{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:57155634-17bf-518e-85a4-8cde62ec7ec1",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.5",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-util",
      "version": "9.0.90-tuxcare.5",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:7b4566a3-afd6-51a8-96be-13eada3fa9d9",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9007d9bd-4c9b-5f21-86b2-2ce71867d9a8",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:235a2874-49c1-5e9f-9f36-afbbd2fcd89d",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-util. Fix for CVE-202-13943 for this version has been already backported by the original developers, so brunch 9.0.90 is not vulnerable"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37435910-4b44-5d7a-b7ed-4ad8ab3a91c6",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:112ca7e1-b8dd-5461-958f-343b273ab9d0",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b79dfe5-e7ff-5cf4-9b5f-683f3d2b2bb1",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e23e8d95-f41b-5445-9dbf-3fcfd4aa53ed",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f323575a-6778-5010-965e-a9d5893fd132",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5aac295c-5e24-57b3-8f7d-c90925d8f1f5",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:129739a6-8341-59a2-ad9b-092d8b15cff4",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23012770-6bc5-598c-9973-05c1f9a945e1",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53ee7dd5-09c9-5de3-adef-bf7aed100da3",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6fdd6598-4400-591a-bb5c-071d5aa6b86a",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6db69eaf-ebdf-5c3e-8d92-0bc2f7931be6",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:165f525c-ff8f-5248-9f7b-18e8b1714ff0",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d8e7ef5-0aa7-53f2-b16b-b0cdbe49a1dd",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f3ccaf7-cde4-560d-891b-2ad763d8ed39",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31651 affects version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8f45554-51e0-5e5d-a60e-e92e2148b045",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83856022-a0be-551d-81d4-f406b38995b8",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82a0ea7f-ff2b-5109-9518-22202d167092",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02ed2974-9049-5921-8c7a-9a46aa05becf",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fd4ad60-2efd-5961-8efb-13e7b81515ed",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-49125 affects version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4aa64932-0745-5e88-86f0-4b90d4679bd0",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19ec91ae-7dfb-5632-bbed-891879bdb6a4",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:533b7cef-d6c4-57ce-82c4-8c26292183ae",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93cec0bb-4913-5b7a-b144-1cbe7601e46a",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f891ba56-1fa9-57e3-b2b9-22a0937fffdd",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fe2128c-7ca2-501d-ba80-491bcca44630",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15315a34-4928-5149-9d4b-67375e0fcf87",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd38f5c0-4fe7-5577-9063-758ffa183dd7",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9809aab-5e79-5dfe-9be1-961f09537d7e",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0cb831b6-2ba6-598b-9114-203540113bac",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec84c8af-53ec-5110-8d36-724db497a8b8",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61e9f830-252c-5bc0-81f8-de8941b3dc54",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d08a32aa-ccda-5d26-b4d8-847addcb3718",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27edbfd3-8746-54a8-9565-af38bc3e95a7",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e0a45d7-fba4-56ea-81f9-491a15e0300c",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86b0896d-8376-5cd7-8b42-9248ef8ebb69",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:264e3cd3-6e38-55a4-9101-6f08ce5df147",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.90-tuxcare.5 of org.apache.tomcat:tomcat-util."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-util@9.0.90-tuxcare.5"
    }
  ]
}