{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3f39684f-39a8-5de1-8db9-2b0452f9bd71",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-jni",
      "version": "9.0.50-tuxcare.12",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:4c5057c3-c871-5a28-be45-9d4f256d2cf5",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-11996 does not affect version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni. Version 9.0.50 is not vulnerable. Summary: The target repository contains a functionally equivalent fix for CVE-2020-11996. While the implementation differs from the provided patch, it addresses the same performance issue using a more efficient approach with ConcurrentNavigableMap.subMap(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0290bf7c-36bf-5ad7-a2d5-9a5578a5e598",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d221a25b-a359-54d5-a185-8c8cf9fcd01d",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni. Version 9.0.50 is not vulnerable. Summary: Target repository already has the fix for CVE-2020-13943 applied. The maxConcurrentStreams check is correctly located in headersEnd() method, not in headersStart(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e65896a9-f4d1-56d6-822b-de3aa9d9aa18",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-9484 does not affect version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni. Fix already present in baseline since 9.0.35. Verified in java/org/apache/catalina/session/FileStore.java:303 \u2014 canonicalFile.toPath().startsWith(storageDir.getCanonicalFile().toPath()) containment check is in place. Advisory range 9.0.0.M1-9.0.34; 9.0.90 is well past the fix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fe935df-faa1-5314-af2a-0dff4f8a74d9",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc3a07ee-ed19-525e-9c3d-932c2adbb621",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62666a56-ae60-59c2-93bb-63220b621b3a",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbbbfe73-6339-54f7-9acf-4f41b3f6b2aa",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a05b3a0b-d9bf-580b-8d95-3020c6029d3d",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e053427-57ad-552b-a9ef-f0bcc6d6f5df",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93d939dc-f0de-5d43-9c59-c2913d6b296f",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4cdcea7d-d999-5f94-bd62-b552ca5a3171",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfb514fa-0c28-508c-9600-2dd8bd56033c",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-24998 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67ab0060-a16f-52c6-9df7-a62112ab66d5",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41d00a1a-1507-50d8-ba6b-6503b5daf8bd",
      "id": "CVE-2023-28709",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28709 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a806a734-54f3-511a-bb66-9ebbf089b845",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad2e080f-d881-5542-880c-8a43d9fc37fe",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42795 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da25f2e6-7466-5de5-908e-8f604231cc45",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40f1f4ed-923b-5879-9eff-45af31370a82",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ac5e8db-1aa1-513d-a677-e1dd5faabc3c",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-46589 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1302a48e-d127-5ad6-9bff-3830ec5d5723",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4adc574e-d64a-5e26-9114-297d676c2c13",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6471f26-3e25-5dac-a07e-b0219fee3df9",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:534d053b-139a-5a35-9bbb-b89b6fa5da02",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83de236b-e2e2-5b28-a66f-3344728e659d",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aebf9d8e-cced-5ca4-8b45-e6dc03c8bb88",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff50244e-2f97-5bef-aaaf-ea8e706416eb",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:315348fe-0178-55d1-9cb0-346fdb597a70",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f4bd8df-5f86-5aef-9ebb-a259ae9210af",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7523a75-a08c-5832-9344-78c7752a8d10",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-31650 does not affect version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni. 9.0.50 predates HTTP/2 RFC 9218 PRIORITY_UPDATE frame support (added in 9.0.76). Advisory range per NVD/Snyk/GHSA is 9.0.76-9.0.102. Code inspection confirms: Http2Parser.processFramePriorityUpdate method and priority parsing in Stream.emitHeader do not exist in this baseline. Vulnerable code path is absent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31bab220-16c8-57a9-a6ed-9849562e2867",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:235dfafd-dd02-5ca2-8086-ca62d5730224",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a355a745-c66b-5ab1-9581-49795126be6b",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab11bc06-51b8-5106-8e24-01c1e95bcff7",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48989 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e9c8070-3a1c-5457-997c-6aee683eb16e",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fdf50a4-09d1-58b0-914a-28024d389b8f",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58339100-c028-582b-992a-7bf02d15a15b",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:729578be-6149-5ec9-9da8-d67c078be214",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0bf1a2c6-0a70-5f6e-b2c8-308a075744a3",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ac9841b-c576-5f49-8922-6b8414181eab",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5eeaabe-5504-55d1-9ae0-58b94923dd09",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:edba2c3c-f2fc-597c-abc5-21d0d0084fc5",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:358a6f4d-fa9d-5d28-9327-43b87aed5cef",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e08a057d-004d-502a-914f-f69281cc3c0e",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6596b050-bd5b-547e-b6c1-d747091b0844",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6809efb9-4287-512b-89c8-8a5f8e8417a7",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:096b8b2c-b07f-5553-ac91-d01624c76814",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a64b394-fa93-55c1-8910-6a71d611f061",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58dd920b-91a2-5115-8f71-eec15347eab2",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbdc2684-3b5a-59df-abfb-5062186a17b4",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c702e99-5090-55b1-843c-6317af61f530",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34486 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6db5f0b9-049d-5083-ab81-4e70a29a6499",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93dca8b5-645f-5766-83c4-be454b8830de",
      "id": "CVE-2026-41284",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41284 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c8baa1e-465f-5f79-818f-862d57828a36",
      "id": "CVE-2026-41293",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41293 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d7816fa-5338-5089-aa03-c72e1cc79e26",
      "id": "CVE-2026-42498",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42498 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a182c21-bc46-5126-8f38-b80f10d196bd",
      "id": "CVE-2026-43512",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43512 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:095acc3f-c27d-5110-a486-0bbb34a8c9f6",
      "id": "CVE-2026-43513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43513 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19cce64e-ddc8-5208-8924-54348a198efc",
      "id": "CVE-2026-43514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43514 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7e985e5-c27f-5717-bd5c-9221cf24f5ad",
      "id": "CVE-2026-43515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43515 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jni."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-jni@9.0.50-tuxcare.12"
    }
  ]
}