{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:650cefb3-fe94-563f-9eb2-6c290b3fc6bb",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-catalina",
      "version": "9.0.50-tuxcare.12",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:4afbd280-6fbd-52e0-84b2-9449ec335334",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-11996 does not affect version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina. Version 9.0.50 is not vulnerable. Summary: The target repository contains a functionally equivalent fix for CVE-2020-11996. While the implementation differs from the provided patch, it addresses the same performance issue using a more efficient approach with ConcurrentNavigableMap.subMap(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd2891a0-9c44-5fc1-b4ab-cedee73a7e77",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6750e69-53cd-597b-8dfa-611dc983b049",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina. Version 9.0.50 is not vulnerable. Summary: Target repository already has the fix for CVE-2020-13943 applied. The maxConcurrentStreams check is correctly located in headersEnd() method, not in headersStart(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e517bf2f-f4ed-5c8e-9c0f-b2f9e1193fb7",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-9484 does not affect version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina. Fix already present in baseline since 9.0.35. Verified in java/org/apache/catalina/session/FileStore.java:303 \u2014 canonicalFile.toPath().startsWith(storageDir.getCanonicalFile().toPath()) containment check is in place. Advisory range 9.0.0.M1-9.0.34; 9.0.90 is well past the fix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9371095-8024-5377-b861-a27c3fd76e50",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:836d6391-c5b8-5da6-bc98-72bfcad4c44c",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad30813e-fd7a-5939-98cf-144cbe98b49c",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7322f909-3e86-5f73-a71c-71ffc854893b",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a422274a-939b-548a-b08a-07325a9ed2fa",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6833ad34-5624-55fd-9e89-1c7f1bb82a51",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be5a4c49-2468-50c4-8297-8e86bfbd2e61",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca1cfe59-0345-5f9f-bb0b-b436c2f9cb9f",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9cdc1a1c-7fdc-5f1b-b852-795f9e38fd70",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-24998 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f0309b6-f465-5250-aeaf-f0f9252c00b1",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67fbd5ae-9618-5c6c-8a86-fa62280819ab",
      "id": "CVE-2023-28709",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28709 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5c1fd96-c258-5dfb-81cc-05aafcede7a3",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b616ae4e-58d1-5f43-8875-95eb5199287a",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42795 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58f8e20b-a11f-59e5-ace4-65176d83954a",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d84f22e4-c066-51e4-983a-a68221becc60",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c696656d-a036-5f5d-a7df-513635642cbe",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-46589 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c7b0543-3b80-537a-8deb-485b7817bca3",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da16a806-426b-5246-b12d-65244c0a6698",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f746fd0-5389-57b5-96a6-050fb8dff48f",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ca22082-de56-5e0d-b39c-d01f98765071",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad49ea61-d650-55cc-8c29-ee2f0a78c8e0",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ca74162-83da-5756-9c58-5a887b32d146",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:958e6212-b673-59cf-962f-83e621fdee97",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:176fe808-28a0-5b6c-9449-a4ca52a9778d",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:610d3f59-ffb1-55a2-a172-9973acc66d0e",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b60a8ed9-4402-58d3-871f-e54a7baa2c38",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-31650 does not affect version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina. 9.0.50 predates HTTP/2 RFC 9218 PRIORITY_UPDATE frame support (added in 9.0.76). Advisory range per NVD/Snyk/GHSA is 9.0.76-9.0.102. Code inspection confirms: Http2Parser.processFramePriorityUpdate method and priority parsing in Stream.emitHeader do not exist in this baseline. Vulnerable code path is absent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4fa9762-4150-5c96-a855-5ef90a5bbd3a",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9221885f-40eb-58b0-89e7-065355f05a4c",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ed2ca81-e547-5cba-add5-5ca1733d43cb",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7658a45b-6dfb-5de3-bbea-04c724ad7575",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48989 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3687b254-165d-58b9-9f39-62e7e9ea59fb",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a81471ed-bd31-5c4d-999e-ee48e0461752",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8dc0fd2b-8707-54ee-9803-085b76ca634a",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77e2ff50-970c-5815-be75-02848a77244c",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfe4193e-470b-59a2-a003-56b180027fd4",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a00228d9-f649-5938-af79-ae2a6a7173c4",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86820836-e54f-5675-a514-212423a2e25a",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1f85c9a-c855-5e01-95a5-036f92377d40",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29a3cfda-0339-5027-8032-e2c9ec9bc0a0",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:760d8439-fde7-5c75-94fb-e214d9999068",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01ba46ec-fa77-50e7-a192-bd670a032211",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:957d3f5d-62e1-59fe-8b47-5c3bc3fb331b",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e208265a-f706-5939-9bfc-6a39992143b9",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d0f29e2-e747-5f97-b480-2da941390689",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d5d0bb4-989a-5f44-ad89-61e76c5970ae",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e01105c4-a4f9-55e3-9e55-061478f0b440",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3efc1cb0-5705-552b-8c85-4236a9fabe11",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34486 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29fd310c-4470-577b-b32f-25cbf397bd43",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0a76913-f6eb-5d0c-a1f5-4bd5c254f7f7",
      "id": "CVE-2026-41284",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41284 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b94f73d0-0d16-5719-9045-06ec13bff91d",
      "id": "CVE-2026-41293",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41293 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54cbafd7-e767-5a4f-9902-f4a10d2b2077",
      "id": "CVE-2026-42498",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42498 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1e6ebf6-c5ff-5933-95dc-53f8552a1b08",
      "id": "CVE-2026-43512",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43512 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04dc0592-9f19-5aad-be6e-95c4dc7c9d84",
      "id": "CVE-2026-43513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43513 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52d944ef-be92-5962-929b-e978d856fad3",
      "id": "CVE-2026-43514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43514 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:085ff8d8-168e-5377-94da-f362b13c354a",
      "id": "CVE-2026-43515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43515 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.50-tuxcare.12"
    }
  ]
}