{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4ffb7a78-8ef3-511a-94ba-b53d69d67bf1",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-util",
      "version": "9.0.87-tuxcare.1",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:47b3fbdf-8be2-5828-8637-b302638f6568",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df759c88-a244-5eff-833f-3a81832b284c",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23a74879-e5b5-50d7-8261-8fe3ac671c41",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc1af752-92c2-5917-9b04-f5fab4a310c9",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97c151b3-5c7a-5fe4-b2f0-94bf3222b677",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8c191f6-a2de-5bc9-ae1b-d3dd8eaa9944",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b302083c-f7a3-5065-999a-9de883a0752f",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fba31af0-f642-537b-a176-a24a8d7ff57a",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c50b4f1-f3d9-5920-bc42-5580b101401d",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88bb26c8-2cd8-5326-9930-a387a7ca58e7",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e9c46d3-9dfd-5a5b-91cb-8882eb2012c5",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72ae80b0-b399-50fc-ae77-aaef232b7e23",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff78a7e9-3f4c-5d02-981c-140a41ee08a4",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-50379 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e2d5076-7d99-5be3-a5e0-fee50943602e",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:951daed5-be8e-5692-a792-3577ea1d3c61",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19ae4c8e-6a2d-5a14-aedc-03f415d518b4",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56337 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fad90c6a-cc73-59f8-a211-36d85018e94f",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aac5127b-c11a-54ad-a60b-03d6ecf69cc3",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd9da734-ecd9-59f5-98d6-4a2e1f4866aa",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fdab830-6cd1-5d5f-9694-b0250d940f84",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e343e55f-189b-51b1-a9cb-b3fc20b007ce",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48988 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c872c0f-f4a3-558d-bc78-6c6300e4f588",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6617343b-b1f5-5ff1-812e-bc90abf85a22",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d10bb56-f7e5-5738-8edb-8310f95fef6e",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3724312-0857-5cb6-937a-6752a0fc3dbd",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ca6bed5-1fab-585d-b559-261391a16c80",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52520 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea644675-fd94-52e7-8d7e-86ddf350bb0a",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a529a083-9fdf-5cbd-8296-56dd7effdef7",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:400c6a6b-cb00-5846-be6d-42af7de76bf3",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:191c0f9e-9fe6-5262-b35c-511993ac9ece",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da81edc1-949c-5cc8-a398-24f15d7603f7",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:396d479b-c9cd-546a-8174-a5217e74d347",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4c4596a-5d06-5d3e-8032-36987e7fc8b5",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28b418cb-0651-5a19-802c-81eb56919ed9",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ae7bea9-c5eb-5f36-a2cd-af8e6dfec2b6",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87e37484-afd1-5383-adf5-3e7885c85303",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af7d9fb0-0cb3-5e71-bf10-d75e0f4b959c",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:046f760c-9d35-544b-9892-d0a86225c5e8",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5bb777b-63f8-55c9-b31f-d36c7fc82b30",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a35e54f-e034-5aac-a152-0ac35786c269",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a170b4b5-b61f-5542-b683-355c8ccacbb3",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.87-tuxcare.1 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.1"
    }
  ]
}