{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:2fa1e58a-fc0b-5284-9751-46a52b6dc01a",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@10.1.18-tuxcare.4",
      "type": "library",
      "group": "org.apache.tomcat.experimental",
      "name": "tomcat-embed-programmatic",
      "version": "10.1.18-tuxcare.4",
      "purl": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@10.1.18-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:1b1c51a6-5e54-5616-9020-5bbc07b8d49f",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23672 is fixed in version 10.1.18-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@10.1.18-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08605732-4698-51be-ac9b-58b268eccb5f",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-24549 is fixed in version 10.1.18-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@10.1.18-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7be107c1-5370-5210-b8b9-dccae263ed27",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 10.1.18-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@10.1.18-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e6d6c44-70c3-5778-8871-a33ffef6a331",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 10.1.18-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@10.1.18-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02b32068-9919-5694-9bac-6497539b7a85",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 10.1.18-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@10.1.18-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5184fa65-b6ff-5471-87e0-b20dc269a9aa",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 10.1.18-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@10.1.18-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:013252c4-470f-55e8-8a68-ee3ad7744f7d",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-54677 is fixed in version 10.1.18-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@10.1.18-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1dd8ec65-46e8-54ab-8ff0-83f11ec28be0",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 10.1.18-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@10.1.18-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8381475-b0f8-557c-b833-758473ceb1f5",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 10.1.18-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@10.1.18-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3325fdd4-7409-5623-a5a5-c73c8153c15a",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 10.1.18-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@10.1.18-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f281f60-9f16-596b-9895-f6bc92b704b2",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 10.1.18-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@10.1.18-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5897ec85-4a42-5600-be38-67ddf47b8714",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 10.1.18-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@10.1.18-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0709b3bf-f93d-5314-b3fa-51fd9dba432b",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 10.1.18-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@10.1.18-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef774a80-7313-5f1d-8a0f-0af454b2d156",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 10.1.18-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@10.1.18-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31530005-7ee0-5718-b737-69ffb74bc3f4",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 10.1.18-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@10.1.18-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e633c44e-d6d3-5037-9bc0-adc31c5248ed",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 10.1.18-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@10.1.18-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67d94ae8-fde4-5fcf-a98c-9b7835b96571",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 10.1.18-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@10.1.18-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e11d1332-863e-5ac5-8cc1-0652dc3a4531",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 10.1.18-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@10.1.18-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:102d6c52-8d17-50d6-a68a-2c795043a9b1",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 10.1.18-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@10.1.18-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6289396-fd39-5be7-95a7-ca7f0d0cfecb",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55752 is fixed in version 10.1.18-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@10.1.18-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d561419-a674-5d7b-b150-e1cce1a6963d",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 10.1.18-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@10.1.18-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4afd260b-e6ec-561f-a903-7a205416a47c",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 10.1.18-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@10.1.18-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f07be1d-a435-5509-aa3e-5b0fad633503",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 10.1.18-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@10.1.18-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1b23769-b282-54f6-a90d-b445e9fad790",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 10.1.18-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@10.1.18-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:236a824c-46c6-5a3a-9e39-fe673250e9f0",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 10.1.18-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@10.1.18-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:731c54ca-2cff-5939-b71b-1971a2516e30",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 10.1.18-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@10.1.18-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:472e2c74-7e24-5670-938c-eaa63fe27a84",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 10.1.18-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@10.1.18-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71a7634c-6230-56d2-85a0-9e6c90b38b25",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29145 is fixed in version 10.1.18-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@10.1.18-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b1ae56f-029e-52e2-befc-7c603dadda02",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 10.1.18-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@10.1.18-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a115091-e4f2-55ea-b150-118dc5b8230e",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 10.1.18-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@10.1.18-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e28e16c4-d89d-5af4-856f-9d865ee9db8a",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34483 is fixed in version 10.1.18-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@10.1.18-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f1fc0a2-3991-51c9-b06d-5b4ab836cdc7",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34486 affects version 10.1.18-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@10.1.18-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36848a2a-da2f-5988-9900-4d15bc4ffee2",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 10.1.18-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@10.1.18-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@10.1.18-tuxcare.4"
    }
  ]
}