{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f09f8491-aab2-54a0-966a-96304c88b0d1",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.3",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-util",
      "version": "9.0.90-tuxcare.3",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:ef5d796f-e7e3-5a5c-8ae8-34bfdc8d343c",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a0f4c09-0321-5d70-bdea-2ec5c5fc5e86",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f21b81e7-1915-5a4c-a717-6c7efbb25d98",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-util. Fix for CVE-202-13943 for this version has been already backported by the original developers, so brunch 9.0.90 is not vulnerable"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a47eeaa-e592-5182-93c8-eef6d28aab48",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ed0f1ee-cd7b-5ab1-8a35-d0f3bcf179b4",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d072b53-c5fa-5921-8841-93f04d9e402b",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:785d2318-a57f-52d7-ba4a-9d3e93c5d89d",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75860747-0c6e-5f7d-b88b-2781b62e9b8b",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23c7c9b4-0541-508e-b7a6-3a4d9d7c37cb",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81b4009b-2102-58e1-bca1-15f63cc9952b",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a920929-da61-5b9f-858d-0276c0e3ff42",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:914e0cbe-6f3f-5f6e-8991-8f4bb5c09df4",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:479b0f96-e4b1-5a5a-84e9-5d29f5518f2c",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b966266-e65a-5b6b-b7a8-16f3e38e9094",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1942fde4-9491-5c11-b042-7c005772dfb7",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe7a9d81-c3fe-5003-a811-009e00cb98f5",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d9affeb-02c7-59e3-a2b9-58cf545ffc06",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31651 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35a28358-2063-57e2-bdef-94a4f6c27c9f",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70de4272-d83b-5bc8-8208-8e5ba2d57cb3",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea4c7c94-33d3-5ef8-ad38-8bdceb7ed42d",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8280b7cc-616a-5de5-b15c-4c1cdd3c67b4",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf1d69b9-1c58-5594-a831-ac38c80d1869",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-49125 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5701c56a-084e-5027-aead-dd83d6913e07",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6089d2a5-63df-5cf2-8f5e-cbe8499f84d8",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c277e2b6-d4fc-50f8-b67f-6b4bc14912d9",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c424c36-4453-53d0-b7a3-e99bce70c7f0",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1547dab5-8a82-5f8f-af29-79f5b9301867",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40b7a3e6-34a9-521b-b17d-34b809fc4001",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98923606-1c34-5752-8d63-f43dbe209773",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be876639-66c3-553f-a490-5c02db3f677b",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5130a62-63b2-5551-bda8-b64d73a449e6",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d1ca18b-69f5-5f2e-bf05-4c0de93e5aab",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:652a44cf-0f06-5b67-85ee-e20f4af662f5",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f94dfb64-e3c0-503e-b4b8-1f7fca6b4c92",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9999c83-0419-55d5-9738-34c4a231ad28",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:033a784f-fdd7-50dd-8474-fcf6f9945685",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b71fbbef-96be-51ed-92ca-18608e94bcc6",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3d5062e-4283-5399-8071-9cdff64b6b04",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d4a8dfb-ea7f-5b94-b22f-4769578a613a",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.3"
    }
  ]
}