{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:fe6f79b3-9338-5852-a778-0c9eecea380c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-el-api",
      "version": "9.0.87-tuxcare.3",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:fee43170-3df9-5299-9806-01cb7addcd5f",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd91b1ba-42d3-5436-8c33-a5cb3f156a12",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:addd0805-bad1-5c60-b8f9-cfc1937e71a5",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:449b1d95-ea0c-5931-9736-be3c937f73b5",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea1e33fe-269b-50dd-a883-144c2fd59a9b",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e52ddaec-63a6-51a3-adae-502b3e2e71c3",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41a54b46-6ce5-5a6b-a480-09f11590d924",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:923a463e-a168-5f44-a49a-f2c101253aa0",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15c7e5ab-6274-569b-8fb3-6a7623f41972",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4efaba2f-745c-5ba0-9873-ea9a33ef6274",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0822c88d-20d7-56ba-87f9-15a92aeaaee7",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4d561de-1431-5637-9393-df413ed8b012",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8771676-40d2-55ba-9980-fa81b0d430a3",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36f5fedb-363e-58a9-9cd2-577d705e41b2",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67a6d3de-2188-5c35-8c6d-d323b7f1a533",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:881b89d6-f624-5d83-9168-6eacd30ac4d2",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e21e4139-45eb-5580-a73a-b919248b5eb2",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb72cec7-7c23-5c58-a221-d80314a5fb61",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9a4fb8c-5ece-5e69-b44f-dc428706dc35",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f5512c8-4c30-5aae-8eb0-3643031aa15e",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be31a937-059f-579d-9db9-2587ef06f34b",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48988 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c592bc6-6f73-5d0b-b56b-461440d7d9c0",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f072deb3-4921-5696-a315-5040cd67071c",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af0fc2eb-17f8-5cfc-b892-b2861ca7cfeb",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21ad6884-09b0-501b-957d-c4ad3a0ac0f0",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12b2275b-3673-5a6c-9e2e-a2c53993c72f",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52520 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c7bc9b5-f42e-5128-acde-f24a3ac2588e",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d8ae8fc-3e12-57ae-a655-8015ea3fb97e",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf5db6ef-4193-5ee4-aba3-c45e23fc16b4",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55752 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e19ed8f0-2179-5c1a-ac21-6646cd1a217c",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23f2d850-6f77-5c0b-96ef-c66a616570c7",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55137a04-c7f4-54da-ac24-ea38fd4c95c7",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26ba20e1-68ad-5de0-8283-77734e2c4f2b",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a925a44-1c41-5403-a275-8f7206ec0204",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d2e8d62-8da4-5a65-b283-234021ee0078",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a512ca4-9eb9-54f9-997b-1b6803512f2b",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f2b223d-389d-58e1-bb0c-d3536230f1f6",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7ba4e3b-57de-54b3-aa63-4ef1eb3c4942",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30047938-9090-50e3-be34-f6576d16ec07",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49c8a0b0-7abe-531c-af26-9cc7919f818f",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1e16bc7-acc3-505a-98aa-59005b2eafed",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.3"
    }
  ]
}