{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:15b434a4-48e3-5477-a51a-ed94e3f60b9c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-servlet-api",
      "version": "9.0.46-tuxcare.5",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:e37dba53-bf42-5f92-ac68-e70abfd5e295",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-11996 does not affect version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api. Version 9.0.46 is not vulnerable. Summary: The target repository is NOT vulnerable to CVE-2020-11996. It contains both the initial fix (commit 9a0231683a) and a subsequent optimization (commit f258efef6c) that prevent the DoS vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1459a230-4644-5828-a050-1fbbc5bf4a3e",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2e3b33c-a930-5139-92bc-3f868488b8f6",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api. Version 9.0.46 is not vulnerable. Summary: The target repository has the CVE-2020-13943 fix already applied. The max concurrent streams validation check has been correctly moved from headersStart() to headersEnd() method, and the method signature has been updated from ConnectionException to Http2Exception as per the vendor's patch. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d9ae6fe-861f-5cf4-8d76-853b2e9d022b",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-9484 does not affect version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api. Fix already present in baseline since 9.0.35. Verified in java/org/apache/catalina/session/FileStore.java:303 \u2014 canonicalFile.toPath().startsWith(storageDir.getCanonicalFile().toPath()) containment check is in place. Advisory range 9.0.0.M1-9.0.34; 9.0.90 is well past the fix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:074d271a-f71e-5d65-9852-70639b1b1f3f",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:746a56c7-d83e-5808-9c7e-f76d4d09a11e",
      "id": "CVE-2021-33037",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-33037 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02f24257-40b0-5b9c-a249-66fa8cb6bc65",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86848f1f-5a7c-588d-a432-a98611bb0b63",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45a01444-f909-5ca2-b98c-3b3603f99bab",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19f69998-f902-5efa-b4f7-60648f23a49e",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2aa3954f-794b-53e3-beb7-8967f73611c4",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-34305 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcbc8533-3b59-5762-be68-0ddc0bfba56c",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3df54adc-db0b-5e8e-be81-f9724fab4a98",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:310e37f4-084f-5702-88f8-c0779e467683",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-24998 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed620c45-627a-5bfb-ae62-c2e981ba2ec1",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62be0a89-ff50-5780-b090-23ad8a67ed2a",
      "id": "CVE-2023-28709",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-28709 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b806851-c557-5de2-91c6-a87470a29114",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e29931d-bc57-507b-8766-0910bc51d3a8",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-42795 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1264db6-063d-5031-9a87-373274f82816",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba2839fb-2c20-5cfe-9916-6f4058a0974d",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:772e9f23-3811-52f9-aa3b-502ddd50df03",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46589 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:011e5877-7733-535a-b059-3a2b09877a13",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a85301bb-d5a3-544f-a09d-782302247f4d",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39410d07-4421-57ec-824f-ecc9b8c7f3bd",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34750 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6474289-5044-52fd-8e82-274ecdcbd41d",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb438ca5-9111-5d6d-b9bd-eebad2f4d226",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b50976f-6ac5-55bb-a496-481f4f2f3530",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b93a4eb-68c9-5688-8ae4-25868ab05890",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-54677 does not affect version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api. The version is not vulnerable. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:647105af-e5d1-5ed3-97ae-8c6ad74403c4",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56337 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:710b2214-cb64-5669-8b66-2f2a9632a6dc",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73390416-7e22-5222-ab68-10dbf01e6a88",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-31650 does not affect version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api. Version 9.0.46 is not vulnerable. Summary: The target repository is running Apache Tomcat version 9.0.46, which predates the affected version range for CVE-2025-31650. The vulnerability affects versions 9.0.76 through 9.0.102 for Tomcat 9.x, and this version (9.0.46) is not within that range. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c605738f-f3f8-5e6b-ba1d-5e312a9da216",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1385c27c-2c15-52f6-b350-c436fc58bd70",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2f32ca5-5281-5954-a4b7-5b11fb559e97",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d463c2f-7396-5ed2-b14f-880d13ca95e9",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68bc599a-ef11-500b-98f0-09e690be29d7",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65cbb712-d55e-5202-8a16-686a94cd51a5",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6fbfd098-4b4b-5719-97ae-e298a0c2f1fa",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52434 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:828d5591-d1e5-5c5b-8443-f3f4ee8affb0",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c69bbcbd-330e-54b5-b93a-001cc334982e",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47274dde-175e-54af-aedb-282ad0a6f824",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1741df7-1efa-58ac-a915-b591ef8dc370",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55752 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b0eb503-9e27-529b-abba-8b4fc8561363",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a6856a0-ea0a-566a-b62a-733a731aecde",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:debc1879-e151-590b-b4ca-c50b45fd6e45",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2601aa2-3554-5562-ac54-90858d88204e",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afa8f169-674c-51b7-a0d5-e8bdba69ef64",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3be809c6-44e6-54d2-a927-1f364242bf97",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61becb38-1dfc-5739-b914-f92b54ff0eec",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ada47bc-54b4-5919-b676-8ac0211b567b",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e675a02-6093-54d5-9a3e-398d7dc7062e",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-34483 does not affect version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api. Version 9.0.46 is not vulnerable. Summary: CVE-2026-34483 does NOT affect Tomcat 9.0.46. The vulnerable component JsonAccessLogValve was introduced in version 9.0.74 (April 2023), almost 2 years after version 9.0.46 was released (May 2021). The target version predates the introduction of the vulnerable feature. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3caba410-6524-561f-90ce-281606672cc3",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34486 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a47e94c-0abd-5434-832a-0efb24e2d950",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3afad44-7d0a-516e-b742-6d2803571ca3",
      "id": "CVE-2026-41284",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41284 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:349bbe97-ac51-558d-a445-c9befb04c416",
      "id": "CVE-2026-41293",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41293 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17bc65ea-d851-5f8e-8ac1-87657328ba25",
      "id": "CVE-2026-42498",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42498 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa6ac87b-2f67-52a7-9b5b-f53448c34eea",
      "id": "CVE-2026-43512",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43512 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae20f767-a08c-5cd1-bb05-127f3fa17e42",
      "id": "CVE-2026-43513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43513 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b08cf66a-ee48-5832-936b-753be320cfbf",
      "id": "CVE-2026-43514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43514 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31d7dbf0-f91a-5775-b49c-571df9a07cd5",
      "id": "CVE-2026-43515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43515 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.5"
    }
  ]
}