{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b965a7f0-78e4-5749-8683-48e38d5a7055",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-websocket-api",
      "version": "9.0.50-tuxcare.12",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:566654b0-cc00-593f-9f2a-6069ad09a471",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-11996 does not affect version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api. Version 9.0.50 is not vulnerable. Summary: The target repository contains a functionally equivalent fix for CVE-2020-11996. While the implementation differs from the provided patch, it addresses the same performance issue using a more efficient approach with ConcurrentNavigableMap.subMap(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:243137a7-fb73-5074-bba2-84e52af0324a",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89510eb5-d3c8-5259-894d-6aaaf7bda14a",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api. Version 9.0.50 is not vulnerable. Summary: Target repository already has the fix for CVE-2020-13943 applied. The maxConcurrentStreams check is correctly located in headersEnd() method, not in headersStart(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b488e4e7-f71c-54bf-90fc-4ae1320637d6",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-9484 does not affect version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api. Fix already present in baseline since 9.0.35. Verified in java/org/apache/catalina/session/FileStore.java:303 \u2014 canonicalFile.toPath().startsWith(storageDir.getCanonicalFile().toPath()) containment check is in place. Advisory range 9.0.0.M1-9.0.34; 9.0.90 is well past the fix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7d50e79-2592-50a1-8ba4-815457d627a3",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ccaa794-ee15-57e7-b82b-44eecfe644e0",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a00910a-09a9-56d5-b5ab-a65b3c9a7774",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c533b6d-f4c5-5bec-87d7-07807fa1fd4d",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5c91f95-18a1-50a0-a278-7e3d75ee581a",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbcd638d-4efa-5456-bf51-96835d657a67",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47ced185-d369-5406-b9c4-cf1201a09969",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c9304f4-be14-5fea-96b5-87a30db49834",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bf5a220-cdb4-5336-8718-983851cb0ad1",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-24998 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fa2285b-f499-5bce-a61c-4b9ff598970d",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3427a5d0-e1c2-56c8-bd54-e16ba57a1ddc",
      "id": "CVE-2023-28709",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28709 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1078d894-02d5-5d0c-bc3c-3ac79bf694fe",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c552697-91a3-5760-ad46-eab85036d727",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42795 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1ae3d73-c39d-59d0-b68c-76e49900fe0b",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a60ada76-75fc-57f9-bb15-bb508f932c74",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1502e614-d5e0-5a6b-b47e-894263a2fa1e",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-46589 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e419edb-872e-54c7-b00d-e323a3069af1",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbe1b24e-68e6-505b-80e3-1a9b0e9ecf3d",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:834358e3-4528-5418-b538-1bc6f135db50",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f335de92-336f-5c00-93f6-97064c84785f",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bdf779d-2fa4-5855-b843-4703f22ac2cb",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c1457f2-7e49-5982-817c-211e248c97f4",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:609d2bf7-1e93-5164-83e7-38ca67ee1ffc",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04570b77-f815-5531-b28b-c501f7801ca5",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02e621bd-c743-5657-bec4-12a6e7a6190f",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5fe54aa-b7f5-50d3-ae7b-b36861784ce7",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-31650 does not affect version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api. 9.0.50 predates HTTP/2 RFC 9218 PRIORITY_UPDATE frame support (added in 9.0.76). Advisory range per NVD/Snyk/GHSA is 9.0.76-9.0.102. Code inspection confirms: Http2Parser.processFramePriorityUpdate method and priority parsing in Stream.emitHeader do not exist in this baseline. Vulnerable code path is absent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba909815-b18c-5136-99af-31e571183371",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8402e14-7f99-556f-889d-4987ee4b8436",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f43f108-37ac-58bb-97e7-7a27ef17b071",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d6e2ae9-0079-54b9-b585-c4a4fb6f30e2",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48989 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3b3a87c-650a-50e1-973b-19ab366e0eac",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2091b9cd-9745-513b-ba6e-198425fdc9bf",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:828f83f8-5351-5cb9-86e0-51bf78cbf50e",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f67e971-9f57-5a6a-afd5-849c0e870233",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87ebc9ec-9b3f-5d8e-bc07-82578aefcb28",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e40e804f-c6dd-5e5b-b771-f1c8702f9e2f",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e728cb0-8aa0-55eb-b586-d1af929c71b2",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79635632-6845-5940-a355-d9bfdd57c335",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37fa7186-3028-56a5-9d27-d5be44765dee",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:184396c7-e5b7-530e-b69d-cf645e39152c",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45997d9b-2986-5bca-839f-362421ccdf5c",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d9c7c7f-ae43-5bff-a2f1-e8cb758cd6fd",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c4c7acc-40f7-5b22-9a28-b2c9969522cd",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3051395-32a1-57a8-92c4-fcf05ab9dd7e",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d7ab216-3933-50ab-a0b7-f12815a7ade0",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3bae15d7-f80b-5277-94e9-98e7255e0639",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5de5c8b-5649-57a4-a545-fcfb414b8026",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34486 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f87186ce-464a-58b0-842a-930ced37ca53",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc1a9c0f-dfd9-59d2-9ccf-cf25f5e16cc1",
      "id": "CVE-2026-41284",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41284 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02000f38-c881-5c87-9d2d-8622ae16f127",
      "id": "CVE-2026-41293",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41293 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97f7bdd4-7a1a-59f3-b78c-1d00f5b5883b",
      "id": "CVE-2026-42498",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42498 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb61ab44-802e-5c3c-92b2-0e28a61df7d9",
      "id": "CVE-2026-43512",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43512 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22d898ee-2c37-5864-83bb-fce734be82b8",
      "id": "CVE-2026-43513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43513 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d320ead-e828-531a-9d62-2e068fde88ee",
      "id": "CVE-2026-43514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43514 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e6de68a-c8dc-5211-88a2-49868ad51e78",
      "id": "CVE-2026-43515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43515 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.50-tuxcare.12"
    }
  ]
}