{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:82139790-4698-5c14-b910-1057549d727b",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-el-api",
      "version": "9.0.87-tuxcare.5",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:5e4d105c-3fa7-5be0-8ae0-b4b2a80b98f9",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9af4563f-b9a4-5625-8178-6843f679a474",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c15c743-2412-516d-bc2e-5f118233abc1",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2104b3a-aa9c-5e9a-91e2-c9e61bbd053e",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80d9522d-eab4-5141-961c-842a56f7a560",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f362fa67-8682-5832-97d9-676c5d44be2f",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f886833f-6f29-5d86-8ae3-d8b89b5b465b",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04e8e325-a2e4-5ec3-9da2-14a441d750bb",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06bad17e-af22-5ee0-8283-0b232e5a7a66",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86864567-fbd9-5ff0-8a19-51a926a780c5",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cec6299c-f61c-5654-aee0-326efab37498",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:981e9233-7121-5576-89a3-1feb6653464a",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbb3b043-bbb6-528b-8c5e-31b2c6cbaa1d",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a6c70f1-585e-5c1d-96b0-7ad0b4f7c8a3",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff73df91-06b0-51d4-a98f-c523f2433c85",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27f6cff2-8b35-5f2b-837d-28a3f94986c1",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:419c5983-ba16-511c-9f9e-63e941ba7924",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc28d5c2-6a16-562b-b368-671af2117e40",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe92bba4-72a8-55ec-9213-1479c1f1c2a9",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4421a2c-9be7-5600-bfe8-0c94fcdc74db",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79157b8d-ad13-5c2f-892c-d56b57dd025a",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3798b97f-3898-5289-81e2-057ae03fe184",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67e7405a-9ebf-5dd6-bfe1-c5a5ce390299",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78133004-4c79-5a41-89e9-44ea641bca70",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a86c1e3c-b515-524c-95f3-053a1db8a1b0",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:128f433f-4aca-57fc-a797-b1bd5e9ac759",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52520 affects version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf1cb9b1-2015-54a8-b4c9-2d54e1eeb6a8",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ab3fc59-5c03-511c-ab1f-89038381c543",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b384c145-bff3-565b-8392-7530a6b4a97c",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55752 is fixed in version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:947dfd74-8bb4-5d02-a4f1-137fd9c685a1",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23e0c6bc-eeb9-5f40-a5ce-cba230c60da1",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1092712-40f6-56ea-8a64-02bc27ab61db",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8108f913-18fd-56f3-a912-d4fe9ab18b03",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9036d7f9-90e1-508c-ac58-bf298c73ed72",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d172dc8-c9e8-5761-9044-78beeb03fa8a",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:696500fc-90d3-59ad-8174-351a03df4b80",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b8af346-1c9b-5a45-a96b-55a3f0df9a75",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8cd595b1-ad52-5de1-af0a-525136eee58d",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3922db09-7fe5-5e69-b4c0-590f22c143f6",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1288cb0f-1060-5793-937c-5eea187a48e9",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d866c5f-56cf-5086-88d2-91674cb75e5b",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.87-tuxcare.5"
    }
  ]
}