{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a0bff5d1-2246-5d08-bc6c-4b474991db7d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-util",
      "version": "9.0.50-tuxcare.7",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:de5005a8-bae4-5b27-a8e2-7c1ef149b164",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ca1afc8-269d-57f9-9aa1-ebe8152df98b",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60a1c948-d504-5bd6-9526-6191b124a991",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5ae3f38-1951-5faf-a640-2eaf2d0d06e5",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7cc1fa92-d929-5bed-ae53-c1a967afe519",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a4fc1a6-58cf-5cd8-8bf1-da7b02c9189e",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9620962-c5ec-5c25-be51-44a9b22ef915",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ddb4735e-e712-5012-bdd3-cab202804d1a",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0dc04f6a-a5c3-584b-8f47-c94123dfbe16",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-29885 affects version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bbf43a5-7eeb-5f5d-b7e9-fb7c7d564b5d",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e314a007-77d4-5c9e-908d-c38b555c6d9b",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f339f32a-cb3b-5c98-a14e-0bf256bc4f11",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da236375-92b5-58a2-b2d0-f7f7351a1066",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-24998 affects version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30d0250d-67b5-58a7-a188-b7886caac025",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d08e4d2-ab5d-5eb8-aad1-dc46ec1bb8de",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da217ed6-4575-5d25-9c78-672920a8a3ab",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42795 is fixed in version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:668348da-f324-59aa-9a93-a2613171c852",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab4aff97-4bcc-5342-874e-7470865a4a15",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b236a89-f572-51d1-b268-c0e28aee6376",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-46589 is fixed in version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42bfaaed-0887-59a0-834c-07967ff6ebcb",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ced106db-42ff-5ba4-a234-ca5fdf339d68",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01d40a8a-0139-5c50-9b92-350228a81b9a",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34750 affects version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b14d96ef-2134-5797-a994-7aaa37ca1e2d",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f642aca-5787-5a91-8349-7148d86d8789",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3927c39-a285-5d49-a144-2a89935dcb75",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69a71b9b-07ef-5cc5-a11a-974feb2f8151",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51808806-8e80-59e0-a225-a307d149df5e",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56337 affects version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66f8be74-4112-5ad7-be02-942b7b561ba3",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2724bfd6-6f44-5d7c-96c6-dedd8381eb49",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31650 affects version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0bf6f329-a4d4-5fbe-b1a7-5db4ffdcefa5",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5ed1850-6c92-5628-bc92-230bc6bab1cf",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b21fde0-d5f3-5536-b451-6616915da928",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd05e524-428a-56cf-a962-5fdee20b17fc",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48989 affects version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26b41882-1510-5a38-806d-6aeec5a64877",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2b2b7e3-5d22-59bf-8989-42168fc09468",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fce42f5-e279-55ef-b544-727748c5f9d7",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab73ba05-ffa8-5cd8-869b-3c45e6affb89",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79486ddc-293e-51e5-b4c9-47283925e6ca",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d54a788-d973-50d0-ab6c-1d6a516df8b5",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07643822-925f-541e-8d4f-73c6b62c14ba",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5dc4bcae-2a2d-5ca2-922f-e8020d7c362d",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6bc0bf09-4133-556b-a31c-16fff1e1f8fa",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:caed6674-cca1-566f-ae12-0ef0588e46ac",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:def23fe3-185e-5b47-aba1-1c4d8d88859e",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:493af8e5-849e-5c84-822c-b2be0789e8dc",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d4fb9c4-a275-5ac7-a92a-d7deda09c210",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22130a10-e592-503c-a442-9f545308ff21",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9eb635b-2e52-5f01-94d3-ced132bed2a4",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20feefdb-089a-5b32-aa66-6fbd4ca93284",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61dc7d48-78af-5ef4-803c-ca9e2d830d96",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.50-tuxcare.7 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.7"
    }
  ]
}