{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:8b82537f-061d-5b57-b69b-5a11a06bd681",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4",
      "type": "library",
      "group": "org.apache.tomcat.embed",
      "name": "tomcat-embed-core",
      "version": "9.0.87-tuxcare.4",
      "purl": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:eb6ae753-c269-5c29-a427-003c1debb9f3",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.87-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:590d0d72-7151-59ec-9a01-c0d6a2e0d1d4",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.87-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1cc23f1c-e846-58cd-95f3-fa7dfcdefcbc",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.87-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6a44d5e-fa7c-5de9-9072-5c075b9889e8",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.87-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:224719b9-7054-56cb-8bac-0b497a272537",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.87-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d4e4529-d063-5089-82e6-752db2caee8e",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.87-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77238483-19e4-5146-891d-edd809abb6fb",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.87-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e646d77d-6239-58b9-8ba7-2026e71fe038",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.87-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a4b8403-c010-5ac0-8c22-6319ef5f4ef2",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.87-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3036cde0-2181-5de6-9217-62bae9151045",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.87-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0305ba0e-e8da-50a2-93fd-1087e3a73dd1",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6432b314-8c72-5351-b7cc-2c99764f74f0",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e9ab0ef-f590-585d-be9d-fdcaad46b8ee",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e2e1f91-2136-55e3-8243-f2c60bac8e00",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b588f7d3-f7f3-5780-8fda-38ca283e990c",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.87-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f79514b-4a7e-5d4e-9980-dc463d3ad853",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:165162be-670d-5618-8456-a1e314ad7c05",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f341ea7-d8c7-5c9d-84e6-3281ab8923af",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc34c39b-8612-5cd3-aaf9-a8df3d6b771f",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f123894-f548-5105-bc66-4df6abff24be",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f87251b-17fd-5e62-93ab-ebc4e6804c1d",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48988 affects version 9.0.87-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17ea8b2e-4a98-526e-afdd-635871fe9a83",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19434141-c3e6-5669-bc75-b0438492517c",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7c8913c-03a7-5814-888c-0cf6eff0d50a",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0113d7ef-e8c5-5092-98c4-7cb65ee56f2a",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1eca3d30-77fe-54ce-85dd-07d69d7b3824",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52520 affects version 9.0.87-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:696e7276-0767-5525-bace-80ac16612993",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d539ea9d-3c51-5235-80bd-1625622a4556",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbb505ff-cb10-57cd-9ea9-69779d252d59",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55752 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e989a7f-747c-5b22-95be-df236d9d5099",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fc6aea7-bdf1-5784-b0e8-bf6f898dab58",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04d71e1e-4084-5f77-b003-e5fde5fc8d26",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.87-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49030642-f76c-590e-874a-7d43c7a26b1c",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc879aa3-44ac-5aef-a867-38f536d3f36d",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.87-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9efc9e6-a44d-55ec-8e39-33b4216722f1",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.87-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:248bc15e-6ddd-5589-b0c4-0f63212445cd",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.87-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:737c4741-1288-55a3-bebb-1c0fa2a78f99",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.87-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe19ccda-4d98-56ea-96c9-892f2075ffd9",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.87-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fddb7da-7a55-5879-94ae-c0804bd71422",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.87-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0e5208d-d2e0-5725-bf19-f938011355de",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.87-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20f34a04-6c3c-5711-b813-1a2a9dfeb08e",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.87-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.87-tuxcare.4"
    }
  ]
}