{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e131ca62-64dc-5431-a9de-bec78afa02bc",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.90-tuxcare.4",
      "type": "library",
      "group": "org.apache.tomcat.embed",
      "name": "tomcat-embed-el",
      "version": "9.0.90-tuxcare.4",
      "purl": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.90-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:24432450-45a6-5358-891f-d5009150dd51",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.90-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12e910bf-e93e-53c6-9d34-e32c4350fdf2",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.90-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3dd4f625-ec69-5e72-a798-33aab03662ca",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.90-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-el. Fix for CVE-202-13943 for this version has been already backported by the original developers, so brunch 9.0.90 is not vulnerable"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9c8e56a-c77c-57c2-b622-2cc049c83aca",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.90-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60969dd8-cd4c-5ff7-b847-02b4847da3cf",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.90-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bf08c6e-7c68-56e2-a7b7-f059e3263a65",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.90-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24bf4a0a-a4b4-5516-a08b-cc7cb4863fb7",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.90-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f02ca131-fa1c-5e3b-98b7-8c25fe903497",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.90-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f260d6c3-9e74-56a5-bca6-a1ea105e056b",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.90-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0ee75a7-97db-56f6-9aac-a47be5c940db",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.90-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:273f937f-bbc4-568b-925a-50df7a246fc5",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c86425d-6dd5-5620-8dce-89482a44f31c",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6bc833b-79ae-562d-b71f-432bec8def4b",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.90-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d70bbe00-09a8-5617-b61e-47b400fa5081",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:440dae10-b075-59c2-8f95-850fe091eb81",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ca76a26-ea92-5ef4-a132-47a0078e0e3e",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c00b48e-38f0-51c5-bd84-1ee300128a73",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31651 affects version 9.0.90-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:202f8955-cec2-5400-8f1a-c1963b5a08cd",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:961439cd-407c-58b2-9724-94d74e7b296a",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1aaf8779-5108-56ae-bd7f-50c7cc985e36",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35cd5742-8edf-58d2-a709-283ba0133df3",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2461a4fa-6699-56d6-8333-e32ef3033ec3",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-49125 affects version 9.0.90-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f52510d-2ca8-535a-8bc8-d46370ae0fbf",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a912651c-da96-51ed-8abf-2eaec3390c8f",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a03f83df-0858-5985-9663-303386eaf7d9",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6eef4c6-634d-5e72-8adc-7399d7f6ff0a",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d506e310-6b86-58af-9b04-a6840456a849",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.90-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fc18b81-26be-54ed-88db-d53ae3921350",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fdfe4613-1bff-5e44-9642-0d4227da3229",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ebb3b3d-e7e9-5108-a605-bdce8a2e30fe",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c91d826-41ca-57ad-bc24-c8e5e1261c86",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9826302-509a-5a15-9106-f53004e04599",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.90-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:708e6868-cdb6-5f3a-a275-a1b0c4f78cc1",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.90-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c63e4e51-e3ad-5ee5-a64d-a08ccd47da4a",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.90-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6edf714-0395-5972-a838-165d00b0a25b",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.90-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6cf0dfcd-1736-53c1-add1-b843f2494a86",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.90-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:275a6676-b3c2-5ad3-8c55-c04cd7a9b8d9",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.90-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51f5319b-6592-5b4f-8f0f-366fd20b2ccb",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.90-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9f52cb5-c9c7-5347-9684-9598f7b69f41",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.90-tuxcare.4 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.90-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.90-tuxcare.4"
    }
  ]
}