{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:35adf70d-2997-5b75-a642-d15f0d9d9e78",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-tribes",
      "version": "9.0.46-tuxcare.6",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:2dfcc2b4-db37-52ac-bc76-ec231b796052",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36e40f4c-70dd-5759-9ad0-6f5634f9148b",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4259c81-60eb-5b33-9c5e-34ce11f37e61",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d466d217-da11-5b28-94ef-7ff5aace7d0c",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0945b684-4987-5201-8860-130dce8b75f2",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa4ab223-bd6f-5dae-a74f-1a9d1d2c0d0f",
      "id": "CVE-2021-33037",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-33037 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2c4e530-e0ef-564c-860d-7f923f3a244f",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39883809-43ca-5e06-b080-53f019ada8cb",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fdb495d1-95ba-50d8-a969-006c3d3b3614",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3462b6b-1ed4-536c-8ebf-eded3a9c207a",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aee5669b-e9bc-5c74-8514-8c4599833529",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-34305 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fd7c42d-a0d2-5c07-8487-77585f5cf781",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7bb4dfc-be4f-5e0a-8a84-b39615463d76",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0f63076-5bb2-58bb-a8c0-df0013ead7a1",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-24998 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c523517b-a588-53db-a0a6-b0f159075634",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4572ee7e-c2af-5cfb-87fe-ab72ad167576",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7b06bec-fb1c-5901-b670-32f19f45f7e6",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42795 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:602fc7f5-a57e-5f17-a047-c0d95a95e2fb",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c6529d1-d8f0-5f4f-87ae-5a93cb1ff846",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:953dc63d-8f76-5de1-8b3b-421b95201551",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46589 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e41daf04-0921-59c3-8ad3-a1635c20e829",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60867c1f-081b-5a60-8745-4d1d9c6d5df2",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f03220d4-abea-5935-a883-5c7c97e86ad6",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34750 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60f880cc-87b4-59bc-8f6e-709b1cf393f6",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0146bfa-9800-542d-8d1d-73059872c3f3",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd1032ac-da10-5570-80ab-bfd2adb18edf",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb493ea3-02b0-53fe-b503-4e7087768cdf",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b25a9f84-3da1-5b9c-a7e3-dabf8c489b20",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56337 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f2bcd4c-181f-5399-b749-16a4ac189647",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df74593d-52b9-5a3e-94e8-8111025e087b",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31650 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efaaf511-37e1-5255-aece-ebf74830cec0",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b23e17a8-6cf3-5f9d-930f-bc2c1cfc0f6f",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47b404ea-ed81-5eec-8c38-f5fd33b13be2",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f7f41bc-5a34-5082-90dc-fc3f79663490",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f0b5e32-0aec-5640-97bc-fd681053b12d",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d30b20a-67bb-5ac7-9d15-3238a12e3385",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:595965fa-4ced-5eb1-b5ee-fad99e3d16df",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52434 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:821a32e4-cb1d-59cd-9a05-5485a2079dad",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:542d7233-d9b6-5774-94ad-6dd1fbd71df7",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cedd1d34-3665-56df-a4b7-3a183b06554b",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa995e6a-1d1f-51d2-935e-177950f71082",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55752 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5d1a45b-0cc4-5c31-8ff2-b1bca6089498",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9dcea2f4-0bd9-5067-823e-5e0a729efda4",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48e2d2ae-72f7-508a-b4f3-fea858734d1a",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c12ac500-7588-5961-b4b6-e61bf86d6963",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:435c471b-e1ed-52bc-aef8-886845812eaa",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77c92fc5-a8dc-526b-8052-724b30468de0",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f093bacb-fa22-50b8-b093-4eafc90da081",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0436d863-c58e-530f-9973-abe909ea952f",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1dae932-f39d-5188-99fd-2d764c3fe072",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19d26b83-4cd2-500f-98da-6ca070fe7453",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34486 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1cedf6b-5506-5abd-885f-2a4e054a4b84",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.46-tuxcare.6"
    }
  ]
}