{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f7aa2ebd-9560-5c2e-b71c-c2118b8290dd",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-util",
      "version": "9.0.50-tuxcare.3",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:ad11fe11-6a91-5bd1-8904-acebc37c60ed",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95d77d5e-ac18-58cd-b519-c69c7e6f2982",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05754396-b1b3-5095-bc85-0cdf09b818e0",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f743868-ac0c-5e34-9f82-4a3438e40442",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:765f0251-1d3c-50aa-ac34-c79e019e93b1",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a3399e9-a8f5-5251-8405-3fc898b053db",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:660d3ead-3b52-56ae-8376-c10b4e36c5c6",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7900f949-d055-540e-b17d-1f107163a13b",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97112814-fb65-507c-9269-84cd027c1e37",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-29885 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3006e04-20f7-551d-97af-c2a42b052576",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:850a197c-1346-519e-a978-75e26f729f0e",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba1423f7-e0a7-5757-8afe-0f7b79e4c997",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e44893d-7d2f-51e8-8911-ed7cf5369b83",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-24998 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:156becb5-686b-50db-9f7a-9bdd6ae1915a",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0094068f-3f90-5c47-9864-9a132bf02f02",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2b58c81-4dc8-58d7-9e57-92ea30a600bc",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42795 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f20b1776-413b-5718-89f9-00d587bdbcb0",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de656cc2-949d-5dde-bb67-f5c50b1de7fc",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06db855c-f77a-5045-a9a3-9604c1a76d37",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46589 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a893e6ea-9fde-593a-bcdb-410003519f92",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5cfecbad-0978-5875-946b-e6335053cebd",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77c387d7-9603-558b-9bb2-d8461a4171c7",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34750 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8cf87c0-c6a4-5f09-b892-1961731a8ca2",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b65f4b85-b508-5d6c-bcf7-b3f189b203d2",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a03abf9-dd83-5c06-8058-d01f4d74ef72",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8600af6-4ff5-513f-ab55-35e0a6a98817",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:986305f7-c545-5c4d-95a9-02da9ff4efe3",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56337 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e500b50-cdcf-5ded-9c3b-4bb5eb349d1d",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a23289b-52f2-599d-9c43-70de2a941a3e",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31650 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99798128-4bb9-504d-a95f-a44d99811408",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31651 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36551405-4b34-5a77-a002-a128600af6c5",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-46701 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97860295-a02d-505d-967e-6210da4a47b4",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ca0605e-f927-5bd5-8822-a8ee60871582",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48989 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b69c860-bdf3-52bb-950d-b8d08ac09d57",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86b0a47a-b5e1-5d67-bacd-9e8e89c8aefb",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b36686dc-9b10-5d04-9e36-161ede55b45d",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52434 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99515300-41d7-560b-9a82-e8a8b66b26aa",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afb80f82-2332-5042-9286-f6ac518b7a05",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:247ec9ee-b0cf-5710-83ff-398be6c0e868",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99c866d8-bd32-5742-a9f1-6861813ae15e",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7816b8e-5c86-5371-bc10-42705eb16e2d",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b01f42a-cf26-550e-a3da-bc0118f33138",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c1d4e2f-b1e1-5732-bdaa-eb0d19971206",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b6c6a37-7fb5-5d1f-8022-9a684dbb54c4",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b74f3fb-1acf-5f18-9d24-7bf3656bb6ad",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bb7b7d6-90e2-50fe-a4f9-58b2128b2431",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9281b6d5-52d1-5f13-bcbd-0ade2620625c",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14527831-f46f-5ce4-9f74-08d0a9f723cc",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c878657d-a136-527e-af27-4fc71e4b67f9",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a80c564a-5c0b-54b0-9b3b-5542d6c1a5a7",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.3"
    }
  ]
}