{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d00b7e7c-10e9-5cc2-b025-7ad042fb42fe",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-websocket-api",
      "version": "9.0.87-tuxcare.3",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:04e7872e-c852-50de-8625-97effe134593",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7b0dccf-936e-5930-9d04-47121f8f8b83",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23e9a594-061b-58a4-b7bf-c721ff970dbf",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd4d2b36-1353-5342-b52e-a17e5de383d9",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c85b1b6-4612-5def-9cfa-637ab38abf3f",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e111b23e-0987-5be0-a056-386977679ebb",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20e5a7b1-a191-5bbb-95fd-8df2e25048b1",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20a646b1-b922-5ddc-98bb-d39d7df51d30",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:575f48e0-8067-5e04-852f-2f602e9bb69e",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fcd38ff-3153-5627-a637-ab9a64ea14f9",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c48f300-2aba-55c8-8a5e-f7f3df9dd612",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20e7dfc2-6f6e-5179-b552-e45d5e6ccf04",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ddd25832-fcca-5d64-a0bf-1971e73d4ec4",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5141ae5a-3d44-5998-9518-d549ba6107f3",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec601bcd-5282-5b8f-8dbb-01e17d2301ca",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:331ecd8c-488e-5848-8f86-9b1d559a1704",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bb4fb78-9149-59b1-bcfb-90bde19972fc",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aacedf4e-45c2-5dc7-ab76-01eae4b80b13",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76910f7f-cbb7-5f73-adba-beddf745c4dc",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9418636a-1d5b-533f-83a5-4d2de24236c7",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85a45fd0-4d73-5afe-a6de-96e290356ca7",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48988 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b611778a-44a9-5b01-a487-7cf5d28eee85",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e52add8e-24b4-54d0-ac0c-3b0e29749735",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3773e5ef-762c-5511-a3d2-ec14f3605660",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c1d69c3-7887-56de-b506-35e219b1d32d",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8f56b7f-76fd-5f32-b3d3-bc19163fdbac",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52520 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fd25100-f620-54bc-b2f8-a30679175fa3",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5cb414b-a98b-5e5e-bae7-9aaad890b2a3",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af3c680c-8b27-5ba8-a2a4-6fef576c45f5",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55752 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23b10d75-c564-56ef-a875-4780435244a6",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8033d4e8-4ae9-5d04-b2ec-ca713312fdee",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8da03da4-90f5-5b27-9e28-b6e9524b7e81",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28907267-9909-503b-ad1f-6f18562128df",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:957266ed-d1a0-5090-ab2c-486d37aa49fc",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d4640a4-d0f6-540a-b429-0f3a9ce1ad57",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38ad4f60-a728-5811-837a-213555f7c793",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a88b9df0-acc2-54a6-b38a-a01e722ce072",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5bd2afb8-81c5-514a-b700-9a5a58f67788",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f1b2a04-dd10-5168-931d-c2c924f2ca36",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e093a6e-b638-51b0-ad06-67e5ba54e816",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52729f16-0208-5e33-a8f9-f0e0b3568088",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-websocket-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket-api@9.0.87-tuxcare.3"
    }
  ]
}