-5081-a005-dd026905ff3a",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3881b6c7-4472-53f6-a4ed-d271bd9a6f6f",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06b882b8-6848-510f-9158-9219f8d7e74f",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:254273a1-09a7-50b7-a713-f20f6a7add5d",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77906501-3eb0-561d-b1d4-fa82df424a83",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-24998 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:960dc838-2ed9-504a-b4a9-fd9d6b8d3cfd",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a74f8474-43a6-5f33-af61-d250c4ca76e9",
      "id": "CVE-2023-28709",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28709 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66a75e7b-492d-5974-b969-e757562bcab0",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2e52522-fbf1-5d9b-91b9-c83fe89ff4d2",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42795 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1696f80-e49b-5129-b6fb-2888cb762477",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:719d67c0-205a-5e3f-bf9f-e9df45d22470",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90e523e3-6741-53cc-bf45-8bba89a1d501",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-46589 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b878ae1d-f048-5933-b516-314523f45da9",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:337381f4-ea90-5e79-99da-17f7a77050a4",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:132d1b0f-a031-56c3-8923-3eb179871c1a",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62e15dad-2c99-57ba-89e8-e9851b383517",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b21b6d5-74e4-5502-bc8a-29e6ec846542",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e76ba05e-21e6-5086-9e14-b0c25e980958",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4bec0452-396d-5b2f-be36-9cad03ba1f4b",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9653faf7-7c41-5573-a760-15cfed922411",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c36d8a62-0f09-530d-be2a-59a9a3e8f5a2",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:019c1df6-a6fb-5228-ad98-e785882247f9",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-31650 does not affect version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat. 9.0.50 predates HTTP/2 RFC 9218 PRIORITY_UPDATE frame support (added in 9.0.76). Advisory range per NVD/Snyk/GHSA is 9.0.76-9.0.102. Code inspection confirms: Http2Parser.processFramePriorityUpdate method and priority parsing in Stream.emitHeader do not exist in this baseline. Vulnerable code path is absent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07299975-36be-509d-93cc-df0776ad2441",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd1328f3-a6dd-5db4-af4f-43afdcaa2338",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09e38270-ffc9-5639-a4d7-41aa494e0565",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c07c4849-41cb-5f32-9587-e68e3b7cb390",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48989 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2693df0f-f0bc-57a9-b424-745f347ea192",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:312394a9-63cc-55cf-a393-8431bba495af",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37c2cc01-5cc7-58a2-b453-da4021b258b7",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:148efb9f-56ee-5844-a0a6-23886c576a84",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb23e3ee-92a2-5436-a523-daaa688258fb",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e35861f3-f217-5691-9128-dfe20b58fb6a",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99ea76ee-be8c-5038-b564-82f966acf8a0",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ed76713-63af-5a26-a6aa-ac3ef7f2a505",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff04df47-21b2-5e87-8798-2dc462853f4f",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f48f6489-9630-59a6-834f-159303636ae2",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55f344f2-9953-5f4a-a6ce-b243034924d3",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5a5c2dc-20cb-5721-9c78-a1b156ded29f",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba7a89ad-ccd2-56ca-a03d-c46554f18773",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61bb9b16-a8e3-5fc9-97d6-e2074f145bec",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:282d34ca-453a-57ad-9f33-0b7a2a16d48c",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e32d01da-1d8a-5bb0-b448-c47bbb84741f",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8919afbd-32b7-5799-9ebb-ff999d765835",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34486 is fixed in version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a979289-5b04-575a-970e-9728da4132f5",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb10f4a6-eeed-581c-8612-110677969833",
      "id": "CVE-2026-41284",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41284 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40b22c3a-5957-593e-8bf6-c744a91eb83e",
      "id": "CVE-2026-41293",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41293 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3828c9b-d00a-513f-848b-321a451bbd50",
      "id": "CVE-2026-42498",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42498 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1589acc-06ee-58d6-a1e0-ee3f769093d5",
      "id": "CVE-2026-43512",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43512 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:605ffcde-8e3a-56d2-8ae5-e6f5bdaad17f",
      "id": "CVE-2026-43513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43513 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:028680a9-a71b-5c44-b252-36c98768f01f",
      "id": "CVE-2026-43514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43514 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:869904a4-4df7-5892-9086-2af5f8a93dd0",
      "id": "CVE-2026-43515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43515 affects version 9.0.50-tuxcare.13 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.50-tuxcare.13"
    }
  ]
}