{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f0f215e4-1a93-59c9-a5da-b5b769626912",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-websocket-api",
      "version": "7.0.109-tuxcare.1",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:3fd16d8a-f601-5a47-898c-a06d67154a21",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2507edcf-353c-5c31-9b71-0dc58ee69b6c",
      "id": "CVE-2015-5174",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-5174 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2a6371a-7c60-5bae-a0c8-66201468f18b",
      "id": "CVE-2015-5346",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-5346 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:633f7907-638f-5639-b5c9-934cca85170f",
      "id": "CVE-2016-0706",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-0706 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72bebe27-b49a-551e-bdfe-f2c945ed4144",
      "id": "CVE-2016-0762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-0762 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ecff935d-d4ae-510f-8c93-a792b18bc583",
      "id": "CVE-2016-0763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-0763 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a2d60c9-4c7b-5717-91ce-48876a4ceb4d",
      "id": "CVE-2016-5018",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-5018 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5a0d769-d90f-5f7f-878c-680576fafe4e",
      "id": "CVE-2016-6794",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-6794 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b1c8909-86eb-5866-8e0c-90c2b4df1fed",
      "id": "CVE-2016-6796",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-6796 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b18a47a1-436e-5f0d-a87f-be5a38ab6ec7",
      "id": "CVE-2016-6797",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-6797 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5eef5620-cde0-590b-a987-4d816a2b7575",
      "id": "CVE-2016-6816",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-6816 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cac64c73-427d-500f-afef-efc38c612553",
      "id": "CVE-2016-6817",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-6817 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f7d0892-d8f9-540f-b834-db43c7953fb0",
      "id": "CVE-2016-8745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8745 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a350aa95-e191-58d3-89c3-352b95de62b6",
      "id": "CVE-2016-8747",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8747 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc928200-79a7-5844-b281-e84be4662b0f",
      "id": "CVE-2017-12617",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-12617 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce7084f9-9cf3-595a-b6cd-7b502bbe652b",
      "id": "CVE-2017-5647",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-5647 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7c9c1a9-c962-5e36-b62c-7b30c3c50591",
      "id": "CVE-2017-5648",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-5648 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f28697d-e0c1-52bc-95d3-8171d20b7643",
      "id": "CVE-2017-5650",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-5650 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf37c367-d36d-5127-90f7-65ec1ece9a41",
      "id": "CVE-2017-5651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-5651 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c4b1a9c-5229-52f8-bf78-0cce2f6cc02b",
      "id": "CVE-2017-5664",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-5664 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20d54149-8eda-5507-982c-e8e51580ea0b",
      "id": "CVE-2017-7674",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-7674 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ddcb9ea-5821-5885-afe5-8aa7d1746810",
      "id": "CVE-2017-7675",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-7675 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:779c1351-7d82-5e7f-8232-f49f98d607a9",
      "id": "CVE-2018-1304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-1304 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25a7863c-a073-596e-9798-be99febd6831",
      "id": "CVE-2018-1305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-1305 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7527049-6a11-5d7a-9eac-73dceeaa6de4",
      "id": "CVE-2018-1336",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-1336 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a1a797b-a9b0-5e3b-88b4-887e6f5d2047",
      "id": "CVE-2018-8014",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-8014 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14ec0f27-7992-5b8b-bb5f-490f1361d3f2",
      "id": "CVE-2018-8034",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-8034 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb8013fc-253f-5dce-b011-6ac0ce16f3b7",
      "id": "CVE-2019-12418",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-12418 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7fccf0fd-9a56-5536-ab5c-62cad0e801ca",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a488817f-18ea-5e48-99e3-96a9237f11a9",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd52395a-c7ad-5238-b341-b39975124a13",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:881116e4-3f85-5fb9-b789-fd1120169fc5",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bae19fb7-98b7-51bf-8951-0892f7120394",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4e56192-b47e-53a0-afd0-7fba0312b641",
      "id": "CVE-2021-30639",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-30639 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3af589d4-2e06-5560-9402-4bbce89265e0",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0448d19-694d-5e4e-8115-af11a1d0604f",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-23181 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a38663f4-6cb9-59cb-8514-2dd7963c1efb",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0cf782df-034f-579f-81ba-cb3d8393095e",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52ad865a-aab4-5301-8dbb-58a137e536f1",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09adcb0a-96db-5bb7-b88f-ebeb3b675924",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38286 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ba8750b-ac46-5ef0-a49b-de84099b44db",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52316 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a61f9f68-58c0-5d51-a753-f1ebd8d4ce76",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31650 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05f851fe-db27-545f-b1b2-0cb1f1de2104",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31651 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d8a39cc-f2c4-5b56-abb3-803bfd241290",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48988 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed5064e1-b58b-5eac-8f48-5c019cabe140",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-49125 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c954b86d-7169-55e5-8a0e-04ad0e0f5448",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a75b59b-8b88-52a1-afae-991b20d96a42",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8aa995a6-36c9-57b3-84a7-bed0df1c56a0",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24880 is fixed in version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:696f8e02-82e0-5cd4-9170-f90f5e66603a",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-29145 does not affect version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api. The official CVE record (https://www.cve.org/CVERecord?id=CVE-2026-29145) limits the affected versions to Apache Tomcat 9.0.13\u20139.0.115, 10.1.0-M7\u201310.1.52, and 11.0.0-M1\u201311.0.18. Version 7.0.109 is not within any of these ranges"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6714cc5b-c42d-58b0-a5a2-fb8169643229",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbfac28f-1988-5033-bf6c-6858d960deaf",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@7.0.109-tuxcare.1"
    }
  ]
}