{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:551c593b-beff-5f23-8228-aad062a57206",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.3",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-util",
      "version": "9.0.100-tuxcare.3",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:eafc319d-ecff-586d-82e9-c68e8273453e",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9af7d672-a96c-5149-950e-400a089059f5",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2e94369-4c44-5987-a64b-4946e2f07328",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fb33210-7760-54d1-87e1-48ca373e5fc9",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:846b139e-61f3-5a74-a6ee-4bae49beb9b4",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ff9bf90-d2e0-532e-94b4-bbb9d9680679",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04930e3b-4a88-51ab-8ecc-223077298279",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe456b30-9ce7-59ac-8830-05fd55b2bb98",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af619f80-f79b-59de-9443-cbc6508042d0",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3bbc2ac3-3605-57c2-a522-131f52d3349e",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:386fdd37-852f-5b05-a750-b0aa036e8233",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52316 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df677cdc-c685-50c1-949e-af28e0051596",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3731262e-18d8-5739-b8a7-0256dfefce1a",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f6ee3d7-cb39-5989-a496-e5b479834c90",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfba6b7a-9744-5f42-82ce-8d0e6950cb21",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a37039b-d347-5996-9dcc-4b5baa044d40",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2113683-1b88-5089-b897-585b636b6851",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d521971e-79f2-5416-ba94-231102e024a4",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:346dfd15-2f4d-55aa-9d9d-f982f3309653",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:702b2f47-1383-53a7-97b1-440015688271",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84178fbf-392a-550b-8994-bcda44fb9781",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a640ca75-4fbc-53d1-8d30-0bf31360ccad",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0140f5af-b8dc-5493-a3d0-640645d7887e",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55752 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18f2bc8a-d23b-5da1-803f-c143ca993caf",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:465815dd-5dcb-5fdf-a0cd-15159b9ed8e8",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdfd920b-8c11-5513-b351-6e48104f1541",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0b8799e-0557-5bf9-8173-133f05849794",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf1913da-c50b-55bd-a554-53ebf8268105",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ffb6948-3790-524a-8167-1d2a56d9e456",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e404bb63-1afa-5eb1-9eae-5cebf1314432",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4cfca316-b7f4-5226-84fe-cd36406de0bd",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2110d81-1008-5a94-9ea0-3548e356fdbf",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fb13e18-c5ad-5fd8-8321-8f6ee1925ca9",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f6e5e85-b94c-550a-b2cd-4b7774b788cf",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:096f5c4f-c2ec-559a-bb09-f68b0807de7b",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23486dd5-6cc2-5517-aaba-ea59ba7a384e",
      "id": "CVE-2026-34500",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34500 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.3"
    }
  ]
}