{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3f7cd412-5736-529d-92e4-8df77d28f024",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-api",
      "version": "9.0.46-tuxcare.5",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:e776cf8c-c7ad-5af2-96c9-5f5a61a72601",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a8f3265-5797-5a89-b53a-249efef283df",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51855e6e-40de-5754-a34a-9f17925a5beb",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2aff438-2a75-540d-9ee7-2b6ce928ba1b",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dad74275-8b75-548f-b95b-75824e5e0840",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:972e4599-f94f-5569-86d5-9e9746dfd08d",
      "id": "CVE-2021-33037",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-33037 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09e52bfc-8a40-5b62-97f9-1f54e18624c5",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2767aea7-f4b1-5d15-926e-aa30e4800684",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e885eeff-e0a0-508a-9dc8-ded60471ce69",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9face61a-29e9-52f3-85ba-09d685c7e740",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-34305 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73134740-9689-58d3-8428-b62ba859a175",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c249e9b-84f4-55ec-8289-91dcd043249a",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d693e62-24c4-5b5d-9900-177ad380960f",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-24998 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e316deb0-1a62-533a-a714-ecf3d6b21148",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa8b8d83-793c-5ee9-863d-24e5e10ddd53",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba52462f-ec34-5bf3-bb1f-bb11614b4412",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-42795 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa3df118-8704-506f-a4d2-8f46fb08623d",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d567759-662f-5e18-8b98-38d964af5c2b",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42acd190-e593-58fe-b3b3-8610c9dee25b",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46589 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8faf640-b7b7-540d-bb9e-454216c51796",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c34cd99-9484-5759-98bf-c93097255525",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63203eb1-b5b5-5348-b1f7-e59941a137cf",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34750 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2997da40-7324-54d6-a9fb-07bfad2fbedc",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5eae1cf4-c00b-5a57-8636-e6c734a4b94e",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b170fa2d-b59f-505d-a0a4-0e16e572e791",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c7cdf51-22d4-56aa-b003-2b94a40b29e8",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72525f83-b774-5395-9e07-df7157575882",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56337 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ec9e6b0-926b-5db4-abbe-19639b0441e7",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:286da143-fb0f-5485-9eec-22a6ca6c28a6",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31650 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1c1468a-d3d8-5cfe-bc5f-0218a1161f52",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:473b0ced-2026-50d3-89e2-4231eb8d815d",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5c04aa7-04a3-5f8e-9677-adf1ac9b099d",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:321e7696-2eee-5805-a241-2cb32cd6ce4e",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b56b4d40-dd36-5e85-bc38-bf115e77205b",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a04a6cc5-22e8-548d-a0fc-7971e5d34d2c",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfd3577d-b6b4-55d3-83f0-5f0436ee049a",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52434 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54180e16-44ad-558e-bcfc-4248f2a75ca8",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9734a4a0-7042-5443-9646-38b808b279bb",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ef8b6c6-5b2f-5b25-918e-dbabf3c63d64",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8c14e27-333f-55e4-816c-de16135b2ad0",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55752 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5736ffb5-12a1-59bf-8181-073ebf846a86",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9fc07f4f-ac2d-5e5d-8267-dfff68c832b9",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c8709a7-d2b2-5fd7-92aa-abc6f1c217ff",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6d50227-cf81-53e6-88f7-853737f57e0b",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bc26cbb-1fe8-5268-8bfd-791f695fab69",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15554ce0-7999-5414-811c-e74c0e35708f",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0d1ce55-2fdc-5253-a007-30bf16cac7b6",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:090757f8-5c43-5f3c-b542-d545f6184f8c",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d68d059-3413-5fb9-bf3e-eb11f8eb74bc",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7eec2879-5784-52f8-94bc-af10ff8f702a",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34486 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e4bf354-8bef-550a-854b-26c7935b398b",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.46-tuxcare.5"
    }
  ]
}