{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f76304a1-434d-5c0d-8e3a-d23e9fe2077f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-annotations-api",
      "version": "9.0.46-tuxcare.2",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:f7a1746e-058c-5f99-9b9b-8641987b086a",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9f6a308-4e23-5d0d-a94d-b119462ad8b2",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4c3441d-c6c6-577d-8796-26ed40c78b84",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d4fa7d0-19c9-5096-b032-b41798009819",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bcd2be1-2b55-5c81-b3c1-a02868c7dbbe",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a87c7bf3-01b2-58ba-8cfe-c6b378d57248",
      "id": "CVE-2021-33037",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-33037 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:371ef99b-d782-58b4-975d-c74a95b6723b",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b57a2f3f-debd-5db8-b713-c222453a9b85",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:263afec1-bb56-50ad-ad9b-72d2f7d279c6",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5dbb93c9-a28a-52a5-8a59-b3b29b166bec",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:986970c5-d11d-5d3f-b7e1-a41e294b8a94",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:677453cf-e2ff-5642-9cee-8d17bf1a085d",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6563712-17eb-5840-91dd-697ee1bd56fd",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:587dffaa-a85c-5c83-8d88-7a0e987bf896",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-24998 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a7b8136-1177-5c1b-90de-68b47a523628",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f385361-56a7-51a9-8d8e-85d87a8cb07f",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcaac2f7-5e0e-5c9f-b9ba-70f94e0fa401",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-42795 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c10a40a4-cbba-5ff6-a598-b2f0f27cb36f",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c517f66-350c-5070-9b02-fef5dd588cbd",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce5bcd37-804d-5f2b-b2f0-ed169fc82426",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46589 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7405804a-a4d6-5292-af33-0df334b6c14f",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a8e1d37-88b6-5242-b134-e8d9c04b3663",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e564d1a-bec3-550e-9d9b-d3e165604022",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34750 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e61272ef-cfab-5637-88ba-f55ebf3264ec",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ac051e0-4f7c-5f57-9299-8bce57e53678",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b7fcab3-86d5-5eda-a601-2879b83f87ae",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27b979ed-b6bd-5185-801e-dfb47604daa4",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb021ea8-1e3c-56ec-b9ad-00624c975fc4",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56337 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb065275-7495-5f42-89f9-7249716c3431",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ebb450d-8735-542d-bb95-d59060a43817",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31650 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef337f8f-04df-528b-8ecc-518150ae11b5",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f81af7b4-8d53-55a8-9e87-08db154a8dfd",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-46701 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e6ddb0a-214a-51a7-bc3a-e6659ce0e165",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48988 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26ca3b10-d76c-5de2-a2e5-c4d0e1720335",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:391e45e5-00b4-5e7f-bdf5-41623cbabee6",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:366890d7-cf85-5ee2-ac3d-317a89f16161",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8cecdd95-5586-54eb-bd38-7c272749e9e3",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52434 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22186d11-7392-57b1-bbfb-86b3dd7d61f2",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eca835fc-ba6b-560f-a5f3-e293b312febd",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7553ca05-3c52-515b-af5c-996ff4b94c65",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85d206b3-7ecf-5e83-a671-2abe620c3a3b",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55752 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f618107-3602-5397-b178-99f8e106445a",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa655af7-4933-581a-bbab-04627a65e5e4",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bac73b65-be85-5b8f-8dfd-35bb5594919c",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:490082f0-4581-583b-a0c9-598cfd8483a6",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ba19568-8bc2-534d-b52f-48b155aa8d4f",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3764f78-a98d-57aa-a97e-b0a8d2d8bd39",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ccb30d9-e53d-5cfb-81fc-a300a98dc832",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08560fca-ef6f-57b7-9e63-4c055fbf7768",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9105d48-2d68-59de-ad9b-9afc29c244db",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:794e5614-6614-53f1-b8b7-a5a413239dc9",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.2"
    }
  ]
}