{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:fca0ce73-cdb0-5ec7-aa4b-3df471d5b4a1",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-util",
      "version": "9.0.50-tuxcare.2",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:320210a7-9c4f-5bbd-a183-4d3d6ea6d6f1",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d251b7e-3491-5bbd-a1b3-d608b82d98b3",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ccecd9e1-0cd6-559c-84af-27b32e2057fc",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ee4c014-7867-5121-8bb1-38856b8433a3",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72039edc-7859-5b85-8ceb-fd8924a42609",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d64b1629-071c-51c1-8647-6589a853cb6f",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bca931c5-f742-51c2-800b-0f9b048de041",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad28b5c1-6776-5d74-87f0-8862eb95c4ea",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3415a5dd-4a42-55cd-b87c-e6d322c4d937",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-29885 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:040aeaee-3faa-5a56-b860-77304b4b562c",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea3c6fbe-c964-5e30-8f3f-f444f78c892c",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe133ee9-2f3a-5e56-80ff-75be7cc44c63",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da4cc9c7-85c1-5a67-879a-adac67585033",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-24998 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c69a87d-0a70-5d6f-9a94-8c893aedb4c3",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b8343ad-698f-5032-8b8c-722a9f76f19a",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9820a165-4d91-55d0-9de5-c7ffa9c6078c",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-42795 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fd74876-2f5c-5860-86eb-3409cf20303b",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f67e2fa7-46ef-59ca-92d4-048dc12adf76",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f8725e2-b57b-537c-8300-100d8dd0fbea",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46589 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bcbe7c5d-ffa8-5bad-b8d9-1d7a8b21f2b5",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:863b67fb-96fc-5fba-9896-9ab3ae60a84a",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3fbac3fd-a370-5836-b527-123baafd49d3",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34750 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9087503-4cc0-5f71-834c-382e2e334d86",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96ad16ef-3a51-505e-a08a-8b9d0fdcc41a",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b086d105-f481-5123-aa11-6d4b39d7464f",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:581a4c0c-b187-5167-bc5c-dd71077cd83d",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73394574-9cba-5bc9-a63b-3833f3747c7e",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56337 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7558467-b03c-5c60-a834-4997afaa0637",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2806de9a-554c-5a1b-98b9-440ce9b1b2a8",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31650 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2abb4e06-1804-5671-9f10-8e5008a0ef9e",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31651 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00d6874d-ada1-5627-819b-9245bbf6c7be",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-46701 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7448feab-1fb7-57b2-affc-b0016fb1e3dc",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1532b75c-9f15-5213-afb2-933b85239ec8",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48989 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f0a071d-0993-5697-8cec-b3464956df27",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a0ed9bd-53b8-5b91-a618-f5e890543175",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e04b218c-025c-56ca-b1c8-e65aad893848",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52434 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e95f657-0952-5cbf-8f46-fb974acdccba",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7850ae8e-f1e9-5e80-953c-06469ab4fc9a",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8cb28f1-c3ff-53bc-ac14-1246f5a92aca",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d770847-88ac-535f-a19e-f99c5a13bea4",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b451b260-2abe-5d22-b67a-eb313b5534c1",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77bff2c7-1f5b-518a-acf1-ce432d2b3a95",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a36649a-b266-5499-9ff6-36807bf4c508",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3fc0bbba-72d2-52fb-a08f-fb4b10ef30bb",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:976c05ad-6588-559f-adf5-b6befb64f298",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e47a7b16-6873-50e6-82de-36725e884246",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1a0b86b-216b-52aa-8bd6-7219ae2a3961",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5ee3aa6-ce29-562d-a2d3-23f006511506",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7792af04-ff47-5b78-a381-64ddbcd89f6b",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2aca55e3-ee82-5c6f-afc0-de9a62523501",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.50-tuxcare.2 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.2"
    }
  ]
}