{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:6cf3e66f-a1f3-5785-9c03-e15898e05234",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-storeconfig",
      "version": "9.0.50-tuxcare.11",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:2fb616fa-e8a1-54fa-952b-884a06da5b60",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-11996 does not affect version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig. Version 9.0.50 is not vulnerable. Summary: The target repository contains a functionally equivalent fix for CVE-2020-11996. While the implementation differs from the provided patch, it addresses the same performance issue using a more efficient approach with ConcurrentNavigableMap.subMap(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63ff0288-1fe2-538b-b83c-21607dc6af2a",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10e92ca8-340b-59c1-aff5-97b399cdcde5",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig. Version 9.0.50 is not vulnerable. Summary: Target repository already has the fix for CVE-2020-13943 applied. The maxConcurrentStreams check is correctly located in headersEnd() method, not in headersStart(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9820c07-f29a-519a-88c6-8d9d8157538c",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-9484 does not affect version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig. Fix already present in baseline since 9.0.35. Verified in java/org/apache/catalina/session/FileStore.java:303 \u2014 canonicalFile.toPath().startsWith(storageDir.getCanonicalFile().toPath()) containment check is in place. Advisory range 9.0.0.M1-9.0.34; 9.0.90 is well past the fix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17ba0a5c-8df4-52b1-ad7f-c779dbe8d9c1",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09b2501a-1eab-566f-997d-cb5a12793d65",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:227e8a4c-cf82-5ec7-aca4-acb282614fdd",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:113cfce1-be82-5422-aa56-0c099f790458",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9cd7cb9-6e75-536f-ab9d-8d6729f0fcba",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb353402-a2fa-5e93-9b04-16f8eadf6a31",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:231142cc-66c8-523e-948c-bde74374fa0a",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92366929-017b-545f-ab38-69db15fea1f3",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:351f2486-d3af-510d-976a-c958600395c5",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-24998 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb50f61b-81c6-5da1-8908-423944606bff",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74d510cb-fddc-5a84-8534-122338262bd0",
      "id": "CVE-2023-28709",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28709 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec3bcc47-9c59-59d9-a9b4-49a3ac1218ae",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd45d07b-61ba-5e1a-997c-f6aec5e4a60e",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42795 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c58ea8ae-1019-5173-a1f5-46d7dc7da035",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d5c4b2e-6d5f-5aee-98b9-ba9c0bccce8c",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fd528d8-54fa-5caa-b207-4669add0e2d2",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-46589 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0c75e6a-efeb-5536-8dab-4b87812bac3a",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:655c9a79-f4c8-5411-9101-5b9f3ef8ebf0",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a287959-7669-544f-b69a-aaab1646500c",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b582233-8320-5d7e-a888-007c666ea5e0",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5af6449c-169a-58e0-9cc9-b9a7c1e2713d",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f68405e-b39d-5ffd-9277-c8951d7b9d5e",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9b8fbc5-ecd3-5bf7-8d75-00eded784d5c",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ab6a67e-6e40-5619-926a-2865fe8c5854",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56337 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15f67a45-e458-5f58-8c93-4a7ec4d5dfc6",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69244ea8-c151-5339-92f2-0832a2384349",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-31650 does not affect version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig. 9.0.50 predates HTTP/2 RFC 9218 PRIORITY_UPDATE frame support (added in 9.0.76). Advisory range per NVD/Snyk/GHSA is 9.0.76-9.0.102. Code inspection confirms: Http2Parser.processFramePriorityUpdate method and priority parsing in Stream.emitHeader do not exist in this baseline. Vulnerable code path is absent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7d758f1-5690-5f09-92f7-5dd87cb4d8e4",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce92da08-0e23-514f-831f-2a64df619d5a",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80853892-3d98-5118-a538-c3f8496c1a34",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f693983c-8b73-5fed-ab0b-cbaf4c191b2e",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48989 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4f9033c-80b4-535c-b8ac-7138c6297432",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:673791ac-c0e5-5339-9a3a-661ff2902645",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd91b801-4132-565b-8c5e-3f0edcae48f1",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce89fa65-3188-5906-82ca-073bd5b121b6",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8445f0d-b6f3-5b24-85ff-072a972bebbf",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:207e011a-51f7-5349-9a80-181b35163f84",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c085819d-a6ed-5631-9999-14fe7a2caab2",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a62138a-de67-5519-8e4f-5e5c7104ae33",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69ffb555-9640-58d0-a5ef-9e8475f8490b",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:034c36fe-6ac8-5026-87ba-fd908e4ca4c1",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5b15902-f16e-5310-8883-892511dc087b",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2baac38b-04ef-5f15-8475-9d9a7152975a",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4b295c9-7c02-5cee-a20b-6200f7d3a448",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a99153c9-72d3-522b-8592-6e12f7cf2ed2",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfc866ad-ae0c-58f7-9911-a60da5239e20",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5cb7406b-05df-5317-ba37-94616a197df6",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc07baec-2e5b-5d9b-9ccd-cfb28756e834",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34486 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6147392b-ab1a-552c-8b9b-862ebff707b0",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4264c175-50ec-59d0-af09-bf159cdeee10",
      "id": "CVE-2026-41284",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41284 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f60e5ff7-d436-520e-be60-cd06ef3c3894",
      "id": "CVE-2026-41293",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41293 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d3381c0-3cd7-5857-9a8e-771044502d15",
      "id": "CVE-2026-42498",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42498 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6cf9fadc-3461-5aff-ac48-cd1ad7581dfa",
      "id": "CVE-2026-43512",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43512 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ea476d4-69e5-51cd-9f5b-0f43d7b03826",
      "id": "CVE-2026-43513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43513 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88f36268-b6b2-5884-893a-a94e17e3a888",
      "id": "CVE-2026-43514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43514 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62ca72f7-e76f-537e-83bc-9b60e09b1523",
      "id": "CVE-2026-43515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43515 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.50-tuxcare.11"
    }
  ]
}