{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:707581ad-3d46-513d-b696-c04706a05619",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-util",
      "version": "9.0.46-tuxcare.1",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:258096f4-e736-5108-9804-8b9dd3ff039a",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff54406a-2c8c-51b5-8824-95050a2896a9",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ca5f8a2-3d50-5fc7-a967-4481a1a24f34",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16627b0f-fc59-5c29-ad9a-aeb679a9bd9c",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18381340-3a00-5183-a0cc-7512d0045524",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:050bcb27-7dd2-5d19-b454-5101050f26cb",
      "id": "CVE-2021-33037",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-33037 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea9c887f-5943-5b40-b15b-ba5e3ec4c457",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17a262e2-335d-5908-92ec-44db35d12157",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1bf8f7d-20d7-5adc-bb1a-78c99d64f3a9",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06b3dc58-5b8c-556d-a1fa-50ecef9a093e",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfc7848a-fa04-57ed-a193-d688bef2d16f",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01a988b8-5634-55b6-8617-926503f6b674",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9044f09d-59d2-5c9d-8152-aa47c36bb356",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1c7be84-1a73-50be-8153-b593a99c2480",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-24998 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7989c11-6a56-555b-b441-bb727d8e0b30",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8922a7c-f02c-5d58-bca4-b030bf192046",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99828e77-cea7-546d-aeec-03ae412192b7",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-42795 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b34170bb-0a63-5ac2-946e-ddc6df97e21c",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6766c24c-e6e9-5f6a-8a7b-bdb74e88152d",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12040d8b-a76f-582f-bd6d-9b9305057922",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46589 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b27431d3-a342-5f87-abf6-05a0fbb10c9b",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40fc4e6c-2262-5357-8e24-a583758f3e4a",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9fdb5bc8-20a9-5fcc-b7f0-d57b6fea5dfc",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34750 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:359e8731-dffe-5078-9982-0104c8f84368",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7b92c71-f64a-5fd7-9d30-1ddbc1a9664a",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a424a49-34f6-507d-801e-8534ee5affc6",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:958eca2c-11be-54de-b229-5630cb7a0f48",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b3d0368-2c17-543b-a0a5-04f5155f1b38",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56337 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5359b370-fdb5-5dac-8acb-b91880a5fe7b",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7833b68e-48dc-5398-a356-753424186911",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31650 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82479bf8-165f-560b-8943-320fdbf7e73f",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f49792fa-0bb4-54ea-b47a-6497bda2a1ef",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-46701 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:333fd3a8-255f-57e0-97d3-671e1406b658",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48988 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f198749-5100-5b7d-b946-a8268b2e5b3d",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a7b3249-7faa-5bb2-8f60-8b1ba0c35a9e",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3840fbbe-777f-507c-84b2-816849b2c2b1",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc120e74-95bf-53c8-8396-a1e665900b75",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52434 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23052180-278f-50d2-829c-78b5e52c5b80",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5de1dfc7-ac28-59f7-bc6b-b437ad610772",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fadda686-c6e6-59e9-87b7-304d54724cf6",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:888544be-9808-5c6c-b913-3d1e487144a8",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f41e4458-37c4-55cc-b900-5aafc728a281",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43d79a00-2107-529c-81f0-f87f4515d01a",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:193d7675-e248-5c1f-84ee-f6e6533916c3",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e674b635-905b-5187-bc85-c37bde54a5b5",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1608817d-b6f6-5538-a4b8-c760a69f128a",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be45c0b4-6044-58e3-afe8-599ffe2eb0d2",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7833b92-b428-541e-a8d5-4492137117d2",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7f88598-e352-5bba-9176-f86b95fc8fcc",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d161c446-9fc4-5076-b52e-d2ebcf0a0dc0",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:134ddfd2-d844-5a98-8a9f-e27e103d5390",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.46-tuxcare.1"
    }
  ]
}