{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:029a4fa1-6f9d-5a51-84c7-1dad1de870d6",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-api",
      "version": "9.0.50-tuxcare.4",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:92064dcd-03c5-5ecb-8e59-2a48ba2fbb56",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1c6a241-2594-5238-bc5e-d3b28727a368",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82feeaad-79e1-554f-b45c-04f363afd3bf",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1f8c618-ad20-5523-a201-3a2213f84607",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:381bae1e-4276-546a-9049-077393664bda",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1dbe8ea8-a265-565a-93c7-16640bc626a2",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1e17917-7256-5124-bbfa-94d47dc43fdb",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8e50e56-4ae2-578b-86c2-9a69f0503bf5",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:182bd3e1-8a64-5335-9478-9ed6a5540b69",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-29885 affects version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e07a5df0-2bb0-54ad-bb8a-36351b60eb8a",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:183bc7b8-6001-568b-89d9-341e7a4281df",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0365e825-f89c-509a-88e5-1f12b7766532",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef31df1b-19a0-5d63-8624-0b66a404139d",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-24998 affects version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ede27edc-b5c8-500e-9eff-439a71f68c00",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17059446-fe4f-55a7-bd07-1d188e68978a",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab161a09-c912-51ba-af77-edbd0144166c",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42795 is fixed in version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00bfdd6c-8361-5c1a-9b35-69ce7acd07c4",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9cb14226-95b7-53d5-a7db-bf973405e693",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:247e2a02-9e0f-5292-826c-9286c3e34110",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46589 affects version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46f08be2-5966-5c05-b19a-368418bdd22e",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e38e8ad0-eecd-5b98-8931-e0f15e87b574",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f1834b7-ae83-5828-8e90-29374ca91843",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34750 affects version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ee9121e-eaf7-5524-b6a4-df2808d341cf",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba37af3d-8448-58ca-894e-1c1bfc16821f",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a592cd8-562c-5bd3-b15b-f178be5145ca",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f88bd217-08da-578d-896f-6c378f431dad",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35f1c109-3ed5-5226-a6fc-b5e4875ec0d5",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56337 affects version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfe54b11-1853-54a6-90c5-34183deee406",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd8df85a-9462-5de4-854d-652a9ade6d27",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31650 affects version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:614b26cf-1a0f-5801-b5c7-696b292a7db9",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94e265ec-6e41-5e80-9094-805af3b03a01",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-46701 affects version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f112882-3b2e-5de7-adbc-de2a4fdf1876",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e8fe58d-ea80-5e26-ae67-4dd11ff93651",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48989 affects version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e25c2ce-6d4f-5e1e-a43f-ff5938323ddb",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c08e753-44a2-5ff5-bd4e-211029305d39",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13af0b48-596b-531d-89ed-87af18dd3d0e",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52434 affects version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ccf7ea9-4873-51d4-8ad8-30a47bfab4c4",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b00152ab-b153-5e70-b427-6cfa398ca469",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3ffc145-5987-5e44-9ba3-15c441e2ed1c",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e13ec2d-d2fe-5331-bd55-cec6cea3953e",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a15b5782-f01e-56e0-907a-aa53f00e0de1",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c9397cf-bcca-529b-9ee3-97777ff97f3f",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82981892-9adc-51a5-8d0d-79f6c30a0601",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54d11047-659e-5ec6-86a7-49c9d7403e12",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58f943b2-2a29-583b-b91a-f2a70d6fa753",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9fbf37f-df1a-507e-9577-56476d36ebb2",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05af168f-19b6-5e9a-adb8-56f48b271c8b",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:219dfcdb-92ad-5670-82b0-a852d9d414ce",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e721dc87-c625-5378-8810-58de9462bceb",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fc5a803-8e5c-57c6-9258-e4e3c1d8834e",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.50-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.50-tuxcare.4"
    }
  ]
}