{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:2c3ca674-6d0b-50dd-87da-4278223443c9",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-annotations-api",
      "version": "9.0.46-tuxcare.4",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:ac9e1bdd-0621-51cd-ac69-620ad50586c6",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39b7dde8-bb32-5f14-aff7-c0f0033b8928",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb1478ba-b327-5b6c-9565-397fa3e86f28",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:daaab40b-bc0c-5c05-8ec7-43bff8360bc4",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:679ab85d-57a7-56f3-9d4c-62b5d48c9788",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:922a52da-59b2-52b8-ab4e-5eaf4cb99e0b",
      "id": "CVE-2021-33037",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-33037 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7d72a81-7905-5df6-9168-d7ee3a5c1518",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e3f250d-3e48-5332-ac44-97dfd7fe7274",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ffd72e75-e5af-53a2-a71c-ccdab3f5351e",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e08e104-669c-53f7-bb8c-67647e3b445f",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc77323e-0ed6-5125-a9dc-662bb913dba7",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-34305 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2728aa9-f713-5ac3-9bb1-cae664ba5a74",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8973f75e-4060-5df3-bd4e-99cf76caf893",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e407656-fbac-51b7-91bd-aae75c5564b0",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-24998 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8652fa20-252f-52cc-920e-57caad795253",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2930649-51de-5f79-9189-67b3ea9f58c5",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:116d3666-fb4d-50ac-a529-5fedc1da7711",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-42795 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6be7661-651b-532f-930c-7f63d27ca108",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dccfe8fc-188d-52ee-8ebd-71522ad5ee7c",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0483fd50-176c-539d-9b6a-67e6a2c7d8a1",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46589 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1882562d-acb2-5a48-a9cd-c5f091edc207",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4950d394-e451-596f-942a-50a2ee7381c9",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6836a7a-6ae4-5bc5-aa21-584c0beb3bee",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34750 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b20a556-7c74-5bf3-bc14-fd04bcac0e45",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b373ffb5-e776-56fd-9681-da447b126df1",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed3ca848-30fb-5358-a834-560b8fdcf257",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6cbdb91c-0f16-5f14-89fe-03350d66b323",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:147e89fc-1ceb-543e-a028-ce3d538c807c",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56337 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:051e5ff0-9ece-579a-becf-09e51dc3a389",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9525a40-070d-5db6-a6c7-9ffc449df00d",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31650 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5c4031a-e9a5-5094-8b84-92c4cfd403d7",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca6b3d8d-b1b6-5c5e-8f2c-a4d1fdff784d",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f232273-374e-5718-871b-cc1e63040d60",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7711c1d-d9ac-5c46-a65a-583516f73aee",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:165a0ecd-5d5d-5a13-a8c2-7cb18d35c6c6",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78b68945-505f-5fe3-81de-fa783cf99cce",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0eec133-49f0-5ce3-8980-77eed475edd1",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52434 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68d809d6-c93d-5f30-8f1d-15edd86c27fd",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77923287-fde2-5a51-b738-d263adf0d70d",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a59ae69-2a3d-56da-9872-c595e8361b36",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e473b1e-c06d-5bfa-8c6e-9bfddc4e77f1",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55752 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8696cbf1-8b58-5dd8-8843-86460d13a220",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99a6a20a-ebaf-54eb-a931-1af5dbf8d539",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04fdc7cc-b85f-5894-b486-05a473905b6b",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a31ae92b-7cf3-5a31-947c-46b764592ee1",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a100602-eeda-56eb-8430-3e27de3c80b6",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d632dbb5-afd1-52ec-ac3c-a7b372353fac",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48686c6c-65c4-50e4-828f-223870882dac",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6efc9359-8fe4-5907-89e3-eb39b244bb52",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5e9d66d-0b6d-51a9-a179-81d58deb720d",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31f625e3-0fee-5bde-9830-2859b97c0831",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.46-tuxcare.4"
    }
  ]
}