{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:5b07a133-0a52-5bdb-b478-4e851966440d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-api",
      "version": "9.0.87-tuxcare.2",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:cf74e385-6031-544b-a14a-9a3a3d373f92",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3149c746-3c1f-55d3-b300-65bfcc879f7a",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd809e85-b02a-5669-927e-a39693095424",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afa41b5f-2c59-5df0-bcfb-7806830a95f1",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f73d8078-c2be-5378-83ab-e259260bfc55",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57190960-b1be-5b0a-a272-fcf58d88d2ca",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d94c0556-0735-5fde-be1c-11ce6cb318d1",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f37b1e8-09b4-5984-a816-0f309c1ba033",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6621d35-ea82-5cbe-b0e8-4e0b262a88ad",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9539e3ae-f0c1-50ce-8a3c-baee648c5b42",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8dcde3e1-ae9e-5690-b8dd-1b19b1a65b72",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7177186f-6045-5043-9cb3-6087ee98849a",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c56d3687-ee1f-5f6a-8908-6bd5fab45c12",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52977194-077c-5a92-b1c8-a63989694df1",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3c1b045-b049-5a1d-ac6b-383e9b9c238b",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82fe4445-11d5-599f-b77e-409ded27b2c6",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81239259-4848-52c0-b669-577548278f5c",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:649c71d3-9ff2-5df4-8c10-112320ef42a5",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6eecd73e-e21d-5fed-a929-fdccb400201d",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95456336-69b0-50c9-8d35-713e6a396450",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9080e1ae-ce28-5f51-aa38-67137dec9aac",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48988 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46e807ae-2519-5601-bece-6d6e7cdedeb5",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0187eac1-46dd-50de-9fd6-be0b88c1505b",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7840901-b1ef-562f-9cad-6f9c2dd5cca2",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7361d363-a126-538f-b727-69cebd888505",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a6b6305-c0eb-5f29-b36a-4b285b428e3a",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52520 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca92f2e5-59f5-547f-8109-56b3ef20918f",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e64c2a9f-2d67-5ff1-abc6-703567606426",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42e4a634-4709-5b28-9ec9-337cb77b7ee6",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d18b3413-25a1-5aaf-841e-27245f719029",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49d7b4b6-2110-5151-b906-ae22e46c9161",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22a8e920-0e67-541a-ba8e-3c024f6d474c",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:489b575d-a54a-514d-96be-38491262a446",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93636d3d-7b85-57e6-86ab-b2e53e4bac25",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6c0f02e-26f5-5d07-b4a2-1cbe4912ca28",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c82ff18f-042d-56ff-98c8-973ad76ea41b",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1791a5f8-71c3-5111-bafb-d74532903689",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9648b04c-38ad-5cfa-b694-48b0b2a0553c",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5a1b8c8-bb5c-5ac0-a4bf-4512eb9e605f",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86f0b454-0d7d-52f9-8594-d8bd49115f73",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f63e431-9a44-53e3-876e-f9d148e1305b",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.2"
    }
  ]
}