{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:29c4f3f5-d0ee-5dcd-a2b8-85c987a76700",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.3",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-el-api",
      "version": "9.0.90-tuxcare.3",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:12649b0f-97c2-5f9b-a5b6-11322c8fab6e",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f6c1da9-322f-5a05-ba4d-0e7fe516846c",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67ad4c3c-358b-58f9-a73e-b4386fe363b5",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-el-api. Fix for CVE-202-13943 for this version has been already backported by the original developers, so brunch 9.0.90 is not vulnerable"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:134f1a45-b627-535d-b75f-988ec65e1fcd",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb1c31ff-e255-5a3e-a879-ff58042c2732",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec1f5f10-b8a7-5393-8c5b-909701f179ed",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0d7cc9a-b4da-5dae-a387-70a1d4722998",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c834927-5548-5302-86f6-850569ea1387",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fca9c2b7-7285-52f7-b675-a6b539712355",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55a1281f-378a-5c3f-8dc5-0ca844723d2c",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb5ba2f9-27cf-55c7-8662-5da492358686",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbe47957-bc37-5c29-a12f-e6a279a7d816",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:087bf5bb-00bd-567f-959e-1bd6e8da524c",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c401524c-032a-569f-ac18-7d74aec53c6d",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:732a36f0-ed08-5aa1-b80e-32e029392322",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2821792e-ba6e-53ac-b3f2-c52b5df679b9",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c1e00c4-7b32-553a-b473-73a72b12a5c1",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31651 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:283e1271-6b3e-5eed-9a19-161f0c891100",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a4a43cd-add4-5cdf-9d0f-daa78c9fc4fe",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e5f2b8b-8c66-58f9-83f7-3b38bc9b4f8e",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83cfb761-bdda-5421-b046-c477702e44c0",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08f35547-6a49-50f2-9fd5-a3461a6ae86d",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-49125 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c04d1e2-cf7a-52ef-a027-b79f1b954d77",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e536507d-ee71-51ad-9e28-a2d6b078ca19",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:175d2724-af1a-5824-a2d5-759637530a41",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb357341-ccf1-520e-9df8-1e4c173a5916",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71d9f8fd-3502-5e8a-937e-77a265c46142",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b0754a4-24c2-5298-af1a-fdc87afd0c6f",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aaf3cdcc-15c9-5b11-a8fa-39d16cad54f0",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3c45a88-6c94-52d7-85fa-ea85189d703c",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6414b1e6-e60a-51ab-a5c2-d518f51ea19d",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:531c6705-5284-52a4-93db-a60e6c42ad60",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cde6a9c7-7bf6-52d1-9d52-c09c35b11354",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7d5e13b-634b-5153-b1cf-d3698b57d245",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12926cf3-2121-5450-b791-a1ae40656bdc",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:041751a2-e59f-542e-8b60-c6545dad54fd",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ad9ceb9-baae-5ddb-80c6-a97f1e03d35e",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6b90a1a-a50a-5834-83f7-1d96e4ab3a80",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:030e21ad-ac9c-54b9-ab71-0e403121d182",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.3"
    }
  ]
}