{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:11b104da-9056-58dd-9ec2-177e57d0845e",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-i18n-ru",
      "version": "9.0.87-tuxcare.1",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:d8408bac-f463-5231-b86d-a3537649bdbd",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-11996 does not affect version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru. Version 9.0.87 is not vulnerable. Summary: The target repository is NOT vulnerable to CVE-2020-11996. The vulnerability has been fixed and further optimized. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38d5d170-c0cf-5afb-960a-f63b053644d0",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3090c43-2cce-5d82-a258-803eae145b4c",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru. Version 9.0.87 is not vulnerable. Summary: CVE-2020-13943 does NOT affect the target repository (Apache Tomcat 9.0.87). The vulnerability was fixed in version 9.0.38, and the target contains the complete fix. The vulnerable code pattern (concurrent stream check in headersStart) does not exist in the target."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73a48ce2-431a-5c89-9fb2-62be183343b1",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-9484 does not affect version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru. Fix already present in baseline since 9.0.35. Verified in java/org/apache/catalina/session/FileStore.java:303 \u2014 canonicalFile.toPath().startsWith(storageDir.getCanonicalFile().toPath()) containment check is in place. Advisory range 9.0.0.M1-9.0.34; 9.0.90 is well past the fix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe4a03a8-e69a-5c56-b196-259560ecdebb",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1536e2d9-e106-502a-9aad-7c84f868bbd9",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-42340 does not affect version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru. Patches already applied: 31d62426645824bdfe076a0c0eafa904d90b4fb9 (already in target via 80f1438ec4 'Close WebConnection', b94ecd1b69 'Make asynchronous error handling more robust.')"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03963c79-27a1-5681-9e29-9ede8fe27de2",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-34305 does not affect version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru. not_affected \u2014 CVE-2022-34305 affects Apache Tomcat 9.0.30-9.0.64. Target version 9.0.87 is not affected because the upstream Apache vendor already fixed the XSS vulnerability in the Form authentication example. The fix (commit 8b60af90b9 by markt@apache.org, June 23, 2022) adds HTML filtering via util.HTMLFilter.filter() to all user-controlled outputs in webapps/examples/jsp/security/protected/index.jsp. Thi..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a34f11b-4f97-5d5b-847e-9b981962acb1",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-45143 does not affect version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru. CVE-2022-45143 is not a vulnerability in target Tomcat 9.0.87. The upstream Apache vendor fix (commit b336f4e58893ea35114f1e4a415657f723b1298e by Mark Thomas) that adds JSON escaping via JSONFilter.escape() to prevent JSON injection is already present in the target's base 9.0.87 release. All three error report fields (type, message, description) in JsonErrorReportValve are properly escaped before JSON output construction."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3f9e738-c1ec-5bb7-b0ac-110139045cd0",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-23672 does not affect version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru. not_affected \u2014 Target Tomcat 9.0.87-tuxcare.6 is NOT affected by CVE-2024-23672. The vulnerability (incomplete cleanup of WebSocket sessions when clients fail to respond to server close messages) was fixed in upstream Apache Tomcat 9.0.86. The fix (commit 52d6650e06 by Mark Thomas) was already included in the upstream 9.0.87 release upon which the TuxCare 9.0.87-tuxcare.X branch series is based. The current H..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc213798-635e-5af0-9df3-e340d1bc21c8",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-24549 does not affect version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru. CVE-2024-24549 is not present in Tomcat 9.0.87-tuxcare.6. The vulnerability (DoS via delayed HTTP/2 header validation) was fixed by upstream Apache in version 9.0.86 (commit 8e03be9f2698f2da9027d40b9e9c0c9429b74dc0 by Mark Thomas). TuxCare's 9.0.87-tuxcare.6 inherited this fix from upstream 9.0.87, which already contained the vendor fix. No TuxCare backport was required."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7b3c6f8-017d-58a6-8325-991d87fd4ba4",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc96ce46-55b7-52e0-a170-cc27fe5a3e4a",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1fa5c0dc-ba2f-53de-b6f1-85a8fcacf6b5",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-50379 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe00d7b2-f41a-57b4-86b0-0f8bd302c4b1",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0731fad6-0945-5672-834b-af41b383b3c4",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-54677 does not affect version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru. Patches already applied: 9ffd23fc27f5d1fc95bf97e5cea175c8968f4533 (already in target via 2b6287521b 'Add support for JSON responses to request header example.')"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65af0822-b077-5156-8e0c-17b3c4cf9e00",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56337 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05aba4ce-07de-5c43-9d43-bb9ea2db055b",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc2b5236-fd7a-52eb-9547-e4f17a6ad96e",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2885922-bb1a-58ca-bd81-09f2d97e3753",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb25150b-5ff9-556e-938a-05d10e58bb66",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66ad1d58-b340-5a61-8391-09a5ae19c50b",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48988 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf85bd80-d154-52d5-814d-078e3900a107",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57ea3c3d-2e6d-5985-9fe0-376de97de9de",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23ed13d5-2d0b-55cd-9998-80eb027adff3",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14858114-ca81-53d9-9895-b3f689b23fd6",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:669b4b5d-c1f4-5cdc-ab88-bcf6fc912d7d",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52520 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2069841d-9e29-5b9e-9345-bc3bf316d560",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f0a340f-b48f-5104-a04d-60eb3ffb49a8",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1acc5fe6-1d40-5aae-a8bd-fab3e9bf0a5d",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fdd4ffd9-c1b6-5e21-9284-558a5d7fd1a6",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5b7d3df-c65a-52f2-8faa-71a428f97988",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:143d8331-dec5-550b-a6de-f8e38b65c119",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bab5b8a1-ae59-5af6-aef5-78f4346e4647",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38576d00-1257-5206-83b4-5daafbc736fe",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46ef1e57-2d47-50f6-b9ba-cc73e1289456",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ce242ba-e4b7-540a-b30d-6088c93546e2",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7efe709f-9db7-5924-97cc-09ef661ad7b2",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e02a884e-0833-5d17-823e-91e1cc6e1030",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11372b96-4346-5855-9f18-d7cb7016a208",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91e3f32c-7ba7-5fa7-98e4-8cb3c7ee84a6",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d1370d9-be04-5a78-9e53-0d52cc07d727",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34486 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e457650-407b-54ba-9365-b7efda019c57",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc8cda2f-cb85-506a-9050-b78c2d1eac99",
      "id": "CVE-2026-41284",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41284 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95a63273-da8d-53fb-a5aa-000b3888cc33",
      "id": "CVE-2026-41293",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41293 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01065322-26f7-5a58-9c74-784e6a6095b1",
      "id": "CVE-2026-42498",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42498 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11ecd6f7-026c-5fab-b6d2-55efa8a8168e",
      "id": "CVE-2026-43512",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43512 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7319631-c0f7-529b-bbe9-d96d978a4f56",
      "id": "CVE-2026-43513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43513 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15149734-f268-5e3e-9696-6720a7ddc839",
      "id": "CVE-2026-43514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43514 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5b376b1-86f8-5ca8-b8b5-e7407ed91128",
      "id": "CVE-2026-43515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43515 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ru."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ru@9.0.87-tuxcare.1"
    }
  ]
}