{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:459b1e4b-fe41-57d7-bd4c-0a63ff671f19",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ko@9.0.90-tuxcare.3",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-i18n-ko",
      "version": "9.0.90-tuxcare.3",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-i18n-ko@9.0.90-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:4de34a0f-47ca-5cae-8638-d4a2d50c4743",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-ko."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ko@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51a15d72-66fc-564e-97cc-676a9fef8091",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-ko."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ko@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89c51b11-0de4-51bd-8858-e24619034965",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-ko. Fix for CVE-202-13943 for this version has been already backported by the original developers, so brunch 9.0.90 is not vulnerable"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ko@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8f4ba68-ba2e-5221-a7ae-f0f7a5ef3626",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-ko."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ko@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f42bcbb6-c778-598c-928d-e8dbf1c0363d",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-ko."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ko@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfb2f6c3-520d-5ca4-a3fb-73242c23fdb0",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-ko."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ko@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce5858b6-9ed0-51ee-89e4-4b975ddce31d",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-ko."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ko@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c802dfb8-82fd-5ccd-b3aa-fb9b95c4c4c8",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-ko."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ko@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:990423e8-0fa0-530a-8164-492671425e4a",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-ko."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ko@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc1e7e4a-92b2-5ed0-ab16-b11f33f5c0ca",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-ko."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ko@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42d3f1dc-669d-565e-bfe5-1d39c9435e2d",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-ko."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ko@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd794898-093e-51a0-b6e9-d509d5aa4be6",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-ko."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ko@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47c49ea1-5f34-56a6-9b39-f71c7c89ca24",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-ko."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ko@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93a4604c-a827-5bad-8c69-03bdb65c4112",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-ko."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ko@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2532e50b-defb-556a-be04-2d71ea858e71",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-ko."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ko@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e881c10-521c-58b0-9961-aa52bb56ac3e",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-ko."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ko@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:194994a3-973c-5789-8bb8-023c965774a9",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31651 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-ko."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ko@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0bd6d676-0aa4-5cc5-9ebd-8608fa189086",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-ko."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ko@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f729f9b6-423c-5ab1-aac4-f54af2989958",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-ko."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ko@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63555fc1-4a98-5f93-b45f-d0a11c198cf2",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-ko."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ko@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65e7a89e-5514-516b-bc73-dcce1eca7557",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-ko."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ko@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eee54a82-5314-5b28-a91c-fba3088126c2",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-49125 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-ko."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ko@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d78d0097-9e8d-5663-9d91-efe09ca8627f",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-ko."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ko@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28457da0-9c3c-5f4a-8171-b0adf0502b89",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-ko."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ko@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdc0603b-8c44-5a01-b925-275480944b34",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-ko."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ko@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fb52d23-200e-5d9d-b59c-d189d32a1e52",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-ko."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ko@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b42fed66-bb4c-5665-9c7a-56b44c989e4b",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-ko."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ko@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28b31775-b87a-51ad-bcfb-1195a18c6d5b",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-ko."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ko@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36b5b1cd-d5fe-56a0-8aab-0ee0c524ce10",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-ko."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ko@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20134ffe-ed25-52ef-bb94-23f6f8d54ed2",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-ko."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ko@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bb544b6-ba2b-58e7-9c2f-9fe44bc447fb",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-ko."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ko@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbf7130b-59b3-5611-bd55-4b0907ec74b4",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-ko."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ko@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82ee2fd2-67dd-5b14-92ab-0af5d87c097f",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-ko."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ko@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b67c63da-dc03-540e-b99d-caa6746dfc73",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-ko."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ko@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91bf9e9b-c441-5747-8bfc-57c3ab0b1fe2",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-ko."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ko@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a38af65-b19e-5dea-8004-049978d56e61",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-ko."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ko@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27c61f34-2283-58a8-bbc8-bb44a5f191e9",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-ko."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ko@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e2b0410-6491-5535-a38e-c95dd9f7ffef",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-ko."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ko@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ba200e2-bd8d-5b45-917e-8418c344ef84",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-i18n-ko."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ko@9.0.90-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ko@9.0.90-tuxcare.3"
    }
  ]
}