{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:46e3100e-27fb-5627-bd75-6994013e121c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-websocket-api",
      "version": "8.5.100-tuxcare.3",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:a7cbb890-10ac-5658-a26b-687a16bff3cc",
      "id": "CVE-2016-0762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-0762 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d767d75-41f6-5cdb-8f45-ad738bf62dd5",
      "id": "CVE-2016-0763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-0763 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b38ab71-864c-5b12-b651-38cff3fe9cc1",
      "id": "CVE-2016-5018",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-5018 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3c34cdc-6754-5731-8fcb-8e935ac9cb33",
      "id": "CVE-2016-6794",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-6794 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c85e6dd-963a-5e3e-a7e8-a6715ee76d06",
      "id": "CVE-2016-6796",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-6796 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be278f30-8c2e-5e85-b5a6-15f60e8f2970",
      "id": "CVE-2016-6797",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-6797 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2d214c6-3818-5fcc-ab5c-f690d4c9193e",
      "id": "CVE-2016-6816",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-6816 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b5d660f-a68d-54b9-b5c5-bccf82530694",
      "id": "CVE-2016-6817",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-6817 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e925eb66-a152-550c-bb8b-dc0dad1fdbfb",
      "id": "CVE-2016-8745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8745 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97274c2b-852c-51db-a008-294d58ce3a16",
      "id": "CVE-2016-8747",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8747 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a29af7ec-f9b9-555b-9a90-bc133c57e800",
      "id": "CVE-2017-12617",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-12617 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a18c6e04-5755-5982-a970-e430d0d5edd3",
      "id": "CVE-2017-5647",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-5647 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b13cdec-8b2e-5954-994a-7d2c1567201e",
      "id": "CVE-2017-5648",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-5648 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d10de34-d9e4-5034-b187-aa65bed4da58",
      "id": "CVE-2017-5650",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-5650 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c5885c0-e2b2-5729-b90d-c43c61c90054",
      "id": "CVE-2017-5651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-5651 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a73e61fe-e91f-56ef-adbd-6a1768db7590",
      "id": "CVE-2017-5664",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-5664 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f23b7c1f-4b05-59a3-82e7-f0447201d1f3",
      "id": "CVE-2017-7674",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-7674 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71c3f00a-4368-5fbb-84c0-9c2a133db87a",
      "id": "CVE-2017-7675",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-7675 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5104c223-b639-5aa8-8088-602143af13ae",
      "id": "CVE-2018-1304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-1304 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67c960eb-85ec-577c-af4a-ae3d8ea95cd5",
      "id": "CVE-2018-1305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-1305 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5727f21-026d-5caa-ad84-769dabb49836",
      "id": "CVE-2018-1336",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-1336 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7629816f-304c-51f3-acdd-096b8fe16eea",
      "id": "CVE-2018-8014",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-8014 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c0b1201-783b-52ab-8f3c-1c38b27c4657",
      "id": "CVE-2018-8034",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-8034 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0896055d-46c7-54e2-9729-7f14fe47b8c9",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0bc662db-5080-56ba-8421-a658f293b9ce",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ff91fe6-182f-5567-902d-4eb6540c118e",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b8d3b70-0a0a-5d57-b85d-c1c6ad2615a5",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.tomcat:tomcat-websocket-api 8.5.100-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a5812bb-4bfc-5d38-8e47-ea4b4990da6a",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a54e1e6-a30e-5971-b581-d060742f829d",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c83dc54-456c-59a3-a91b-eee5cfe8fd0d",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf1a36f8-eb3e-5cce-a2fe-078515f4df57",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9fb0793-6b4d-5ee8-b65f-cd2ce44d257f",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:745b432f-cff5-5ded-9364-2c1ae31ba1c8",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:535228b3-6f2c-5fcc-b986-b676d6e3efb9",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ce0e02e-4cd0-5c40-b738-3ce2c2ccba5a",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bda700b9-64bd-564b-8546-c943e7cdc6e3",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54c5d46c-b91d-54a2-87c8-0fad2aba6eae",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05cce61e-f8f2-568b-ab4f-f48a3d35a6bc",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e29ee79-2e72-5bc3-8489-9eedc56e06d2",
      "id": "CVE-2024-52317",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52317 is fixed in version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46f0f9c6-515b-5c49-9041-f4a06d8ff008",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43dad599-53ec-5178-a696-a0ecdd220992",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f557818-b4f5-5f9f-b1be-a18d42961a8e",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:020899c6-1006-5143-ac03-8d59a3a6aea6",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbbcb220-2bc4-55aa-9e13-a741b349f9b7",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6836d38d-8178-52d2-8cb7-b8e3e2fbc872",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26755007-9bd4-5c38-8536-9618a1490c1b",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4983028a-ecf1-5503-8836-01fcaca61cf7",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05b69755-6524-5754-9745-0d3857fed23b",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52434 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e55a083-8fe9-556c-af86-4f7c6ce98f78",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52520 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87716058-f5af-58f7-ad9f-858b60baa018",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-53506 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f371195b-56d0-5631-99f5-787b63ba7a5e",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55668 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:118f8826-ceea-5d8c-aa77-6e1250c8f332",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ac71652-00c2-5efa-8eb8-f02b0c40fae7",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55754 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09beccb0-b5c1-549d-ae77-c43d85576ffb",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-61795 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c677d572-3412-56c4-955a-81dfa2c2ad61",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6fc622c-e152-539a-9f0a-357f09718417",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1647036-d66f-57a6-968f-b5553a5bdaed",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5bfc417-9326-5b01-9f43-a635d73e44a7",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1756d39-d303-53d8-94d3-36fa1b5fcf22",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:210c3aae-4e13-5e93-a98c-f44b306fd98a",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 8.5.100-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@8.5.100-tuxcare.3"
    }
  ]
}