{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:37cdfecc-cecb-591f-82c6-0936f93ef39c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-ssi",
      "version": "9.0.46-tuxcare.6",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:c6bc0d94-6b94-5030-8f68-7f7ea6cb8886",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:699f9207-25c6-590e-bb79-4af730a6c9e1",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d548b56-6c29-54b5-b099-e863ba5de727",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:686b6689-8229-5874-90ba-6e600ccc8cc6",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f67436a-e5a2-541a-bef4-750d51f861ce",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a9c4629-77d0-5ede-8b03-e8f20817b193",
      "id": "CVE-2021-33037",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-33037 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b9e3330-18ea-51a1-9b09-168df5b482e1",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f69c34b-9718-51ec-88d2-06ab64d4d829",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bee76433-f3c6-5976-a5d4-611cbcbb8aa2",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0339c6a2-9057-5e11-8593-a3c7c2988c43",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed22949a-4bf4-580f-a54d-a06c9a516793",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-34305 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91aed642-17de-59df-b92b-fb66f1fe2bb6",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1805cd8c-b2c8-516d-9030-b19322b359cf",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2797195b-e75c-5d38-afca-69733f38434c",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-24998 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da5e9369-0e87-5517-be75-653054b59996",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfe62803-000b-56b7-9bab-a9ce203912d4",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d3e4d95-1ea7-50f6-a350-d95cbb284c28",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42795 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66e181b8-721c-5507-951f-cfc7fd0ed43d",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6d1d051-3fc2-5d30-81f5-e5bdb1e445aa",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9033dfd-b83c-546e-a6dd-df8abdaca089",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46589 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2025fa9-1e08-5d6c-b544-b00b4537ba5a",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1727877-0f3d-5e5d-a708-1182f9a69304",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b79c721-ad4c-5d50-9b1f-baca1a42876a",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34750 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c181b942-c9df-59f5-9b8f-eb3f12664670",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6623f90-7393-56a5-b1ef-e1997b6efe8c",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d03e487-8a69-5b55-8b7b-b44d714cc60b",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e93a79b-f35c-5ad0-a08b-63c94927b0de",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a07a0496-b8cc-51c5-a0ec-9ac45dbc5b1a",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56337 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e462c01-055b-51d6-a728-dbac0a20a8b0",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a21c832-d331-5047-b908-a3c03b5144e1",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31650 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12b7510c-072f-5045-a566-11d5f55d3c2e",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e665fb0-724a-5f06-9ec6-38375c8d230e",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:307e0544-c904-5540-8393-b48d84ed793e",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34b37a0b-fe92-5a8f-8650-164bb80a9087",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b95727c0-c59e-51ae-b5d7-67e5ce44531d",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2571e249-8d4c-5501-ac73-efdb3c450f70",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c376111-a90a-5426-8dcb-15d346f06915",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52434 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5920c680-ae3b-5ff4-9400-db34eb502b0f",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4a8c683-3a0b-5027-b8ac-0a881a290203",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a7b9ed3-49e4-55b8-b556-a9bfc49f7400",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e74a42a-b935-5105-a0b0-72acb51eddde",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55752 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fed557b-1318-56d4-8deb-3f2022157304",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85940ed5-505f-5205-9e04-82c03a3e1672",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b0119e3-7091-5225-8210-344fbfe57521",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89a8b311-9b10-5811-8606-45865660686d",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b91495b-d863-570c-bf70-fe777740c775",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcfcd564-bf4c-5c11-9cb9-f8d0faed99c0",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bcb5252-72e0-5db6-8eaf-ed7ca9211052",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c14e92c-1b28-53eb-97b8-66c79d72a2b0",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4399c4a5-3498-5570-a0cf-3813a8179ff3",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90eb7726-14c7-5153-a5de-d03c9de5efe0",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34486 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97f7a950-cb3b-5998-b327-1ef3a71a9cae",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-ssi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-ssi@9.0.46-tuxcare.6"
    }
  ]
}