{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:7a1ac6b8-144a-59e4-a29e-aea015ceb3a4",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-api",
      "version": "9.0.87-tuxcare.4",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:647455fe-ad08-55f3-ad67-2f79f53a3fe9",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94049cbe-c683-5fdf-b1bf-fcaf78e61d9b",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7871f217-7635-54ce-a68b-7441e4c667d7",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1d41c2c-800c-5d6b-bd99-0f9c5b841ce5",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09f28301-3c12-5e3a-9234-aa29099acaf1",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f2b7e1a-c493-5c3e-ad78-e28a9321ce33",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5900b57c-afd9-59c0-87ab-75e4220b567c",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f573267-5858-5cc8-9d5c-66205f5ea157",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a9060db-e16d-50fb-aa61-51a60c56d38a",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:223b6f9f-6d2a-5ce6-a439-52c8add708de",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb784fe3-b6f4-5e17-aa90-3c4707fd0415",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ffb62fe-188c-5c49-8542-c0ea35f2cfb4",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ca817ee-0df1-508a-aa89-266e8229f2da",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56c90de7-3c12-5198-af94-0bc83907de14",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a24deb0c-9a2a-5d3f-a02d-9643f65c3c21",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79592375-8a76-5e4c-be3b-0d10cde45cae",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfa6c15f-3e8d-53b3-9337-f94c89cbf266",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a20a61ef-4fa8-5e01-bc37-a898394cda9c",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e216c79d-23d9-5b63-b586-bdc842a04597",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49b75042-2a01-5691-99e2-f769b4ffee08",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73780a70-cb80-585b-af14-0df3d4739584",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48988 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1e727a0-6de8-5c2e-a657-60a45b5dabec",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e7e8ae0-0cf1-5d5b-bb05-47e81d5b54e7",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:143e962c-c021-514d-8bc3-47f693970891",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55864195-4121-5fec-af6c-261650077824",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c923c93-b602-5a89-ae41-7cc322de8c06",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52520 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d79439a9-7d5b-5542-8c22-5dc0721b7e89",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:484d3e2e-223f-5281-8286-147c8f944a7d",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5383a1cf-953e-56f8-bb4a-507cd25e1d87",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55752 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6dd02a3a-fe12-545b-b9b4-a35fd771d174",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84d23b3e-fbb1-586b-81e3-5b1ed1d87012",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6ebdc2e-2ce6-593d-9619-2f72e4a90f31",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87ce16d9-7f07-5a63-82c1-a5f1b810229d",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b9f30fd-15e4-5fd0-a5b7-857fb2aa7f38",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12d146c8-90a1-5f23-9803-963d4d5aafa1",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a85dae5-4b3d-5b38-894d-fc88b403ff7c",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38a5647a-79c4-5197-96d2-cae97d8d685b",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:009bbc7f-4700-5d84-b7f1-c42608a63b14",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f348664c-6948-58db-a722-34cadbf3e7df",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e898254-bb05-5305-87e5-566545fb7e0a",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78d81029-a000-5147-9e77-b98e3aefacc1",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.87-tuxcare.4"
    }
  ]
}