{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b23d2c1e-6031-5435-ad91-21eaf63e5dda",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-pt-BR@10.1.42-tuxcare.1",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-i18n-pt-BR",
      "version": "10.1.42-tuxcare.1",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-i18n-pt-BR@10.1.42-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:eabb0087-565e-5062-bfb9-9eb37e3e1d56",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-23672 does not affect version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-i18n-pt-BR. Tomcat 10.1.42 is not vulnerable because CVE-2024-23672 is fixed in 10.1.19 and affects only 10.1.0-M1 through 10.1.18, and 10.1.42 is later than 10.1.19."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-pt-BR@10.1.42-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6052619c-13df-5e9b-b8e4-214ec81b77aa",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-24549 does not affect version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-i18n-pt-BR. 10.1.42 is not vulnerable. The issue is fixed in 10.1.19, and 10.1.42 is later than 10.1.19, so this version already includes the fix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-pt-BR@10.1.42-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f1c047e-9164-58c1-9a6d-13fd515be365",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52316 affects version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-i18n-pt-BR."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-pt-BR@10.1.42-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f3ed57c-ff9f-550a-a0cc-d216e0030d69",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-48988 does not affect version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-i18n-pt-BR. 10.1.42 is the first fixed release in 10.1.x. The fix is already included in 10.1.42."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-pt-BR@10.1.42-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5dff990-c441-54c4-b0b1-2a989f784c3e",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-i18n-pt-BR."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-pt-BR@10.1.42-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e07449a7-30dd-5dd9-bc11-9037f7b4ca25",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-49125 does not affect version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-i18n-pt-BR. 10.1.42 is the first fixed release in 10.1.x. The fix is already included in 10.1.42."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-pt-BR@10.1.42-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce7fc560-273f-524d-8545-ed09a07808d0",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-i18n-pt-BR."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-pt-BR@10.1.42-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7aa43592-2e60-53c9-99bb-ddcaa3d4687d",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-i18n-pt-BR."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-pt-BR@10.1.42-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41ca7c70-5b6b-572b-b2bc-561bdfbf862e",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55752 is fixed in version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-i18n-pt-BR."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-pt-BR@10.1.42-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4cefaebe-bcec-58f5-90ad-599fc2d16434",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-i18n-pt-BR."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-pt-BR@10.1.42-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a66b0a40-2eb2-532b-9274-3871835a21c5",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-i18n-pt-BR."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-pt-BR@10.1.42-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:487a34a4-b217-52d3-9779-d4bcf66d97d4",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-i18n-pt-BR."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-pt-BR@10.1.42-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a497eac-4d78-5301-9bf9-f356980daee5",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-i18n-pt-BR."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-pt-BR@10.1.42-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9526782d-9027-577a-8acb-cf77aca3d3b3",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-i18n-pt-BR."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-pt-BR@10.1.42-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8bfc9d5-a2ea-56bd-add3-33fdd30c72a4",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-i18n-pt-BR."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-pt-BR@10.1.42-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7fafba72-f45c-56cb-8a16-11978d2550c3",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-i18n-pt-BR."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-pt-BR@10.1.42-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:829b3fda-63ce-5d1f-b376-4df5434e2d62",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-i18n-pt-BR."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-pt-BR@10.1.42-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ba56b4f-6947-5aa6-ae84-814030262f7f",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-i18n-pt-BR."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-pt-BR@10.1.42-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:189800b5-19e8-5ce7-874f-19c75d732ec5",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-i18n-pt-BR."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-pt-BR@10.1.42-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4720fc28-5fe5-5422-a5d7-46f4e3d722d6",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-i18n-pt-BR."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-pt-BR@10.1.42-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76ede524-6ad3-5d6c-8384-f5df5a3da585",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-i18n-pt-BR."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-pt-BR@10.1.42-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b67a6d8-fabb-5dd7-83d9-2ff7efbddae0",
      "id": "CVE-2026-34500",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34500 affects version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-i18n-pt-BR."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-pt-BR@10.1.42-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-pt-BR@10.1.42-tuxcare.1"
    }
  ]
}