{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:34b339ab-faaa-5bb5-ac9d-d837f67ec56c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.1",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-api",
      "version": "9.0.90-tuxcare.1",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:3d0a6bb4-e63d-566e-901f-3977385848c9",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77ba031c-3970-5245-95a2-386deb751beb",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35b3cc1a-e73a-58ca-801d-fa7e539cfcbb",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat-api. Fix for CVE-202-13943 for this version has been already backported by the original developers, so brunch 9.0.90 is not vulnerable"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c07dd065-4c18-5874-b411-cf3a80877bc6",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9aac0ad-4137-5fe0-b3e5-33db88d6455f",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fc6bad3-9361-52f0-8669-c9c0ba74f8da",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46a4c31a-7bfd-52f4-b6be-841c031d03f4",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7706b354-8f79-5f5d-9e90-454745435c65",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b58f79c-2ec9-5c67-b57b-0cdf1df4002e",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12e70113-4ce1-53b4-a8d2-0fae4f53ccbe",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2be226f3-740b-5128-97c4-aecdd6a1bae2",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42b64f56-a84e-5500-93cc-67feb3599dcf",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7943b4b3-5f52-58f4-8a25-fd8fdbba2201",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6fbb8e4a-43e5-58dc-814b-0c10271719d4",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56337 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46634f5d-5f37-5982-9942-dede75343377",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99cbb118-8c6d-59dc-9095-ceba2da26f4b",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5b9f5b2-5bd7-52ce-b15a-f663e3ad3db8",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31651 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13c01c1f-3012-5a5b-af59-70f1fb75f3be",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-46701 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65f68e40-7a70-515c-b98d-b44cb6c7b144",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4650fc49-56d5-5157-8015-ddf212dbab38",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48989 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afeb6020-2b5a-507f-a007-577653fc77af",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5823dd3-0de1-5630-b6d1-45f6d63f02f6",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-49125 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f095b95b-e40a-557d-b21b-c9202ea4ebbc",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52434 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9dccf77d-59c6-5a6e-8902-c4c50cded52b",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dad4ad0d-6be0-5a17-af77-a6150b25fa69",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbb14a70-9976-5619-99b8-32f059171c4e",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36a8ebc3-2003-539c-b313-b1c065c5f96a",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9fdd7d4f-959e-53f2-aa18-ad0d1d23458f",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0849e469-4db0-5667-97de-957ddad1f82c",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05e2bb0c-50f1-52fa-b405-23de8a487e93",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41cb6676-a9d3-5441-857a-c78d29e56f8d",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4300787-fd23-5ff3-853f-be292f6c4592",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2f661fb-d8e8-58af-b067-e110f155e190",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8010f0f8-01f7-5558-a56c-8b0b31fe105b",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da32a3c6-c21f-5f85-a133-87f91dde425d",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fcaccc5-ac8f-5b82-8639-af6b8ddf80bf",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:270c47c1-596a-52bf-ac5a-60faea3c1199",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e44a6e0c-f7d9-5156-a198-99ecf413657b",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27fd5fd4-36b6-582a-b8f5-19eb87d5de13",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.1"
    }
  ]
}