{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:14a44d15-a351-58f3-ba42-3b9b35af2976",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-i18n-zh-CN",
      "version": "9.0.50-tuxcare.11",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:532c5a00-71fe-507a-9334-7e6e3c699a8b",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-11996 does not affect version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN. Version 9.0.50 is not vulnerable. Summary: The target repository contains a functionally equivalent fix for CVE-2020-11996. While the implementation differs from the provided patch, it addresses the same performance issue using a more efficient approach with ConcurrentNavigableMap.subMap(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d88bb0b-e254-57f7-b4a0-6d4daea12d9c",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4da2a228-8216-5e92-b6aa-ce7298898086",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN. Version 9.0.50 is not vulnerable. Summary: Target repository already has the fix for CVE-2020-13943 applied. The maxConcurrentStreams check is correctly located in headersEnd() method, not in headersStart(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9d42bcc-ebcc-55b7-9969-9de828761da0",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-9484 does not affect version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN. Fix already present in baseline since 9.0.35. Verified in java/org/apache/catalina/session/FileStore.java:303 \u2014 canonicalFile.toPath().startsWith(storageDir.getCanonicalFile().toPath()) containment check is in place. Advisory range 9.0.0.M1-9.0.34; 9.0.90 is well past the fix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:511a410a-775e-5e06-91dc-27412a6efbc4",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93229137-6b65-5ea5-a7f8-9675afc7bec5",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d089f6e-5048-560c-9d38-315c020d3d98",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:618697d8-fbbe-5532-9536-a7753fd2a2a5",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3af14e88-828d-57cf-a7c6-84cf4142e04b",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2075721-83ad-5af3-9a8f-e0bc7800a909",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:384ed3d0-98e6-5425-9574-5db3b2089547",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:212e4068-fb43-5026-b995-395c47173dea",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d242bd9-bfdd-5e7a-b4e7-0d0250eaad23",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-24998 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae1cc16a-a5d3-59a7-b744-a6ea1267c82a",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0890d5c-b0f6-5400-bdfb-70794d4ddbe0",
      "id": "CVE-2023-28709",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28709 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7ce5e8e-18e3-5f66-a126-98ed45c04ce1",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66d5febb-761d-5dc2-8956-5016d9a7f4f6",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42795 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3bfeb027-6b2c-592d-8942-17bf7ded66d9",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b034eb2-133b-5a0a-af6c-44231f0bb95b",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3e2376c-29ae-5199-84ea-f17bbf9ef46f",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-46589 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f57d1acc-1108-5085-aae1-5bab81d76bbe",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ca61e49-a88c-5fba-9297-8c395d8be8f2",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d79dfd1a-3293-5d22-b5dd-037f4e72d46a",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c089605f-6be4-500a-8817-f6a29ab13cbc",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f7ff19f-68a0-5c4c-98d5-d37f849fbda2",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a90f9ce-5fb8-5238-b5ba-cdf0a256adcb",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f40931a-ab01-54c7-83c8-aba1b4a8bac9",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfd01430-8161-5677-8934-cc069a9394e0",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56337 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a139d9e4-5285-5ded-a8b8-3a1a929ad3c7",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06e43fe9-a642-52cb-8fd9-8ff429e98d77",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-31650 does not affect version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN. 9.0.50 predates HTTP/2 RFC 9218 PRIORITY_UPDATE frame support (added in 9.0.76). Advisory range per NVD/Snyk/GHSA is 9.0.76-9.0.102. Code inspection confirms: Http2Parser.processFramePriorityUpdate method and priority parsing in Stream.emitHeader do not exist in this baseline. Vulnerable code path is absent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69a22f11-0d8c-5064-836d-3136cd835067",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:becb2793-4de2-58a7-9039-0709ae812f98",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19062599-706e-5e1a-bcfc-98c94fc1bd19",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9ef0ca3-b98a-515a-87e2-bc4f4e00ea3e",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48989 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:133f7a7c-991a-5db0-ab84-439845b48db4",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29c3f1ac-d862-5866-bfce-d22f83127656",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64883b91-8432-5756-b52e-51c16931a64a",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9c40288-8534-55f1-90b4-a19653d8c090",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f07f24d8-f1f4-56da-98ee-ed80ae30f1c5",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88103bea-cc28-59bd-a673-b52f4ad17a15",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a79cb110-21e4-54e1-93c8-8986bf35d37f",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07a64d67-85b7-5c7b-813b-584cdf82cafd",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b4d9fb6-1ad7-5e53-a998-29a91f304a76",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1879b5b-97a8-5d52-bd21-5169ea5ccfe9",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b546bd5-d794-5bdb-a8f6-11ffae940db8",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a074112-f4a9-50f1-8891-87df645f825f",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31bbf5fa-a420-5193-88b4-b713b5e21ff5",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:679d83d0-a493-5d48-821c-641a7ad42871",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03125c8f-79cd-5785-9e14-53e21a0eabb6",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e8fb525-2aaa-525a-b1fd-e80115db4295",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6974e7aa-a420-52b3-80b8-8af2a14e3ef3",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34486 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7fe2ba34-eb18-5f0d-9570-3b33c8cd57c6",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f3afd6b-b5a0-5c10-91be-e0caee514910",
      "id": "CVE-2026-41284",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41284 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21d64a17-811c-562a-a565-48228be86fb6",
      "id": "CVE-2026-41293",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41293 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6acc57fe-afa6-5b52-b63b-9323b7bc69c1",
      "id": "CVE-2026-42498",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42498 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ecf8002-67f9-51cd-909c-2bd26d2c9565",
      "id": "CVE-2026-43512",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43512 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:100a5da8-195f-5ac9-9bc2-c4e8f383f190",
      "id": "CVE-2026-43513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43513 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db47616d-03fc-5281-95d6-1d21774005fa",
      "id": "CVE-2026-43514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43514 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d466c9bb-d8b9-583a-bdc8-0bc3f80e2b77",
      "id": "CVE-2026-43515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43515 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.50-tuxcare.11"
    }
  ]
}