{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3ae4dce7-2379-5457-b591-eab9709647f3",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-annotations-api",
      "version": "9.0.50-tuxcare.15",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:d4364328-0cfd-5134-b917-6d1e479a97d7",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-11996 does not affect version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api. Version 9.0.50 is not vulnerable. Summary: The target repository contains a functionally equivalent fix for CVE-2020-11996. While the implementation differs from the provided patch, it addresses the same performance issue using a more efficient approach with ConcurrentNavigableMap.subMap(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:865402c0-6340-5a0d-9ab0-4e7682e77d0f",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d438606-5e56-5fb3-9553-734cdd1b4a84",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api. Version 9.0.50 is not vulnerable. Summary: Target repository already has the fix for CVE-2020-13943 applied. The maxConcurrentStreams check is correctly located in headersEnd() method, not in headersStart(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f58252d-cae9-5d13-8fdc-dd139f28f259",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-9484 does not affect version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api. Fix already present in baseline since 9.0.35. Verified in java/org/apache/catalina/session/FileStore.java:303 \u2014 canonicalFile.toPath().startsWith(storageDir.getCanonicalFile().toPath()) containment check is in place. Advisory range 9.0.0.M1-9.0.34; 9.0.90 is well past the fix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44196793-ec75-5645-969f-4e45c052bb99",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32c88d3e-4935-5b79-a632-45557895f827",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96f9e20f-ec51-5258-a7b5-1bdcd3fc36be",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9448849-6045-5f10-b4c8-3cffc2205979",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3afa8f7c-0f20-514e-8caa-0190bcd8634f",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c00b81f0-f95a-5375-8a22-bf9612c5c62c",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-34305 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8757bb02-b593-58ae-a34e-2ef60b5e350c",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:200808a6-d132-5ea9-9bf9-52e525ccfec9",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84f2dfc8-fc6d-584d-96fc-235fa211a3c5",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-24998 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:814cccb6-636b-5245-a2b4-92b2a48574eb",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a15c3c0f-5b6f-5115-b391-777ad05e2ba0",
      "id": "CVE-2023-28709",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28709 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa0bb13d-dc57-527f-8782-5608f65a027e",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20287436-5e04-58f1-81df-2d6f1e22ab4f",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42795 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5698ecfe-9356-5b0b-a94b-34d77ae1ddf3",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebbaa474-65b0-51af-add2-59053cff82c0",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2558d9f-6b7d-5894-b727-f63378a37f1a",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-46589 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4456bb91-5506-5a16-b938-ba9f4dc51a43",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3405e8a5-81ed-548a-8b65-bcea6c9c3a88",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1490766f-44c3-55b0-ae88-1defd74bc9a9",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84e48ae7-8024-5bdd-a204-9219a30a7831",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5bf5b7a-5abb-5b79-bf80-1c9747c0c215",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5d90b08-ca49-5dc0-b8b3-bda72201feba",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43772836-afc4-555d-ba5c-82d0aae67783",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2dd5fdd2-026d-593a-a10b-2191e6727a2c",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35540869-e87f-5cae-bf6a-6031653e4859",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6e12dff-9c0d-5ce6-92c3-dfba47b548dd",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-31650 does not affect version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api. 9.0.50 predates HTTP/2 RFC 9218 PRIORITY_UPDATE frame support (added in 9.0.76). Advisory range per NVD/Snyk/GHSA is 9.0.76-9.0.102. Code inspection confirms: Http2Parser.processFramePriorityUpdate method and priority parsing in Stream.emitHeader do not exist in this baseline. Vulnerable code path is absent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9832b23d-51a7-5999-8806-e71255d1a6a9",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7141594a-138b-5802-8b76-494cf08efefc",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66e0ee90-3323-5631-a95b-ff32d2f2ccc7",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cad3eced-18aa-5a38-b913-aad846aad328",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87a08c6c-24b3-5b01-bd5d-d2c1aba18081",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:beb80395-9f18-55cd-8236-36618d2cf4c2",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6443e641-af1a-5a50-8f4d-f1d2a99032dd",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ea845a1-daa8-5a92-b9df-54ee011f2dd5",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5382f8d5-4bbc-544c-8011-42c1c1a97dc1",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1e09775-df81-5996-9c2c-05b391cbde20",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d70c94f-ef08-55a7-bcbe-0e68a33e0af9",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b80670e0-13aa-5d0f-8ff7-04f930253242",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76cd121e-f10b-5cf2-984d-598f30b8de46",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c896be53-581d-524a-90d0-30a367f31058",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37ebe575-b1ae-5756-8451-75f28370780e",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c03fc7d5-9db7-59be-a0ee-e89905499feb",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:adf77e82-3c95-5ae2-bd43-7eeff8621206",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e0d4545-03cd-5ebc-92fe-98f5c1344e81",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:009576ee-a9cb-5d6f-a01b-544d4b0d6df4",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06761598-e3a2-5955-850e-7334709b4a42",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f4d25c5-209d-5ae6-a070-d423c1174bc7",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34486 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99bf1fbb-b79a-540c-b4e1-5f213f3dbaf3",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bd18ce0-2354-55d8-b6f2-89e2c53f2138",
      "id": "CVE-2026-41284",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41284 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53db0fe1-cc1c-5a42-bc9a-cfddf05f4373",
      "id": "CVE-2026-41293",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41293 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:363cf1a7-adbf-56a7-84f8-9603125d465b",
      "id": "CVE-2026-42498",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42498 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b45d8a2e-88c0-5c24-8c80-d097afe0629e",
      "id": "CVE-2026-43512",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43512 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d414625a-b67a-52ab-a135-deac448253aa",
      "id": "CVE-2026-43513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43513 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18642499-e403-5513-be0e-839d403650f1",
      "id": "CVE-2026-43514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43514 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:195be9e6-b7e9-51fd-97db-4bf7c8fc0d40",
      "id": "CVE-2026-43515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43515 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-annotations-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-annotations-api@9.0.50-tuxcare.15"
    }
  ]
}