{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:295a6824-e6d9-5be1-8cc0-faa36759e310",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-websocket-api",
      "version": "9.0.46-tuxcare.4",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:e45e5304-b695-5c74-ab7f-eee4e245e23f",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee1668c0-3bcb-574f-895a-4fe711d85b6d",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0954b9c7-3cc5-5bd4-b6cf-694736a9edd2",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:465385b2-1039-5fbe-b9b5-8a87818ea7a4",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5310e0a6-4b05-5c2c-a9c7-eae08d4afd81",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b73fab16-ba77-5c1a-8585-2fa0b0e7a0d1",
      "id": "CVE-2021-33037",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-33037 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9b0131d-b610-53e4-9f78-13fffd8f25fa",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef329570-f7d0-5994-b7dd-0c9f0941867f",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:984a008f-43c0-5274-bbcd-8480b2f17f45",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a44a7a1-faa1-5266-bb73-42b5e282f795",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0294f225-f36b-50e3-88f6-efc98db7383e",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-34305 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfbe7b3a-08e9-5bdc-93af-8754ad150b69",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:522f71c3-b90d-584e-910d-384adbc587b2",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9a9dcd3-f27d-534e-b029-4c38190a17b9",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-24998 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aaf72510-a0e2-5197-830c-f2c07bc5d2c8",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6c6dbe3-a3b0-5a5a-bc63-bdb118095bef",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15ad7cce-22b4-540b-8ee2-ee67d903dea4",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-42795 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97a6f234-816d-5c21-95d0-49c1d6cb2116",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:249a5e68-1ec6-5e0a-80f9-861c12a9f818",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:219995ad-2bde-56ed-8ad3-8caaa3d9b575",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46589 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8db821e2-ca93-552e-ac69-855f71ed34f1",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b56bd2f6-aa45-515b-9817-b19f85941f8f",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7949097-cdb4-5b9c-8e44-2ec402714824",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34750 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7668baca-2185-57bb-ad1b-6df6b29f8a4a",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0d69ee0-8829-5ffb-a47b-06c2ecf288e4",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36dd7809-b836-5325-8849-867911009247",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25e8cae9-7676-5a13-ae02-a71f38c736dc",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ea99360-4bab-5e84-b782-c012d65554dc",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56337 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0dfda5be-2b3d-5d43-975f-faef8bfea12c",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7f47ef5-7c9a-53f1-8ae0-95c73f506194",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31650 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:738cc5d2-2eac-5b4b-afaf-5cda562c40ba",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff67e319-a1a4-5ec9-a00c-bf841f7d5e36",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28434588-a5c2-5107-93b8-e4ceda3c7a2d",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a580ce3-3e0e-57b1-95ea-e7bc4098e19b",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:649290e1-3a2e-502d-b3ae-921df188f121",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7cd8b76-79f9-502c-8a5d-e5f295c91913",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cdadb34e-a040-59e9-94a4-1bbb7d2a3b39",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52434 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8a052dd-eb52-517d-8cea-0bab8076cd03",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d893e59-d9f1-5f03-a5b2-f05cbd367468",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2a7e0d9-1c47-5135-b435-a2648d73c3a8",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ba31200-b7a0-5f9e-af5a-f2b5b94f55c4",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55752 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf6c3719-e61a-57e0-864b-4c808091ac86",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f53f91f-8589-5e15-9fe2-06399a507806",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c118a1f3-e18e-5944-933d-7335a55eb0d8",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e171746e-d2ec-500c-883f-e8a7bbe06245",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a785b4b0-b730-5bb0-b54a-5d6b08c67962",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2480d28a-0833-5653-9587-ba842cc19cb0",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff3410ee-a2a8-5fb3-a7e1-f52eba63db7a",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:701b34c2-df8d-5b93-b91b-c7c7309aed8c",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a707ed3f-f030-5104-be38-f396e6f372cb",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1f6b7cd-4c39-55d9-8a33-238e1218cf87",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.46-tuxcare.4"
    }
  ]
}