{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b566df5d-d6ea-581e-97cd-f9e2b4007c1e",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.1",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-catalina-ha",
      "version": "9.0.100-tuxcare.1",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:3643aa71-a242-5041-ae02-bb061d4f600b",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab5a17e8-0e60-5cea-a229-1b3b5e05eac8",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b424342-a6f8-5ee2-8e9b-c91b2cd9ff9c",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78adc103-7ffa-580c-9158-8f7132df287a",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6e4718a-79b3-5990-995e-9022d9a621f8",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a172764f-72c6-5fe0-affa-bf2081310ae4",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc3d29b6-c7af-553a-9573-2674cbfd96a6",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74d3304d-a50d-544d-9858-15b355bbfcb9",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34d0b932-d967-546d-974f-894472e8273e",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efee4e87-84d0-54f9-8b62-bb191ef25923",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:419cb891-eb86-5af1-b895-14e8bdf8771b",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52316 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bd83914-34fa-5674-881b-db4f132cc314",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f48f11b-0739-5932-b80c-dc951012b35c",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90882dcf-ef2f-52e7-a990-966e494fe702",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1d41b20-0c2d-51bb-b980-a0269a250310",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48988 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36d960ba-653c-539c-8059-568447a2bae5",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:084b2cb5-33ff-5fdc-a322-a6a357e04c4d",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90fc1656-7807-56e1-8783-48a1d8cb6aaf",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad331973-0221-547c-be01-c6dd9bf11e9d",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a9fcf57-fe93-553e-bf75-bfafc100d066",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0f7679c-b6cb-5d37-9aee-6b8db2aeb698",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d2592c9-c81e-57b7-9329-c884771e64ce",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0db5dfb-9a3d-5386-9e7a-fa88a4c52e21",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d04f091-997f-5065-9ff1-07d560920004",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d69bfaba-9ae7-54f4-9f24-9be32a3adef5",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:224cd886-ba29-550c-a185-4bae2420ce6a",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a48dd802-1394-538b-859a-4e80b5c01ca5",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac780967-6fd9-5e1e-af39-e5b5d46d5478",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87c39f24-f4a5-5f07-9e43-6d80038b8d48",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b84c3ee-a126-505d-8f40-847a5bb912b4",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4429a0d-cb50-5bd7-821c-f2a99e9f50a5",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d795d75-61b4-50c7-bcc5-af3d5ab1c90a",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a0e99f1-9763-5bf7-a1e4-360c3fb2c416",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31be1703-af74-594a-aea3-8ecc83328e3e",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfded1b3-cb05-5a81-abd7-384cb7607810",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03b9e610-dd64-58c0-b0eb-3788bb22ee7d",
      "id": "CVE-2026-34500",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34500 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.1"
    }
  ]
}