{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:9ba3ea7b-463b-5ef1-b75e-7188498b5596",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@9.0.100-tuxcare.4",
      "type": "library",
      "group": "org.apache.tomcat.experimental",
      "name": "tomcat-embed-programmatic",
      "version": "9.0.100-tuxcare.4",
      "purl": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@9.0.100-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:6e3de64b-9350-5908-a8b7-9018470b9902",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.100-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7fa9aa8-ec51-50d9-b434-790251fa135b",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.100-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:695a1996-ae92-5a7f-90b7-b18298b245c0",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.100-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67c94c12-0647-5caf-b15b-9703e599854a",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.100-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7fcdef73-6c4e-57e4-a741-87c5cf87d07a",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.100-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f282abac-0fdd-51b6-93d5-86680d35a766",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.100-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:422d2ec5-b8bc-5be4-8838-7be6619453b3",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.100-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:068e5f30-dc65-5e61-aefb-a3e047cba62e",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.100-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6d4ba57-2d09-5d6f-9936-0c4776be620d",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.100-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aacd0a28-4c46-52f8-9ce4-f81fb7bd90c1",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.100-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e964b32-3bcc-5327-ac7c-ade791ee33f5",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52316 affects version 9.0.100-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12981bdd-0120-5f85-a909-6ed05d084568",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00cd2250-8f34-5cf6-b135-bf74d68266ca",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0507510-92a7-5f54-9215-9e5b931abfd3",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:057a5e4a-efc2-5e24-98fd-4f090c3e95a5",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83438b48-3d37-5804-af84-d1db43e1d06d",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32433e17-4c81-5726-8ca2-7d6b0d01ac38",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:740c6674-efdc-51a3-8387-526a6190d1d9",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75edd293-288f-51f7-8130-a30719a823e4",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55e035c1-b35c-5658-b7b3-9b7e7450f97a",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e25898b8-a01c-54dc-aa68-bcd02fa2ee40",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5e5b97f-4964-55f9-a724-69e3d74d5cf3",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7df8279f-55e9-52bb-a446-2dccb865a854",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55752 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f99c5b8-19e2-5a07-9fce-8e2df07941d6",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8527508e-0704-598f-8cde-46601488afbe",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23eb8470-2e89-54c0-950f-a77190bfc9f2",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.100-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f6ecaf0-fec7-57a5-89b2-003bc4e9224f",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61b028d8-fae5-51a7-a28c-d1dcceedc9f1",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.100-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a171adac-babd-545a-9eb2-0a7694165c13",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.100-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56de847c-dd1d-5287-8e0a-40422b13ddc4",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1788a40d-9370-56b6-9265-94f40eb8f14f",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.100-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93e30bef-65f0-58b1-b161-8c980c242146",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb2ac008-cf8a-51fd-a16a-4e2d2b0dcdaf",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.100-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ffc058f0-e1d1-512d-a8ed-b74ed0ad0216",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.100-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46a4e493-9d22-5bac-8fa2-e8f04bcec607",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.100-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6de52fa-fdc2-598d-90bf-baa405c29d79",
      "id": "CVE-2026-34500",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34500 affects version 9.0.100-tuxcare.4 of org.apache.tomcat.experimental:tomcat-embed-programmatic."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@9.0.100-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat.experimental/tomcat-embed-programmatic@9.0.100-tuxcare.4"
    }
  ]
}