{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ee6e5c54-2147-516b-a119-2a1629bf1fd2",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-i18n-zh-CN",
      "version": "9.0.87-tuxcare.4",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:1ef61489-cd79-5823-897e-d3d7b9554124",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9d97de0-d2f4-5844-90cc-29a4e034b4c9",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d357056-3596-5cd7-b065-ef702f2add0e",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a6d6e60-9b61-5e67-b7ae-380df31295ca",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3b7ed2f-56c2-5db4-b1ef-e9ccf54be3ac",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b0c6fa3-955b-5f92-96d5-29b5d2385850",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d4213c5-80eb-56ef-99ea-96cb385a1de2",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5553ea5-a1e4-59f1-9de0-bcb3b59907c8",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff0cb316-8f89-5511-a4fd-8abc6b01734c",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97b24a7a-7a05-58cc-abb2-5c715392e79f",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef01b5c6-50da-5ca3-b2fe-be3dc46ce375",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b398a25c-9054-502b-bded-30a932fc91ae",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5801061-2b20-5575-8d64-daadee034a3d",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c32c77f-065b-5c25-a0d8-94840187bc17",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a57bd5b6-9d49-57a0-be73-797b268c4eb5",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c3e20ac-ee37-5085-981b-58221317ca65",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a5c5c79-99fc-57ad-bb32-9afe6a0852f3",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90cfb64b-c5c4-5e7d-b832-4f0f73abea50",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7848f93-ddce-57f6-ba68-77957b02b8c3",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44069dbf-6954-56c9-9204-79e17aea7e02",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d930924e-6f36-5bd6-a501-a23cbda90572",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48988 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4caf555-30b0-585f-a643-49f98de4c089",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbdbfceb-31e7-55e9-811a-4980d4fa11bf",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:939ab94a-3d76-5964-9c20-de0a935177b7",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2dd5c958-b0a1-5332-8f8a-19400a75f474",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3400505-d440-55a9-b04c-9b94b45c5f97",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52520 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ed9e8ad-e46a-509b-80b3-f6df4715e1f2",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d78b0d87-1ada-59f4-8cf0-931abfdebcee",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a794c730-d611-52f0-bfe9-5011460f9dd0",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55752 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbe2efc8-167c-5985-995d-6376d8ec1183",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab7a5b2a-ffad-5f48-b47f-34dc026ee3cf",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3536e28e-cceb-5948-ad2f-f06698c243d3",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d5210f2-d61c-558e-bb31-f4b80d4a604b",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbbe4067-513b-5beb-950c-db8926360f2f",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69d2859c-a2df-5c02-a99d-eb3d465aa1fd",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00a405f8-0d4e-5152-be83-3d0e4e9d39cb",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d715ba13-a3f7-554d-8e85-884fe04e8c37",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78959086-7e0c-5968-9834-a18cee818671",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8c2d2d9-e3c0-55aa-ac8e-0d747877a89e",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dda9eeee-fe8e-5bc9-8c8a-ea37d0926119",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3af33894-0969-5917-aaf4-382a6b247c5d",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.87-tuxcare.4 of org.apache.tomcat:tomcat-i18n-zh-CN."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-zh-CN@9.0.87-tuxcare.4"
    }
  ]
}