{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:21378add-7163-5e5a-ac94-d3c7486c4371",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-util",
      "version": "9.0.87-tuxcare.5",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:3da274c1-300e-5a4a-bfa2-0144f1c1d708",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5bd3f7d1-31b6-55b7-9c82-1cd4c094b09d",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44db9dca-9614-51d2-9a66-c50a0f02108f",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ffbb031f-145b-5830-8390-e6b548fd71a7",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12b7fdce-88cb-514d-acc4-23769c92a0c2",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93f8db9d-db8f-521e-8f93-cac71e0ddbb0",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ab6be43-9a7e-5250-8b97-a66fa0c6018f",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e0d27dd-7ee6-53e7-ba2a-b4dc95c7fc6d",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:818397cc-a070-52e6-b6d3-05ba29b2ab19",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c11f5b7b-9f22-5fe9-aacf-99dea59b80ff",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7387422-e9c0-5584-98bf-cef61c4bed9f",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9777e6da-431e-5fde-b006-5bb8c2ce3ca3",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:933bc964-5612-5ae0-8718-497b7e419b05",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5fea1e7-0e38-56fb-9864-0f9f785e0f60",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4feef82-073f-5121-b4c3-b603ac13df0e",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a244d08d-27be-5070-9aa7-c7e958ab97a5",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bff9aaf7-1aec-5869-b305-6bbdadf535a7",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c279f408-7da3-528c-9e0f-eb6ddbbadd65",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7f67807-94ba-5c19-a6fe-83161195c165",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d987aff3-c3ec-5b85-89af-7a8bb40cbcd7",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a6df9c6-15c3-5d28-a72f-83c1709b3341",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f81ed49d-9ec5-5f90-83a4-0f865b57faa5",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73b9c63b-88b4-5a30-9a18-47d32f6c133f",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3e5384a-c622-5281-8643-fef20e5ff4d6",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb4d843c-d917-52b3-ad57-9f7e4b96617b",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b5f4302-e1f3-5614-856a-6a6c25ec4b1e",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52520 affects version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80728899-675f-5504-bf46-61e729fe695e",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a252b01-2a12-5bc3-aa6d-443a40075625",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a090161e-70e8-548f-86f2-b00310823a7e",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55752 is fixed in version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c01890f-a620-5edb-9343-bbb8dd9dd5e8",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0644a6d7-274a-5f1d-b79d-108f3be1f95b",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c1ab1b0-5f4f-58b0-8091-f9ce8d667a61",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fa9a182-1f21-5505-ac50-59428de21d61",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4296d5ee-88e3-58e2-914d-3d7519a7de7f",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e87c7c58-ec23-5151-94ba-56c2b07d8c07",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87075f3a-e95f-564d-bedf-8750fb3ff555",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1056b8d4-b793-5a8c-9802-7f30156da5a5",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40ba3e22-173d-5d6a-890c-05920ea82841",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31fc2351-ccb0-51c6-8c45-542a4fc2f1a3",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:742780f7-147c-5275-a1bd-526508904fc6",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa185998-b9ab-5d20-b043-63e3e6d928a2",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.87-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.87-tuxcare.5"
    }
  ]
}