{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3bc089e7-cab1-51ab-805e-6e400ae4dd73",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-util-scan",
      "version": "9.0.75-tuxcare.1",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:1b29285e-6cb6-5917-8c01-d65e7d3c9b68",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-11996 does not affect version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan. Version 9.0.75 is not vulnerable. Summary: The target repository is NOT vulnerable to CVE-2020-11996. While it contains the affected file (Http2UpgradeHandler.java) and method (closeIdleStreams), the implementation uses a semantically equivalent mitigation that prevents the high CPU usage vulnerability. Instead of iterating through all possible stream IDs, it uses ConcurrentNavigableMap.subMap() to efficiently extract only actual streams within the relevant range. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dff842e3-0530-58f7-9edd-49b2e82a4ef1",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bed448bf-38e3-5ce8-96bd-34a4e11446fa",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan. Version 9.0.75 is not vulnerable. Summary: CVE-2020-13943 is NOT present in this Tomcat 9.0.75 repository. The fix that moves the concurrent stream check from headersStart() to headersEnd() has been applied. The concurrent stream limit check now occurs in headersEnd() after all headers have been fully received and validated, preventing the header pollution vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d964313a-8fb2-585c-b7b4-2317b01da7f6",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-9484 does not affect version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan. Fix already present in baseline since 9.0.35. Verified in java/org/apache/catalina/session/FileStore.java:303 \u2014 canonicalFile.toPath().startsWith(storageDir.getCanonicalFile().toPath()) containment check is in place. Advisory range 9.0.0.M1-9.0.34; 9.0.90 is well past the fix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da504d7f-3758-510d-b382-21c0c1fdce68",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcca47d0-e957-566d-aae5-9d789bc5f52a",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7793278-0019-5195-b5e1-0bb9f52306c4",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c94d8a5-4b2f-5e92-9f22-3c4ca05fd062",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c699db0-3bcc-5b7e-8488-2b06366bceae",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04e27dca-7725-5ac2-8956-b1d0fe601e43",
      "id": "CVE-2023-42794",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42794 is fixed in version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab63e792-f089-50dc-be06-8f16390eef1c",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42795 is fixed in version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81e1f20b-2e29-55ed-be74-b80afa23f921",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c51297c1-6624-5d1a-bff0-af84032edd6b",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d5a32e0-1ca3-5e48-8d46-7b317915c153",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-46589 is fixed in version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18488864-f125-527c-8d97-e941222103df",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfe56765-ecbb-5795-b0ce-5b0d5adf5a06",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-24549 is fixed in version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1759a406-e4f4-51b8-9bfb-dd45f4949578",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63761b0d-4450-5cef-b8d3-5f3eb99d6751",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34efb7f7-9989-5111-a2af-f1c64b4fc875",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a541111a-e2dc-5b71-bb9c-e4f14ae2b42c",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3265bb18-c326-5296-b27a-c808e0d0557e",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-54677 is fixed in version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d940f92-68b5-5353-93aa-46f6c95b4a4a",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40621dfd-af15-52b2-8c9d-43b468c4898f",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8120700-c0de-532d-ac28-ebb74e06ae98",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-31650 does not affect version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan. not_affected \u2014 Apache Tomcat version 9.0.75 is not affected by CVE-2025-31650. The vulnerability requires HTTP/2 PRIORITY_UPDATE frame handling code (RFC 9218) that was introduced in version 9.0.76. Version 9.0.75 does not implement PRIORITY_UPDATE frames and therefore cannot exhibit the memory leak vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10c26db9-4e3f-5c8f-ab2f-80f1bcb9abe5",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41646a12-bdd8-591f-b4cb-01db49da179a",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:417c1c71-a5c7-5632-9b65-013c14868857",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df4dafca-1eb3-529d-8b6d-8f39e9669ed2",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48989 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:825d40ad-ec72-55ca-8b29-58b5f6fe85a9",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17267949-a171-500d-870d-6be705b0ed7b",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45455513-3571-5a9b-801c-38bd482c9a52",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52434 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08301fd5-be8d-51e3-bceb-702971472970",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52520 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:748bcc24-5435-5060-8db2-00c7aebb6757",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-53506 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a15bd77b-61a2-5db8-9938-8ab228ee61cc",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55668 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac0fff73-46f9-5590-9651-35aceaeba666",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7cd2aba-fe87-5de2-98da-04f09bad19af",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55754 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d529ce7d-1599-588e-a329-b3321c08ec83",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-61795 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1cb47fe2-4c2a-5ee9-a597-2d10c3eb2593",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fea5bf02-5200-5baf-8910-a1d984c38b86",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:100848fb-2049-58f0-a6e2-feab96b51784",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85c67c11-b2e4-5efb-8267-98605b82f95d",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f13e69d-fde3-57b6-aca7-72dd6a485292",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f06024f-4664-5f61-af66-17c02159dba5",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d6c561f-f1b0-5cfc-b3a9-a40608327f0d",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84030ce3-020d-5e6a-a477-05d007e38bfc",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34486 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:496d21d7-8097-5802-9aac-26700460b8ce",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3ce9a09-dca0-5e16-af47-1d9262561547",
      "id": "CVE-2026-41284",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41284 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcf14a3c-8873-535f-bc42-3c52a5d61680",
      "id": "CVE-2026-41293",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41293 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4cabb39a-db04-59b2-ac60-09d623442f45",
      "id": "CVE-2026-42498",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42498 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:802a484d-466a-5407-8560-38a022548da9",
      "id": "CVE-2026-43512",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43512 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2c606ee-4ea5-5b3b-a226-e539dac89187",
      "id": "CVE-2026-43513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43513 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ffc80085-4635-5792-954f-17e399a1fcdb",
      "id": "CVE-2026-43514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43514 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40a4decc-c432-5aac-b537-65e8a552dd25",
      "id": "CVE-2026-43515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43515 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.75-tuxcare.1"
    }
  ]
}