{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:89ad93d6-8318-5999-abb9-a6a2b711628f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-i18n-es",
      "version": "9.0.46-tuxcare.5",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:f7fffe45-a7d4-560c-9af1-2180f26ee4e6",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7977eacd-e087-5668-a822-f7addb4ab7fa",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:268f6185-18b6-5466-88c9-963b130b31da",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09d1785e-85ff-56a3-be23-f79cf40890b7",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4e9e195-5278-5efa-b5db-e9cf5b412a6e",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3cf717f-1c35-507b-a443-846ca0e7337c",
      "id": "CVE-2021-33037",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-33037 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08a19742-24f0-52b6-acd9-a2f663baa21b",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e062c39-3234-5bc2-85bd-a98fa30a8080",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8333af6-647b-530f-a254-f98aa75e5f7d",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e24fb8ff-1951-5271-929a-0f404af8a4a8",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-34305 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:085f89bc-229e-5d6b-a422-bdfdde6f4cf1",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3bd781bd-f7d0-5565-af04-e2fccbf7c35a",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afdbd8a2-09c5-5530-8908-cb83aa02bd63",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-24998 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9edf104a-e33a-54ba-99ed-793c7bc81c2b",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1545124-0ff9-52ed-b37f-6006d0c43941",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e639e112-8c71-5082-b6c6-e9844fd643c1",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-42795 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01ae28b2-54f0-57e6-8d71-4965901e538e",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3341e51-a1a7-5d90-8872-cf9bb304d6bf",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1a77c13-3dbb-5a05-ba87-91290d8caf17",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46589 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0426b27b-dfe2-5509-a374-1f3b3136592c",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1e99d13-eacc-5dd0-a9cc-75478cc243f1",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8146becd-a2b4-59de-ab6f-3e30d682cf4e",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34750 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03b4816f-bd5d-5b27-ad86-b1dc10d50d4e",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9395dee3-6184-5f5a-94b3-590695050938",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7d95b5b-32e9-5dff-8a54-03dcaca1dceb",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10cf7669-81f2-5c66-a6bf-1687b58a3c2c",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4c5ea48-cca4-5c7f-8572-3a3132bd4200",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56337 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2144ea8d-d837-5bd3-9e3a-a8e143cceaad",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:648a043f-71a4-55b6-8307-1f7f562acb70",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31650 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8521b906-c294-5cfa-88ce-01272350efa8",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db679787-0dc5-5b8c-9598-6cfd8284a0e6",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b30c04fc-e76c-5878-a64f-6c81d129086d",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5a6edec-946e-54a8-aaf0-d982c9633557",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6088866-c4c8-503e-a779-a302cf9eefd5",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5206b97f-df19-519d-9acd-931bd7ff3569",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5065df77-4cf4-5b6e-a7a8-24107341069f",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52434 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e8a8e51-a804-5d33-8e02-0760b1c523f2",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7d314cd-8079-564f-b262-707d222bee38",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8f1799d-af0b-5510-9a26-22d1b9215caf",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c71b29e9-66af-5170-b6d2-248e5d1cb785",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55752 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5628187-6cbd-5d94-a43b-702e44446f46",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97602f2a-195b-5127-85ca-8ac153a65afc",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01e7ae83-3d5d-553e-a708-27887b632cdc",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d4bb4fe-742d-58b1-aafa-c823857d8e1c",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a801db7-5dc0-515c-b1d7-9b43904ee8d0",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5dd77ad-5915-5568-a97b-09d90e4ed71f",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abd89306-5697-53c6-a136-ed69804235d7",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d4f47c7-baee-59d9-9533-4fbb59a179f1",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fdb76b07-93bc-5fe0-aa0f-8b01d1f9d5dc",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d9113f3-1492-5005-99c6-5d4e00952ee7",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34486 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5924dfed-984f-5dfc-90d2-129aa978faac",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-i18n-es."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-es@9.0.46-tuxcare.5"
    }
  ]
}