{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f534d72f-cd45-57e2-a524-3c059aada9a8",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-websocket-api",
      "version": "9.0.46-tuxcare.2",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:2e8bd09b-541f-5235-b3f0-2cf5a7448ebd",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c48ed68-26fb-5e0e-adcc-9625fd72ea8f",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88b2df57-c654-5b08-b8d8-414580aa5ec2",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4b441bb-1ddf-5f7a-a752-a42c2061e91c",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77c0bd92-b591-5824-8c18-22378d734c05",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53e5bd67-1f25-5bf3-b246-7b6bb08f0e62",
      "id": "CVE-2021-33037",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-33037 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:785eccb2-b90c-50e8-afb6-ceed5adf24d7",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad50df0a-79d6-5660-9f31-2caf150ea450",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df97a54b-0e00-5622-8200-5b0e9a0eca7e",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2365e2b1-f026-5a4b-85f8-08177568ac78",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f937abb-0d8f-5f31-8d05-169a36adc93a",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b668ef9-4dc7-59d0-8b38-8c542bee8443",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3cbe209f-6370-5ff0-9ba3-0c5d5ab9f73a",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cda0d9b6-1211-5a71-917c-64b605ed48eb",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-24998 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1accf026-7fe5-537e-956b-2cee0d92d76b",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57281e33-a907-5b53-be69-28132b344d16",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4febeb50-5383-529d-b6ca-83f34cdbea0b",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-42795 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:373e73c0-d568-5302-a040-73abbe5e7571",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:867fac94-6300-5c77-a0c0-dcad9c3dbd2c",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5eeabee5-c0f5-5396-a602-6206b15dff5e",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46589 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d151fa8-1e7b-56d9-8eba-7f05026b4b80",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d7446be-8f79-5b22-856b-df09be324ee4",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00f558bd-abc3-53c0-8908-91fb15f61055",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34750 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a777605-f9b5-52f5-b8dc-3fd6023683d8",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0420ce62-c208-5175-9bbd-ef757ba053dd",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1c385cf-f7df-5503-a5c9-893679dab2a2",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e72d560d-b4f9-5cd1-8bba-91f207d269fd",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d3c7b4d-2f02-599a-8a76-27381f682a8f",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56337 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ecae0a75-64b4-5102-9f59-e3c6dce4843f",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5470212e-8355-5ed0-bd93-cbff41ec0483",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31650 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0abd6c3d-4f3a-5b93-8c38-e508fa73aac9",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:950ab4ba-6b18-586a-b928-066346dba149",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-46701 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94144999-676b-5717-a634-a132a2735638",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48988 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:743a969e-9840-52eb-8947-71aaddfdbeb9",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47ffc267-2dc0-5052-a2c5-1f29edc5c280",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60bc7954-3535-52e7-a29f-ab9ea12cf539",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13adcd04-f570-5cdf-8db7-78c9718108b6",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52434 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb1b10bb-0373-5dc6-9ac1-9a6d813f5ac1",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0a2f2b6-0723-5dea-8675-41ef62d7abb4",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3274798b-4e9c-59cb-b6aa-275169605a90",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5686972b-94bf-58c3-9399-ea5cb9786d05",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55752 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06a89c32-1f9e-567b-999f-04c03b0f7637",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1350f3c0-93da-50cd-a5e2-fe84fe878227",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ecbc4e4-7bd8-5b25-9036-452f90ac536f",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6a30eef-5683-5c95-bb75-7905d8475c19",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e3f4b2d-5e21-53c2-bde9-535787961306",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46b71e22-fc49-5ef4-8e22-94f799e93f35",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1af76094-faae-5b48-b220-0003dc6f21ad",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9fca226-12a1-5bdb-9440-8cac466eaf58",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdb763f5-bb93-529b-9448-697cbc9398a6",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3753e246-c6cd-50ab-9c0b-f1f8372037de",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.2"
    }
  ]
}