{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:90f48c05-0f69-5f6e-aa61-f6992e1dc401",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.6",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-el-api",
      "version": "9.0.90-tuxcare.6",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:c80eb3c3-8fc0-58e6-a431-6cbd1557824c",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17787a15-3b51-58e1-8bcc-e99a677cb49b",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7da65f3-e382-59b7-bc0a-96d56a868e33",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-el-api. Fix for CVE-202-13943 for this version has been already backported by the original developers, so brunch 9.0.90 is not vulnerable"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8145cf24-1294-5d94-8962-746f795e6918",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c63c44f6-989d-539d-b4b9-738c88cc61b5",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ae584ab-23b9-5b5a-bbc9-4e3713596193",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d70724ae-032d-524a-b3b1-57cd1105e0f8",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ceb68f3e-01f2-5e85-bb39-7ae79531b1ea",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d02c7bf-d55d-5534-b592-8a0da4e76b6a",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc1501c8-6f08-5ce0-9dc5-6e2db388fa05",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66d9c39e-3857-5281-8ac5-5cf53c8d19e7",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9df28c25-7b77-51ff-9bb6-f0fc962810e8",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e42fc25-f600-50c9-9eec-04ae3cc236c7",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:556c2029-f5c5-5861-aba7-4c51cde52b17",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ce9b2fb-5d3c-58f9-b822-fbbde705a8c7",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9debe2cb-47da-5edf-8efe-21bee0d0f7b5",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12b5d056-499f-5461-8f60-e5358d1361f7",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31651 affects version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66b33b23-916c-584a-8f12-aa31de5ec394",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d30fb1a8-a2d3-523e-8986-4be7139c3ab2",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8616eded-382c-5fc3-b904-a9023843042f",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61853c6c-8764-575f-a4ee-b3d02e335514",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4cd09e68-58b0-5459-90a6-78a5c24d3e44",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-49125 affects version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c03f0e9-dd59-58c2-bd0c-fb08e802ee9f",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac370463-cf16-561a-bba1-542d7eb207ac",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7c77b3a-0899-55d2-99ef-88c15dbb4c64",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86b421d6-2805-5439-9a3d-029a9ea6028e",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1e3ef02-1ad5-5eae-93f7-5e4a14c72e0a",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f38dff7-a0ce-52f8-96c5-defb0dc571c9",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14f4b96e-6b20-520f-9b47-3ba69768d16d",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2962c30-9d94-5bb2-b25e-484ad3fc43e5",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:faa3fd3a-5620-5cd2-bd20-548875658a76",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af44e1f9-513f-55a4-8d01-90f4dcc46b0d",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb161525-598c-522a-8a99-f963d7662cb1",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd36fc37-f56d-597f-8b2d-a2fb10597b8f",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3d0caeb-7989-59e8-8ec5-d7baf5c8733f",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5bf48da8-a14f-5cff-be05-2a9573ad18a7",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5374b2f6-20e3-5b21-9bcf-b76cf6b30053",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca2ae473-3210-53db-9f75-6841b25758bf",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34483 is fixed in version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd77533d-e0d0-5904-aeb5-522ff318a924",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.6"
    }
  ]
}