{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ecc4e66d-8986-589e-b3e0-477f02b576cb",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@10.1.42-tuxcare.1",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-websocket-api",
      "version": "10.1.42-tuxcare.1",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@10.1.42-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:0f88d4b7-5ba4-5d7d-9921-c2986fbdb110",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-23672 does not affect version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api. Tomcat 10.1.42 is not vulnerable because CVE-2024-23672 is fixed in 10.1.19 and affects only 10.1.0-M1 through 10.1.18, and 10.1.42 is later than 10.1.19."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@10.1.42-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37155bd6-2381-58d9-9ca1-99c488edbca7",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-24549 does not affect version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api. 10.1.42 is not vulnerable. The issue is fixed in 10.1.19, and 10.1.42 is later than 10.1.19, so this version already includes the fix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@10.1.42-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94ea5bd2-7444-5bfb-9e53-6db9bc823dac",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52316 affects version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@10.1.42-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63526b3c-c5db-5688-bba3-09258e20a649",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-48988 does not affect version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api. 10.1.42 is the first fixed release in 10.1.x. The fix is already included in 10.1.42."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@10.1.42-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37ee4628-c6bf-50e3-bf45-adae13ab43f4",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@10.1.42-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0236e126-49be-542c-89fa-8cdf04e696e9",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-49125 does not affect version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api. 10.1.42 is the first fixed release in 10.1.x. The fix is already included in 10.1.42."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@10.1.42-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85600374-fb37-5357-add5-955c8aa8f07c",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@10.1.42-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c828f67b-09df-5c09-b907-56806b34a7c7",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@10.1.42-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7b3f8e7-0cbf-5720-aed1-2b1529ff9a48",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55752 is fixed in version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@10.1.42-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d19e2d93-8387-5b46-8e18-cf53c6edc0c6",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@10.1.42-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfabfa09-db20-5795-b562-341dc3ebb6d1",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@10.1.42-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f04da594-7479-5404-b288-6aea378bee93",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@10.1.42-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f5aac78-67a5-56eb-b7b6-fe025c97721a",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@10.1.42-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dde88b06-ab3c-5059-9d9d-89abb2967f46",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@10.1.42-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb5c7298-6f0d-5d09-90b0-275a31a127bc",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@10.1.42-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:185ce8d0-a852-58d7-849b-a800defd50fd",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@10.1.42-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:186c3979-442e-5424-8ea8-497a0ba90675",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@10.1.42-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00336c11-8c60-5bce-b5c8-d2be18be0871",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@10.1.42-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ffe3f80-4c04-5de0-8ecd-6e6d04544a23",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@10.1.42-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3758b5e5-1318-5077-aa9b-86419548b0ec",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@10.1.42-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de383369-4feb-53c5-b702-3a2d5eb709d2",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@10.1.42-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a14b7d3-acce-5e4a-b4ac-0b4895b076b4",
      "id": "CVE-2026-34500",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34500 affects version 10.1.42-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@10.1.42-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@10.1.42-tuxcare.1"
    }
  ]
}