{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c92a7d13-7919-54cd-9756-9fdb7bdc4530",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2",
      "type": "library",
      "group": "org.apache.tomcat.embed",
      "name": "tomcat-embed-el",
      "version": "9.0.87-tuxcare.2",
      "purl": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:6edba388-1600-50d7-a2d3-e307ade90a7b",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f35284be-93dd-505b-9fb9-838791f0668b",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca30d0be-b29a-54da-81db-707ce2b40f5a",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c0bd861-04f7-57e7-87c7-3408a8c5ae38",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4d8b102-b3bf-5d54-aba5-33179ee641b3",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cad28c8c-1b52-5b25-b44c-6a72f88c1c23",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b720372-b3e6-55f3-9efb-b358304ddc00",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9dd6ea0-3399-5f92-bc4c-cfad51b2db4a",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:884e7009-f8a9-55ce-aef8-1d600afa9cf9",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7338e503-4a93-5e52-bf39-44c037c443c5",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fab64c0a-462f-5e08-8251-90b20ebf965d",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4cfa441d-b82c-5f13-8d60-ca2c2ed773c6",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1faeaf4e-5aee-59a5-afd2-69ebf73a53e1",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e32cc283-d2cc-5b97-a806-0412286c9aac",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f998a2ac-045b-58f4-b139-28677267be14",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b733025-dffe-55f2-8c75-0a73ee10325e",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e134802-3064-5401-a2cb-8a293e962cc9",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4f87c6e-a248-58af-8632-591f3f058550",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10161684-f7d4-583b-9911-a654f4507528",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e591d1a-3174-5843-a55a-f123cceec03b",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0cbe0622-4ade-56b6-baa3-da025df876e8",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48988 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a09260bf-594f-5954-a8d3-4c6107a32ec1",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43e83952-5135-53db-ba64-8d70a501a957",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee924704-4e09-5cc2-8d01-5a671c6b3cd6",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3dedaa02-c8d8-542a-855c-9791e2c8a61c",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcff06ab-8a10-5891-97a5-e6ac21618b16",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52520 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:223797cf-9b94-5da6-ac94-97f602343874",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b9f6a24-69f8-5e30-bbaf-a496f45fc7ad",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f094b429-0d55-50b1-93cb-5c59a4ca59ec",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1339d7ba-570a-505a-b568-d9a25a1ea05f",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97c62947-2464-51c0-a28e-b9e0b225c72d",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fcc9b15-819d-5c3f-9c12-f27696b70d07",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:534c30b2-357f-5975-8bb3-a64bd31ef03d",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14a4b7ec-4a97-56ff-bd7c-ccd7d7df7251",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e7b7440-0cc5-5f4f-8054-47dcb3bb8ff8",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aec94602-1f4b-555d-bae7-27b7e8578780",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8ee1958-ff30-5850-aacd-37c0625ef287",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a596b61-551f-521f-9d89-551613715dda",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4ef39ac-e00c-5ee1-8ea5-d3632348d1fd",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b307c3f-b25c-55b4-8d19-390439f69089",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5138b0d9-9b39-5ecc-8322-983bfd0781ac",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.2"
    }
  ]
}