{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:60330255-92d9-5a22-8cf5-bc934b35ca01",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-api",
      "version": "9.0.50-tuxcare.2",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:a125d366-655f-5c41-b048-e9777b57c9f2",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca102b40-7316-5abb-b4e8-29468d081463",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31882d5e-f10a-5ec2-95e5-a6e1f2f1961d",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e6e7335-ab60-5fcc-82ae-123cb1e65145",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a07dfaad-07c9-5b8b-9ad8-e7ad4a8de820",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dccfb958-043b-51e2-a576-a83fa02e2eee",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f680c785-eed3-5389-a116-ac43c16fcf23",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4f5f64a-2ec9-5f7d-8ce3-6c21761a8130",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf8598f7-464a-5e10-ace5-0a9eed2494fe",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-29885 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99390cab-213f-5c95-b985-2c7d6b4ac413",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff63de39-f724-5eeb-b6da-c24a62c7c37c",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7885a3e-569b-5677-b146-368b8f891df3",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6a7feb7-d4b9-593e-b59b-0fcd87eee1fb",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-24998 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90a991d9-67b3-5c3f-91f2-2576e7ceb16c",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:206eb3f0-99f8-569b-8d5f-4887c5af8967",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fb3b0be-caa2-5ca3-a0a9-bb8a325dbc8e",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-42795 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:366e7fc2-2fd9-5584-b1c5-2c0e1efcd092",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d62ec87e-0388-5684-8107-df65191234d0",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2cef9933-8fce-5bdd-814b-e1bb1a436907",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46589 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6595c3d3-55d0-5ddd-a405-0a57a1b51b42",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1f0cdb7-dd38-5822-b276-62226b43d1aa",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:336c7a65-7d43-55e7-884d-b94e836c0601",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34750 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6a232d5-772c-5994-84d0-1e0fac08cea4",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98d73854-6906-5501-b383-a0fe525bb6e6",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ccfdcded-6d35-5c02-87c8-aceade309500",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ead4c94-0cdd-5ae0-b81b-937e29186f51",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f879df6a-3c67-5647-81cf-80c91b6e3b28",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56337 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0213f76-6b41-5e9c-8256-51fd276f3e41",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37292160-5314-57e1-aa9a-cbc965c231bb",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31650 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6bd4cb6c-059c-5ca9-bc47-308b05d78f3d",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31651 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4add0228-873a-540c-b13d-7d0bd29e6c0b",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-46701 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06f34da9-7c7d-5350-8fa5-abb8cb91a6ab",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce06a6d9-a50b-538d-b158-25c608f434b6",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48989 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41a6ee12-52d6-5d48-b0af-031de6a30423",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:797f5642-e575-5785-a9d6-e8e959b2f1f0",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e4b4c3d-551b-57ea-8029-1953394dfef8",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52434 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9a57e98-58dd-5949-922c-3a3256bc6539",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16658615-a131-5626-a0b4-cf42fac6cba0",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a09b0d03-178f-574c-b043-26656a011627",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d4ea7e6-82d2-59ad-b3a6-7f5ecc44ddd5",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:938cb041-0a9f-520d-ac94-977f39b91c43",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67d879b1-f4ce-50d1-bdd7-1fa1f1a9d464",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:096d2254-24fe-592b-aabb-084dbd29e606",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d2098ae-0a2b-57af-accc-13d85e4214fe",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79734ac5-3e39-5cca-8cd7-4fe344eddaf7",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3b218a8-3eef-5646-a1f8-8476d51f6572",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f576a40d-ed8d-52d3-99e5-049497e5ffae",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f06c2dc5-8b13-587b-9bb8-a8a6c0c14799",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4a8d91b-ff53-5722-ba0e-52f1322b7c5c",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:572c4394-7b4c-50e5-a7cf-e950e9a4b05d",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.2"
    }
  ]
}