{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:073d7ab0-72ba-5582-94c1-b5a50f83a415",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.3",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-i18n-fr",
      "version": "9.0.90-tuxcare.3",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:935a2c12-28aa-57d3-b42e-fc731c906695",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3afe9c0b-acdc-505a-9784-6c84a0b3651c",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d51c73d8-be7e-59d8-b2f4-29a34357610a",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-fr. Fix for CVE-202-13943 for this version has been already backported by the original developers, so brunch 9.0.90 is not vulnerable"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b610455-7876-5ba9-a38a-4b4b5919bad6",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:355b0087-df43-5910-9056-e574f0951dfc",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6c59eb7-e86e-57d7-943f-3a3b69b48f5e",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14e1f0f1-beda-5d21-bb8e-9c97a533869c",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e45e82b1-f796-5235-96c3-8a0c8ea2824f",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8fd0461-6f1d-5c38-95c6-342e14595bbe",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d51f86d0-cbf1-5a6c-816a-ded19b6de25e",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9872d8c9-2294-5b62-b8b9-2844cd32bfba",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34dac195-3e4f-5244-bf48-604f4b834ca1",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67e015e6-9f34-51b7-9bd1-5ce6834767cb",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9f3b327-2d89-5a20-8790-0032dfa80a5c",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f1dc67f-dfeb-50fc-8156-2f4434b4509b",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0256bd3f-555e-5e62-95ad-f51fa5b713b3",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:422e8ab5-a66c-5235-8849-11f3193c4716",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31651 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0cb3a46-8358-5363-afb7-21351fe28343",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94755c83-7b58-5059-a6e4-d00d0d5a1633",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:337a8495-0f24-5c29-8e05-0174fc5970c4",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd9cf950-32ea-55d7-a3e1-f0c83219a9b3",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71935f66-12b0-583d-a882-061a2b963eeb",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-49125 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:811609bb-5fa9-5a6a-bd9b-65d226608f65",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36f34ca7-7bb9-5617-991b-e5df283d40ff",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93eade0c-dfcb-5e6a-99a8-c3eeb21d38b2",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0bd5168a-39ea-5911-a22e-9f333ccaba65",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:561d38bf-bf40-5f7d-9e0b-821b3b763427",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1e7be0e-aaf5-5218-91df-805c8452b01a",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24294fff-8d5c-558f-8aeb-9e2c605a1391",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3995cc2d-f621-5306-b39a-c89786b06346",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72372746-f660-5906-9419-1a3152b22e0d",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d7395fb-966f-5d47-a53a-a836e99df59a",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ab2336f-72f4-5521-8820-4da9dfb33ac2",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7451209a-0374-5135-8471-7f59c1b99940",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8005b5a-b71e-5d46-8bc9-213424bc1af2",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcb0e05d-2d8a-565d-b39e-d0a8f1077306",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:140de275-7da1-55f8-9cae-286b97fd3764",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9b88f67-505a-5265-b809-ffec7202ddd3",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba118bb2-ab38-5ec9-b1d6-b348ba6caee8",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.3"
    }
  ]
}