{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:30440176-e542-5a76-b79f-c4d89564f392",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-util",
      "version": "9.0.50-tuxcare.8",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:68af1a9f-d636-5fb5-a777-6addc278a638",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2cf33e9e-6ada-57b2-bc4f-30574dfe9a54",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9fa2451-c822-55b1-9238-bc9f28dac84a",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abe40a7a-5e55-521c-af26-acfcd50931b1",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e2480c7-83cd-5c95-82b0-ad77b9fc6d61",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b180d207-c6e8-5d16-b3c3-11975acc4b45",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0078dd19-1253-5b94-87df-e0575b12cd4b",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39bf1711-bdd8-5370-a2b6-403626731ffe",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be56237e-1927-5bcb-99f2-ec951b7d6909",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-29885 affects version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5539661-2df6-5f8d-bd9f-09d0f6b53b97",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2f10d93-8dac-5b04-b8d7-0733b7a45f27",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fb48499-81fb-59d0-82ee-c94a8e1e16a6",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e6150f1-4a14-5fd6-b1df-03ce872dc1cd",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-24998 affects version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:394e5b4e-1800-59d9-b6e2-93307d1fac49",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7310b730-472d-510d-a7f3-eb44946d906f",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4780a95a-1c7e-51c5-ba28-963baa11ca0a",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42795 is fixed in version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03e244a3-791f-5aa0-8d8b-274312bfb5ee",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c400ea22-72f3-518e-bc06-85e165dc5a5d",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b12a29d-fa2b-5245-8bad-72431c27b0d5",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-46589 is fixed in version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fdeba964-186a-5652-ae5e-1255d8e8d6ee",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f28d1666-80f2-553d-a8a3-a6032edfde41",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e20349a5-ee22-5955-b637-e322897af883",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34750 affects version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d137b0c-ec47-54b7-9d63-a56ddfe89141",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:343b7a0a-c759-5b66-8d3f-dbadac6e1846",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37d6eb4d-c0fd-524b-b028-a1f220bd22e7",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:644db9d4-9f2f-555e-9d68-ecdfa710f90a",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9543a2b3-f7ab-5097-a74c-7e1928eb65a1",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56337 affects version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f7344d9-9da6-5265-b4d2-0a0bb8372aa1",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:787b252b-788b-597a-a236-f8e698d3e35d",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31650 affects version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eafd954f-369e-5243-806c-ae8b9339fea4",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3cc1dcdf-27ba-5e0f-9cf2-ee3ec98506c3",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5feedf63-893b-59ee-a54b-0b267b58c2c1",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b115c23-ffc6-500c-be92-cb1364206bc0",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48989 affects version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:941f9e56-caa3-5fb2-adb2-693805616389",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1b499c1-657f-525d-8d0e-2b8dfc5d564f",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed28cceb-24b8-5de5-9f24-516e2eebd573",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8dbc58dd-7040-5f68-83a0-c0a7f6a898af",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f21250d-5877-5f9d-aaa9-945c4e9dc3de",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35303d76-56e6-5769-ad67-65c70c121257",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e282f19-0643-586e-85c8-42c89f4ea607",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b28b8b8a-fd4f-5a18-9545-af7a354173ee",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67fdd407-3cdf-54e8-b27d-45ffdfe0c34c",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3baa002-373f-5363-9929-ffef23096298",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8642a695-0225-5161-b826-60a1d60249de",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7627934-5f5d-5c93-8d65-27f2a44c2cc8",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8b7ad97-3c68-59fc-b3b1-a7f7b31fa286",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ac05336-077c-5bc0-ad42-f89419970a01",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80478530-b8fa-5591-97c4-b6e833418e15",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78fd2012-076c-5a8c-a0c1-6e82a20219bb",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d67ba5cb-9e2e-57ad-863b-a26a19c2df88",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.50-tuxcare.8 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.50-tuxcare.8"
    }
  ]
}