{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d9d75654-4869-50d6-a9c3-6ecf3dcb0793",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.4",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-api",
      "version": "9.0.90-tuxcare.4",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:4af6116e-6bac-5367-88d4-d6d78eea4e50",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8038d636-894e-57f6-a506-f66614892ffa",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bb0e090-d698-53cc-b46a-fa701ca73d8e",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-api. Fix for CVE-202-13943 for this version has been already backported by the original developers, so brunch 9.0.90 is not vulnerable"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f0c5116-659b-5dba-b0c4-1900438f8387",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e177620-5768-53d5-b14a-e045b3f11c59",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:656824cc-e5a2-54e4-9fa7-2306f027a358",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0888560-a2f6-5da5-9271-fbca4868f740",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c46cbca-a904-526e-841d-7b98ae5fff49",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ae154cf-2e66-5589-bdbe-318d4512fd50",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61af20fb-d9cc-5361-aef8-c5069b6e7fdc",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99dc41de-e423-5910-b625-345e91d0f010",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f111434-3f47-5a2d-ad8c-39004bef3ecd",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98151ab1-5246-5ac7-bb84-1c146d514ae8",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f12a0821-f980-5e26-9d95-4ba82e563ffb",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52426db4-1766-5d64-bb8f-4f3c56197c0c",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e373ca9d-7ffb-52d0-9a15-0fa148988506",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8baf830-bb49-5cd6-bc80-80735437ab2d",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31651 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b4fa6db-2da0-59d9-ae14-07223db1fa87",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8575102f-dadf-51e6-b8c0-4c216921a82b",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e53f0ce8-3a08-50ca-b549-4c8e737524cc",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf1047b8-fdf1-5cde-8148-d2fb11d4e30c",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7377d65e-f8c4-5126-9f1c-c85e20150708",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-49125 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c52f144-5c01-53f7-94e9-2685f6d536bb",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfe8281e-4190-5267-a477-efc5b19ad065",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c76d7b00-2dd7-5051-b1d4-0548c389f16a",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bdf76cf-4c2e-5f0e-b5cb-c1f34253576d",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32b5a3d6-ebd7-55ec-83d6-a8c7a1cd33e8",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a4b6798-e102-5e23-8f0e-ba37db818700",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea03abef-6f5e-5574-a8e3-c86055916fc0",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42a4b7c7-baa4-51e8-a5ba-7f4a4800d271",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b03f5bb2-0e1e-5eb7-9f0c-c5c32016d1ce",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45bc27f3-175a-5cf7-ab18-673e5eb1c174",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6afb9bc-f4c5-57dd-bfc8-b2429a95ccfc",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f06c9564-dd2c-55fc-9def-3cf0d645ae2e",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:513ff6a1-085f-52f4-8905-f5b1f4d2018e",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1234732-937a-50cd-9bb0-86ee03200aeb",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1148075f-2d84-5d31-bcd5-0297241ac35a",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dca39670-3ac7-5db4-9c0a-b4ca85803e82",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e83968a-c3c7-593e-ad3e-687b60fa1b08",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-api@9.0.90-tuxcare.4"
    }
  ]
}