{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b2e4c35a-35d1-5d0f-9da2-b65d709d091e",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-util",
      "version": "9.0.50-tuxcare.5",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:980b3b0f-2db4-5c3e-a3da-f8ab7e32e65a",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99d51a1c-20c2-574d-b05f-af942a58527f",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9aab077e-5cc8-53b5-b344-96cfcec29075",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18e2cd56-bb86-58ce-ba25-cddb679dfcd8",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0568857-7d6f-5ed8-aab5-a69483328247",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2699fc9c-5256-522d-8108-3b0a26a678aa",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7d34263-1990-509f-a54d-0a56787ffa57",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:282c2e09-c29b-5501-a2fb-8c6b72d0b1f1",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bbb5878-7bc6-5a5c-9f15-809e1c99efe2",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-29885 affects version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d325981-6034-539d-941f-83344051289b",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18b5084a-70f2-5b82-91c7-0b6b116e8569",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51e65810-0e40-5e15-b41f-57839b00d881",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ca415e4-0629-5524-8db8-7a2d673c0fab",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-24998 affects version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64d367b7-600c-5a25-8003-0611bdf64254",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db6b99fe-7bc8-54cd-9ecc-9ea609c03e8d",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2a31eed-3b73-5aba-8061-9287f09c793f",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42795 is fixed in version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30b2b5bc-25df-5db7-9b4b-c5c66dee9a7a",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:908b0953-95e9-5fd2-bb80-6c5a895d2d6f",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33c2e4e7-e495-5e71-8587-c1386c02f2ac",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46589 affects version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3252231-25bf-571f-a10c-76c4434e2e0d",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5ef5aea-13c9-568f-9d6a-e7fbe4258a93",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbf4e509-39bf-5fa8-bfd1-5210040f68e4",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34750 affects version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ccbb493-053a-530f-a7fe-60fc2e7bf82b",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afe9033a-38bb-5733-b01f-2589e7534b8a",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7904957b-f7fd-547e-8157-a1f864b10aea",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c72c891-c13f-5818-814d-a09945ceb574",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9b07694-ce31-52d0-95e4-f6487d2a86d4",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56337 affects version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db30a777-bfc1-5aef-ba6e-586eb0112566",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4a062e6-4490-5eaf-84dd-cf8cd8dcdb20",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31650 affects version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d57766bd-3192-56b1-89f9-58da2d2d038b",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5bfd4d81-bf37-5130-9c24-26026d0ae38d",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-46701 affects version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1432ebe-1855-5dce-b335-e30f8b55cdd5",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f98ded1c-6d90-5e98-8fd4-58445534389b",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48989 affects version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7fa5a28d-133c-59fe-ae5a-bc406dd0a71f",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6e74515-5900-5f53-bc88-0d4a17aecd6a",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:048023bd-e287-5e56-8cc2-346ead459e75",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48087243-b9ac-576e-95bd-98322a64899d",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d1f7d06-1ab8-5f11-aaf7-338ccd96f4cd",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9236fb3-73de-52b3-a5d6-900caba2e984",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ad93962-4c92-5005-8521-1fe35babdd44",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1517649-5c29-52d9-bfcd-72d0bbf405fa",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ba8b135-2b78-5aa2-922e-a657ca912841",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a71efdb2-c724-56f6-93cb-ab51fbd6beea",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90eb7267-e280-5322-aae2-fbe10ac0594e",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b90cefb6-853d-502f-afb6-1595cc714125",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:380ad966-45a8-5b15-8d5b-ab053f4ccd6a",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78704717-a4ca-59d2-958e-76bb17edc2a9",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7b1d14c-bde3-5baf-8776-1b720584f323",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb6b4407-2a0f-5b60-9fad-c650cb5ae053",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:247b8628-661a-5c1b-ae07-c50ed6e4b91c",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.50-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.5"
    }
  ]
}