{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ad665f4c-5c97-5bd7-8b19-25cae91cf8e5",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.4",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-util",
      "version": "9.0.100-tuxcare.4",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:bab44cfa-55f1-556b-a4f2-a8fa6728a2fa",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de685d5f-97b5-564c-98bd-5a4db8c0b6e7",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db004b9e-3c13-56c7-b763-3f39ab00a598",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ba10d77-113a-5fd9-b088-ade77da32038",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02818d4d-0aeb-540e-b0e9-526b17b11051",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9781016b-8dda-550b-868b-39ab1990a6e7",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd1265d2-d510-5e7b-96cb-fe2a4d30b780",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e082c22-083a-52d1-8b77-b27cdff33ee9",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:670b64ba-b98f-5267-bd1c-5e25f42e3180",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:571650c4-ce21-50d6-bd9a-7b971ebb9460",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c008b78-3e88-5247-8a91-5870c602d459",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52316 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3cebb5bc-f923-5443-991a-d2c201c4a542",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:747cfc21-7c17-54d2-9121-42b26daf2e68",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf7f9bde-5fcb-5938-80bd-ab765a5490d7",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9e2917d-22a4-50dc-8c89-0c4b7320bc0c",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ffb67891-32ac-50ab-ba0b-cdc1de2d9c6b",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19193aa3-c8be-5888-a162-bf5a8b23918a",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eee85c4d-3b54-50b1-a704-87c854b19b17",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d090d58-ce94-597c-a1d6-2216b6ada285",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39dd5938-f34b-5ee5-ba40-54ea3dd80996",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2424abed-18a8-5dad-866c-abdf7cfccd1c",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9399f181-6d1b-55fe-b357-db7d890abaab",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21cc1778-83b5-56b6-adc9-1c5d4b365088",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55752 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4df39b8f-d1fb-5777-a184-d11ebc18a7c2",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f216a48-e3c1-5e25-b98f-9eecb537a7fe",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:422cb5d5-dc9f-59e9-8f45-2cb0ed5de742",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9041a5a-3cd4-52e1-aa63-fa590355f555",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4cf75599-7291-5353-83e5-759bb7dc1754",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4eb3a84c-ac23-58c6-867c-40b028f26c00",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:367ec784-e283-58fa-83a7-2cdca7ca7d76",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d959946f-7696-53cd-98eb-53c7778a41c2",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1c31f27-0ceb-5871-a3d1-fdafb5de0db9",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e75e5b62-af55-5ad1-998c-564bd68d41f8",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73aad010-b320-5e9f-b27f-81cd83df949b",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20339bd1-2b7a-502f-8ab7-d99da435010d",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c43930ce-fbf3-5251-b825-e2bbda80370c",
      "id": "CVE-2026-34500",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34500 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.100-tuxcare.4"
    }
  ]
}