{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b6ea0e9d-c126-5b73-ba47-a0ac813e6467",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-catalina-ha",
      "version": "9.0.50-tuxcare.11",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:0f94426e-0d29-5b64-9978-7bd9c5fb48bd",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-11996 does not affect version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha. Version 9.0.50 is not vulnerable. Summary: The target repository contains a functionally equivalent fix for CVE-2020-11996. While the implementation differs from the provided patch, it addresses the same performance issue using a more efficient approach with ConcurrentNavigableMap.subMap(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea10291c-a1dd-5ca4-b5ce-9acdd08f5add",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be68080e-7fcf-5eea-9c06-4368ac34dc42",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha. Version 9.0.50 is not vulnerable. Summary: Target repository already has the fix for CVE-2020-13943 applied. The maxConcurrentStreams check is correctly located in headersEnd() method, not in headersStart(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e6b1a8d-d101-525c-a283-5f669f8f6c91",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-9484 does not affect version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha. Fix already present in baseline since 9.0.35. Verified in java/org/apache/catalina/session/FileStore.java:303 \u2014 canonicalFile.toPath().startsWith(storageDir.getCanonicalFile().toPath()) containment check is in place. Advisory range 9.0.0.M1-9.0.34; 9.0.90 is well past the fix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e5173b1-98fb-5408-a461-5fb456f71a42",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c467dd0a-0f23-5271-99ba-497a28e5efec",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:765976d7-789c-5abd-b9ed-d4c7640e5efd",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbaadcd7-91fa-5158-a47e-8a8c35e112d2",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ffe5f2c-a50b-52f7-93de-1d5ddcd58f8b",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ea993d3-1940-5f7e-9ff9-5a58431895ca",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88097d4c-449e-5e20-9e09-2aecfa77e148",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1032811-506d-540e-9f53-9f7e2857b05c",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fda9da26-ad3d-5634-af3e-52ca2f45cb22",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-24998 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9caffb18-55c6-540f-9c8f-1acd028fea77",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3408bc5a-358d-567a-b6bf-37a616038539",
      "id": "CVE-2023-28709",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28709 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7cb098f0-da70-5060-ac58-ff902988a144",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78e4643a-d6bf-5b9f-84a1-c2ba0f9d6a81",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42795 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f46afc1a-bf13-5188-ae69-0fa3b3c7fe9c",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa7b304e-3e75-530d-99ce-b93a6e1e317f",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2e2c8e5-56d8-5406-96ee-f4436837349a",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-46589 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81760454-1e07-5d45-ab22-479deaf82755",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e46eb12e-422a-5fe7-916d-d7e5c0aa5918",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd48ae15-6d65-5acf-ba39-67ed997bef98",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b14957d-03ea-513f-9e0c-2d856bdd5430",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a9b5d4b-65e9-59f3-a8e3-128b4260f19a",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3140fc2-777f-579d-8fc6-ad992eaee480",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdc09668-1a93-50fa-94d4-ad8113ca95d5",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e88082f-41ea-5b79-a202-b963c4919eff",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56337 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:243c4573-82a3-5f18-afe6-6ba8e451ede5",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a05312f-48b0-56ee-a860-3df3e1919da9",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-31650 does not affect version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha. 9.0.50 predates HTTP/2 RFC 9218 PRIORITY_UPDATE frame support (added in 9.0.76). Advisory range per NVD/Snyk/GHSA is 9.0.76-9.0.102. Code inspection confirms: Http2Parser.processFramePriorityUpdate method and priority parsing in Stream.emitHeader do not exist in this baseline. Vulnerable code path is absent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e771dc2e-7a48-5f7a-aad9-127ed0cad3e9",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3918be74-e4f5-5d87-ab0d-285e5ab09eb5",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b61cab3c-09bf-5fdc-a6dd-dd75f17b2fe7",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ee932bc-4aeb-5eb9-b5ae-fdbb472e8383",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48989 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc3a94d3-56c5-5036-93cd-cef859bd27e0",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:169aaf47-462d-57cb-a9f8-b4ffe7935fb6",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd305958-9638-51f0-adb2-e63f0262aa0c",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b71e358-601e-5cc6-b70a-63eee7083f12",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1eb14e7-8d80-53bf-9370-7b0c1466aaaf",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:adf1f9a4-5722-5431-96c4-43dac4f68c4d",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f97c0ad6-f027-5185-bbbc-a456b54df0e4",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5e50607-ba5b-5670-a08e-7c12e71d0df6",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff666b8b-f4b8-54db-9e02-5cd60538457b",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69943ba2-3221-5359-94d3-8179efbe150e",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63d79986-d00e-54cb-a966-f376de7117ac",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95f65aee-7424-5bb8-a4b5-1f35c6ace02f",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:600530b0-3a65-5926-b7ff-47742d33e5b2",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b673c46-7af1-59c0-bbd3-72369c716f78",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2138685-c725-590b-b87c-b1f3906f1244",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6fdfb5ee-780b-5713-a2d7-25f3db4d00dc",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e92ae6ba-4ea2-55ce-a1e3-ba02fb53f5a9",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34486 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2194234e-2fec-5042-881f-43706e0544aa",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da6bfca3-1843-5c95-acd5-2863997047e0",
      "id": "CVE-2026-41284",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41284 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3f45291-45d8-54df-8129-fdeeab33a187",
      "id": "CVE-2026-41293",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41293 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74d52dc8-3b15-53fb-afcb-dbea175c10a2",
      "id": "CVE-2026-42498",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42498 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f89d834d-90e5-54a6-a372-00131c2e1a00",
      "id": "CVE-2026-43512",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43512 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90bff4fc-964e-5d99-bfa0-058177da9b4f",
      "id": "CVE-2026-43513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43513 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4e17452-4c1d-5897-9687-a7a14fbe4096",
      "id": "CVE-2026-43514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43514 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:869f8678-648b-5613-8234-29a036b40621",
      "id": "CVE-2026-43515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43515 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.50-tuxcare.11"
    }
  ]
}