{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a04c3701-b175-5f02-8d9a-50b10cbec85e",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@10.1.18-tuxcare.5",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-servlet-api",
      "version": "10.1.18-tuxcare.5",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@10.1.18-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:93d1183a-b938-5862-9839-5515fbdd510d",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23672 is fixed in version 10.1.18-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@10.1.18-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72122f6e-7dba-51a9-92cb-6a1697262ec4",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-24549 is fixed in version 10.1.18-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@10.1.18-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7416eeb6-c39b-55bc-bbf8-2c1c56916bb6",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 10.1.18-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@10.1.18-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf555327-342b-5f67-a934-3630016b9eb7",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 10.1.18-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@10.1.18-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8b9d06f-0ec4-541b-bb40-3f9f80eeddbd",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 10.1.18-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@10.1.18-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af662d63-2529-58a0-b0c8-d11ff1268559",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 10.1.18-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@10.1.18-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0dfea5ac-b4b4-5bbc-b626-2ccc869bd8cb",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-54677 is fixed in version 10.1.18-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@10.1.18-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a93ccc35-232d-57fc-bdba-09f6c1286cfb",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 10.1.18-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@10.1.18-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0aff61c-bf7d-5a44-8b8b-914f231e8347",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 10.1.18-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@10.1.18-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ecc7ac56-3576-5367-b8dd-22b13b62ef40",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 10.1.18-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@10.1.18-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:329e09a8-1a0d-52a6-9e0b-185f519ba598",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 10.1.18-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@10.1.18-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca4428f8-8594-598b-87a1-e1dd8b9cb699",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 10.1.18-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@10.1.18-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:668b39cd-bcb1-57bb-a455-ca667483d005",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 10.1.18-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@10.1.18-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf3af167-337b-5a46-bcfe-043294a3cd78",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 10.1.18-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@10.1.18-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38fa481c-da8a-5a2c-accc-ff9bd9c8d9f5",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 10.1.18-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@10.1.18-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:121e7ab6-0dfb-5347-ac86-ea14349a3d83",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 10.1.18-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@10.1.18-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31ed13ee-a721-5e6f-a116-87a742036f65",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 10.1.18-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@10.1.18-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7fabc470-875c-51e8-a9c6-50ccc57477e2",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 10.1.18-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@10.1.18-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f68d158-94e8-578d-b463-e19b5ef0f2be",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 10.1.18-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@10.1.18-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:542758cc-d72d-56e9-a8fb-4e6f335fbe2b",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55752 is fixed in version 10.1.18-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@10.1.18-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81498f15-9bfd-5278-bd93-e0ec3ac6771a",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 10.1.18-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@10.1.18-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8510a8be-3a77-54cc-897a-8fdd2c77e3fc",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 10.1.18-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@10.1.18-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69891611-48fc-51f6-bdb9-7070f9a85952",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 10.1.18-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@10.1.18-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15403827-1e6a-59d9-b22c-af3f234ca38d",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 10.1.18-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@10.1.18-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb26a534-cf82-5a09-910d-0d11dc2a4e71",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 10.1.18-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@10.1.18-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbbd33d8-8e2e-5e26-b0d7-4d028cb38c9f",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 10.1.18-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@10.1.18-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c1e73ab-8a6e-57f9-bff3-b9599705d837",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 10.1.18-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@10.1.18-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e6bdf04-bd43-5236-94e9-a7bf99848cea",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29145 is fixed in version 10.1.18-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@10.1.18-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2e5a354-02c5-5330-868e-a9ec17371790",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 10.1.18-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@10.1.18-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e474cd4-3487-52bf-b8ec-7a40ea65cb92",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 10.1.18-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@10.1.18-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8760ec15-c441-5a29-a6a7-246737547f15",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34483 is fixed in version 10.1.18-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@10.1.18-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b35dd3e-9adc-561f-bdb0-5ac7fcb8c802",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34486 affects version 10.1.18-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@10.1.18-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f545c2a-a0ca-5e59-9479-f17047ce6571",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34487 is fixed in version 10.1.18-tuxcare.5 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@10.1.18-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@10.1.18-tuxcare.5"
    }
  ]
}