{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:656c651b-6281-54aa-98fc-033e2d017616",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-servlet-api",
      "version": "9.0.46-tuxcare.3",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:1db646a9-0e16-5424-867f-d98dd0ccef7d",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1bebb72-906e-5b85-9223-33bfd3de4e4c",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6618cfb-0598-5c24-8977-ecab67cab30a",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3bb41552-405f-58a8-bc54-7a3b46a36caf",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:757fa827-cacd-5507-ab75-fd9de037b805",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:036da919-011a-5d9c-b41d-b07c539ae8bd",
      "id": "CVE-2021-33037",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-33037 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef7ff943-1074-5314-ba8d-5fa72c239cee",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e87a6ddd-546f-530b-be32-6f6b34968785",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb8ca624-4c41-55ff-befe-c5b3751f4a26",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d60875a2-5244-53c3-b0c0-940cf96b1586",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed331704-5f46-555f-a63e-5be71d738932",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-34305 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3005d675-3df2-5c6a-82de-759bca8f5d39",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97c73af7-b746-5add-877e-818f1741eb3e",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5c48532-2815-5ffc-816d-e90e83d22173",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-24998 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21436d41-ba8d-5bde-ae6e-067df75d4d7d",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0100cd8-c7da-5a69-b8b7-c9391dfa62be",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26e0a7ca-f0bb-58b9-abbb-bcf91e0a2cef",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-42795 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6414662a-3498-5de4-9cb6-d21fc430c893",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5d1b3b9-d80c-56ce-b8c1-abf6b74fd767",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17df3a2b-bc92-57a5-89f8-f45855e112a3",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46589 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1daf77d9-8aa4-529f-ac26-8f2255564740",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6cc534b6-dae0-5625-b1bd-22ef05ecdfb6",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c058781-a467-5edf-9d22-69947c80fce1",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34750 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0910ba19-e5c4-591c-ac92-e6bb8cf2f621",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e0692b4-b07c-5c9a-a728-0b94cb312935",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a676da8-29a6-5210-8f1e-afe566d6aa65",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3821a7fd-ee11-540d-8b99-9f1f6e266fd2",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5ca843e-4051-5af6-abf3-a8ad26c6a872",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56337 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ac5ca0f-ebb9-51a2-a0b5-4ec44bfee0e8",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ddc655dc-d4d9-5dcc-9199-8c12818f7979",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31650 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:988d1f40-3b8d-5b12-a2a5-1edd7cb3949c",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10232903-312d-515c-b027-4690d90795a8",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:310ed63b-e76d-5d97-a083-6eebb669e9a3",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48988 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ef62b36-94e0-5ac6-8dc6-cab1add317bd",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac2dd304-19ee-5fe7-85dc-7aad2321d164",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:daf7315e-73e9-5a04-855d-bc1308324ebd",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63bd32da-f85c-5d04-83b7-27bad0d2a4be",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52434 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:113a9351-e772-5b79-8b5c-1d3d7456083a",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:479cf4f2-ac30-5939-8c52-955cb6ac9c22",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f35c82db-daa1-5868-b240-bc97ce2d8dc0",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df76269a-ae16-58fd-bb25-c44d351e15f4",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55752 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a345110-68be-57e6-8b02-c6b17ad75230",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e1898f0-2941-5b4c-8e3e-dff417a69981",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60fe860c-44a6-5cc1-b1de-26f510d32bee",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1fc11816-1d94-5525-aa61-55042c3e25b1",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2dc3df76-5ca6-5552-9fce-fb3f44a41119",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e593ae9d-6a3a-560f-b371-aca2fca5e0d3",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7aff137-a093-5d13-9774-ec2f3af9ef84",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b01cddf0-6e2b-55b9-bc4b-4549515d8656",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76c6acfa-2f18-59e2-8aa7-d052344c751a",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4be4c369-c555-57bd-bdc7-69bb2601d07e",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.46-tuxcare.3"
    }
  ]
}