{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a92a3581-380d-5255-b856-0812428df227",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-websocket",
      "version": "9.0.50-tuxcare.3",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:6ea257af-6adb-5fb4-b6b0-326d6e53a151",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8622464-3476-5345-bf5e-fe6897562bca",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13c93736-de32-5e3d-9f6b-afc498df477e",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dac55261-957b-5318-b4ce-f21b965bbc50",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f2ce936-3457-5259-a394-c7e982f4a901",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dff16b4e-843f-55a1-bd5a-d2cfbd9d9f93",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce751b6f-f779-569b-86d1-c65705da5409",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:165534c2-3887-5caf-bdef-3f2afe06d715",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:caacf6fb-f4ba-55bf-80e0-6009091dfeac",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-29885 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a3c0db3-ed52-5b51-8f60-4c6f6a9ba8b7",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40ba9763-9e09-5a4b-b6c2-0ece19295fa5",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a18cf20-2953-5fe6-aa91-4a48f92a685a",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12774bdf-d9f7-5303-b7cd-a974e3668cdb",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-24998 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b656048-c946-594c-8e72-2d991657a6d5",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab75e1a5-1080-53d5-be8e-e6a8ebade242",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f78a491-313f-52c1-99e3-14dce78d018d",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42795 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87517e6a-7a10-5b35-9829-436b39294751",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:046417bf-c608-548d-9f6c-d79a13d4068d",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:606619b6-dbcb-5f9a-adad-457daf38db83",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46589 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a224e57-f5b2-5904-8d94-a211a499363b",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a31ae699-8c5d-5f5a-85a5-0041dd70490d",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a1951ad-99dd-5600-9434-16949383e83e",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34750 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6027f1ce-d46b-57a8-8aab-2f71e260b39f",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e187b43-d633-5f7e-8c32-71cf3621552c",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b953277-c1dd-5d48-a518-b43f0b27c27a",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e3f40d2-7047-54f7-bb27-36638412522b",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbe2ea13-21bb-5213-a0f4-69d1d3b4b8b4",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56337 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88dfa57b-ccca-52e2-b428-c59db0e7b5ca",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7efffdc3-1def-5630-85d2-537a6bfa5de3",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31650 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01edd7ea-f7b7-54ab-a455-4972ee5438ab",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31651 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf9c2d39-3a9d-5935-bb8a-9d91061a6a99",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-46701 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad0a0127-f31e-52da-8841-71939bbef322",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4bd35173-6745-560d-8e5d-79a53905162c",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48989 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4771c984-8ca2-56ba-adc0-c5cfbe89d3a9",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b2bd4a8-0480-5bd3-a32e-8940fa8b13b0",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd5dc000-4e30-57b5-87f3-47a214e624ea",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52434 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6bd0e01b-9f8e-566c-8db2-fa772096885f",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:722244bb-3981-52dc-a26c-2810a6442855",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50870037-547a-5ede-aa8f-f18868b66cda",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fdc3d4d1-8ac8-5a95-81ab-ac8a9e0292ed",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69f43134-392d-5d00-a078-cd2ccc1ebc64",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:249c2776-d15b-5da0-b98d-4fcd7c532126",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef05bb44-40ac-598f-a195-6d4531829537",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6a0144e-6c39-5e6d-b642-2e3cd03a6898",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7eddb0bc-531a-5883-8823-50c3ddee9821",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:653c7fb0-44f0-5152-8bd4-7838d7f60057",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e03ad794-c92b-568d-ad80-2745c4edc390",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e75983a-bdac-5bc7-bd27-73c084fd6153",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56ac9f79-7ad4-5c64-a7ff-951101af584a",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70671cdf-fc3c-55fd-92fe-936a26b0e93a",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.50-tuxcare.3"
    }
  ]
}