{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:6c8d3c1f-21f0-5cc4-b3f7-10d4ed562bf1",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.100-tuxcare.1",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-servlet-api",
      "version": "9.0.100-tuxcare.1",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.100-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:af35aeec-d0a6-59df-8d09-279510d2455b",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e5c87d5-80e8-5964-866b-186fd1ceeef2",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af1dc1ca-0000-5f49-b892-8c127469b7ed",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2957f452-2e01-5961-9e8d-6b6d56d5aef2",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c062915b-2aff-562b-bdf9-33cb54262caf",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9ca7416-a4c4-5ea1-83d9-efdb394760f3",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4222988-a386-5069-bec8-1e8ae06f27e7",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7206eae6-db73-59b7-9a74-e06131f74e23",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91792f0b-cf11-54ed-9c3a-451a93d69e8f",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a972fcc-c52b-54e8-a1e5-25a49b6e098d",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1a7a82b-20c5-5802-b628-05c5b2a2bc44",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52316 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aab6fd1b-3576-5584-a5b2-40eb119ef0b0",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a874af45-7fff-5682-8e8c-db3666f6e49c",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:acabc0f0-6b14-5e4b-88b8-8e0be029b46d",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6456b484-5be1-5eb6-9aa8-55e86df45f3b",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48988 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b0d4a59-b6cc-5f62-b27f-1671ad4acd31",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58f3d262-b647-5abc-882f-99f4977816d6",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:899bee8c-3322-5338-bb5a-1a1b5fdf3f59",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7636fd42-6b17-5ac0-90c0-1a3270044b0d",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d118c9e-f39f-5eee-91fa-1ccb6e131e43",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e468f045-520d-52e3-8988-e412e2f5ae82",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ae74d43-ef95-537a-805c-eea4bc0d3c21",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27a95940-4d6b-50cd-8ddb-66420f0e8675",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:730cde32-2da0-5c5e-bebf-16d883b5d089",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:857d8811-df3e-5cc8-92ca-4a307f1a9c93",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:acb1128d-ba6b-5e1d-9d4e-e613bbea62d1",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9cad55bd-5c53-5296-93ad-a11ab10daf6b",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54f3c66c-161e-55e0-b579-9aae4bbe4eb2",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4d08a8f-a72b-52bf-889e-69b300e679b6",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0534c42-5eb0-5bbe-89dd-70700859f41f",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:832fb7c5-bb94-57f4-a423-17001db5ac1e",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85ef6f6c-bf1c-567b-9fb0-9521ebc31bcc",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88d3a3d8-165a-5f17-a746-89dded025600",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03ec4ff2-d26c-5f2a-a7f2-c780e9d2eaa2",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6d04eb6-901c-585e-9259-659711b9396c",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f299d9bf-ab16-5853-8348-6eeea76d29cb",
      "id": "CVE-2026-34500",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34500 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.100-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.100-tuxcare.1"
    }
  ]
}