{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:8abf64df-026d-5195-b4df-3102999937f5",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-websocket",
      "version": "8.5.100-tuxcare.4",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:1ac76e5a-c0b9-5bff-85c4-ca1ea1256561",
      "id": "CVE-2016-0762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-0762 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8faa141-403a-5d2f-9426-e5e1476565c1",
      "id": "CVE-2016-0763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-0763 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:730ce013-7f1b-5c51-988f-fc90cd24eafa",
      "id": "CVE-2016-5018",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-5018 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38c15425-f86a-577f-a049-097294327d31",
      "id": "CVE-2016-6794",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-6794 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:647ab327-89f5-5aa3-9ecb-cf967cbc4664",
      "id": "CVE-2016-6796",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-6796 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c756501-a6ed-5c16-8f7f-f1d3b93a7039",
      "id": "CVE-2016-6797",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-6797 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7add4e6-845a-5a5a-94f3-2937f764f4e2",
      "id": "CVE-2016-6816",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-6816 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52b30fb6-5196-5e08-8834-88d17b384bdf",
      "id": "CVE-2016-6817",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-6817 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df8ab418-c140-5dae-a665-eb81eb1e2435",
      "id": "CVE-2016-8745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8745 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b01991d-a41e-54df-ad53-567ccad8eec2",
      "id": "CVE-2016-8747",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8747 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60f6bc35-a5aa-506d-b527-17618ac845ae",
      "id": "CVE-2017-12617",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-12617 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:964840a6-da32-5112-a55d-8b25650a91d1",
      "id": "CVE-2017-5647",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-5647 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0be517d1-52ff-5017-9923-61e78a17b462",
      "id": "CVE-2017-5648",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-5648 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c2df927-aec1-5d21-9e50-89718675bd23",
      "id": "CVE-2017-5650",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-5650 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76195d8e-eb3a-5d96-86a9-a533cbbe830b",
      "id": "CVE-2017-5651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-5651 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:926e8721-bc9c-5775-b0ae-eb287dabd6c9",
      "id": "CVE-2017-5664",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-5664 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fcf5ccd-3a09-526f-94ac-b5972e435e74",
      "id": "CVE-2017-7674",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-7674 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a8bae7e-b98d-5454-8c90-8f3acf002fef",
      "id": "CVE-2017-7675",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-7675 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18880901-bc60-581b-a2e3-628ba761a126",
      "id": "CVE-2018-1304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-1304 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:988f415f-ee8b-53a9-b520-7d6bdb0e3ef7",
      "id": "CVE-2018-1305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-1305 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d1b2b47-c5a8-5bef-bc9d-aa3bd97a8193",
      "id": "CVE-2018-1336",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-1336 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e660de8d-58d2-5275-b319-c0a7cc01d915",
      "id": "CVE-2018-8014",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-8014 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d1ad1ee-e9d0-5f8d-9d99-0c4d58c7821f",
      "id": "CVE-2018-8034",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-8034 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5a2385f-700d-5647-a22d-e44c4fb5b43c",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3aa02287-63a6-52b4-9a81-3d0a08a5235f",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a079919c-e51d-5c3a-b9cc-28655dfa3d60",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1beb2dd7-bd00-5d38-b06b-c0525d83a30a",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.tomcat:tomcat-websocket 8.5.100-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4354cde0-572e-5ac3-b1e6-1dbd3d0551ae",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2290445b-68ed-5eb3-afb6-06f419c40d36",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8070e46b-54d2-5129-9b73-afeb748dbe8b",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4daae3ed-7c73-5903-aa40-cc3cb8109e5b",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab0a89bc-12a9-5664-8818-0bd90929395b",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e8b87bb-569d-5907-a43e-6a9c8bcae858",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:798d278c-12a0-5157-bc84-f52820415f78",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c51efe9-2be7-559d-9987-b5c73dfc086d",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1c65777-468c-5394-adb1-6cd27cde2799",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ede1699f-1164-5adf-83b7-75222baa0ff6",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c4f8e68-e221-549e-b4fe-25d8130de510",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ce8dbd4-698e-5472-b62b-82957cb5c8ce",
      "id": "CVE-2024-52317",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52317 is fixed in version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abc511b7-744c-5ca3-b7c2-401fae123243",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70acb195-3ee2-5c31-9627-0b390858cf84",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4cbec584-b712-578d-9cc1-db712147eda4",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94ce6e28-6e04-5234-acc1-e3a39819579a",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06792ec5-0f2e-5dc9-9ba0-c60412c0698a",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a819d68c-abd7-5067-86af-d654a8c3ed16",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38c590e7-59fc-5166-85a8-a73b67915279",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47b2ee00-7ce2-5145-8163-a5e1d2f65889",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36e225bd-a4e4-5e2e-be8e-03fbe32b6dba",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e05e7e9c-cf80-57b7-be7c-814ddbe0b8d0",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52520 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d37244ae-c4ea-544e-89de-679a700698df",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-53506 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fed291c1-4d0b-5429-8015-977e32003935",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f5eba22-4f50-5c7e-9f3f-e0707b432e51",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d22c81f4-a22c-5fa0-b24e-34b1ea96c31e",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55754 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8025b5f-4563-578a-b306-7075ba0bf0aa",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-61795 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78eb21ab-553b-5f7f-9577-dc5bc30df118",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bafcc86-549e-57c9-9976-d748ee9dab25",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7d94513-e94d-516b-a4a7-9b03456925bd",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be0c8c8d-3dd9-5cb9-91b4-f35f4d3c197a",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d723e6c0-109b-5e82-a2e8-3737b55bf522",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64717f8d-85db-5186-9a0c-3c9c42c87338",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@8.5.100-tuxcare.4"
    }
  ]
}