{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:5320cee2-d27c-51b4-ac41-d81dcf23a40f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.5",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-i18n-fr",
      "version": "9.0.90-tuxcare.5",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:15e02c43-ce76-5450-976c-d102d5d7c5fc",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29a7f0d4-3144-52c8-ba07-7564935b6fa0",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:394b55e4-9448-5bd2-98e3-156ae07a9fbd",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-i18n-fr. Fix for CVE-202-13943 for this version has been already backported by the original developers, so brunch 9.0.90 is not vulnerable"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f858604-36b4-58af-846a-c107e01cd298",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2c7da14-bf8a-5c3b-84e1-ecb31eae25c2",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ae7ce55-ce19-5781-88b5-78969aec7b75",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f84d3a8-1a12-5540-bb31-f7c8abe8b56c",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e87b3145-7ad6-5365-ab31-20a3b966164b",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d75bc364-040d-5551-a655-0b46e280ef3c",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3405df1-f191-59c5-a976-e1a1196347df",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f924d3e-a270-5a60-95a1-5010c21d3280",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9de9c5fc-307f-5b59-8fb4-b9fc238e9670",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26763056-fc44-5109-bb96-f71ac961678b",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a17990e7-a13c-53e4-a71e-ed1251a74f26",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3781ff26-acec-5957-927d-3d36ccff576e",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30b02ff7-56c3-51dd-b811-48ff6ec512d3",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efdc272a-a87c-58d0-bc2e-67431222723c",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31651 affects version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2dd184a8-4907-5aff-bd57-5e654a8f1d28",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4c0cecd-876f-56e0-876f-3e5031ec362e",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9aab535-82f5-5a36-8e1c-819adf46fcbd",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f69c2760-2266-57d2-b735-d5a475f0a725",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de04fba6-9c50-5bc3-95d0-506f8ddf54be",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-49125 affects version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b411628-dbd9-5845-a198-bf767d37c9c0",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81b11ce9-3626-5a8e-a6eb-d407b73c4725",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1c36976-598d-5d8e-a868-3f10d8b483d8",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e8ef169-caa9-53ca-894c-df2a6891154b",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65599f41-5930-5962-bcdd-558effcac8bf",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96c89d1c-2813-588e-a22a-b73460bcfe4e",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c00fc5d-3fd7-507e-b090-8d1f6c7d6424",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0731cd6-e32b-5964-bf40-28f324b8a8b7",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07c43197-f9b4-5e30-bb9d-4bbbd29ff0b5",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae0e28f3-b454-56f3-be5e-0f4b631b3870",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4319978-5944-5a78-bf97-2a6c544d65a4",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b784e168-349d-56de-91de-912eef67e49f",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b11c417d-6af4-5810-bf27-547cf32825ce",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09b02e5a-1128-5b42-92f2-96d7d885b625",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9998db85-1220-5232-a56d-5c613c206781",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efa42d63-7836-5b15-ad88-aa336fdbc501",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c632111d-daab-5f10-a1b3-ac72ee8e6a35",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-i18n-fr."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-fr@9.0.90-tuxcare.5"
    }
  ]
}