{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:dab3901c-f202-5236-b37e-0e4c9959b1c9",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.90-tuxcare.1",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat",
      "version": "9.0.90-tuxcare.1",
      "purl": "pkg:maven/org.apache.tomcat/tomcat@9.0.90-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:0147c476-3f35-5a10-bd04-48580caa4be9",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36463a58-b3d8-5586-9b3d-8da3577cf53c",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a0a54dc-7f46-51bf-a039-8076ce6628cb",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat. Fix for CVE-202-13943 for this version has been already backported by the original developers, so brunch 9.0.90 is not vulnerable"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e28cc2ea-4730-5eaf-859c-72276fac7b52",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28edf3b4-0c32-520d-8f0e-865cd55756a8",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:615484c4-22fa-55e7-bc3e-ebc2b64a1fc0",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fecefa17-2476-5354-9aab-1fcad1710e54",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:356af8ec-fb9f-5c8f-9f1c-9f7ec09d27b3",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b48e0fd9-f32f-5912-8832-031e07ec45a0",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76fedae0-9fc5-5171-b83f-d930e404d0b8",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3291f411-e859-50f6-aa10-d35d11f1143d",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb701e18-7218-58fc-8287-5607485fa6dd",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3e2c701-2d85-52b4-bfc7-ac6d369a7cae",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f91eacc6-2d01-5951-a6a8-908deaa5afc7",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56337 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a653a0e3-bfda-5f1f-a85f-f6405c79caaf",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa140f2b-571c-5fb6-ac70-5bcafe284713",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a014b8b-e9dd-5a64-86e6-c0080f35224d",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31651 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:408dd6ef-ea13-56b1-af33-c40ed6b591b6",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-46701 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92397a44-172a-526c-97c3-0c1642649319",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c97f830-6eba-5c1d-a15a-eb9a9008198d",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48989 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64850fde-c22b-53cf-811c-09ffed1ec92e",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef4206f0-6387-533f-9a52-d528928c79b2",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-49125 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4422e8e-fa1d-5dde-ad07-ae00e8bd6e2e",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52434 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b33d35cf-18a5-568f-867c-75f133f73686",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7df53bce-f6b3-58b3-b087-a821f2339c8a",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea0b0f49-8a44-5b49-8326-13d3b4831ff2",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28ff3c6d-3621-50ef-ab12-b1e975351307",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e85dd8e8-e033-56b3-bc2f-53b0db19c987",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc92ba31-52b0-50c3-aa67-81ab613ec7c1",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:170bbf80-25ab-5b7f-b53d-51371ddb778b",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ace27e89-6111-5e14-a01f-248bafbec4bf",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8eedb295-5733-527a-a5f2-fe66315d61ce",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca401ba9-9589-579f-89a1-c66a05666d9a",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f77bd55d-166d-5106-ab9b-949e39cfd421",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:213c923d-ccf5-5f14-9fef-1626de3ed308",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbd95ba5-bbb0-5adc-a2a4-8bbdb6e5963d",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eab22422-be9c-5a61-ac59-9b44fcf4a309",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:824143e1-e1ab-592a-a2a7-a7537057e0d0",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.90-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f565d27-23b4-56d5-87f0-6ae5b4ce6cff",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.90-tuxcare.1 of org.apache.tomcat:tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.90-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat@9.0.90-tuxcare.1"
    }
  ]
}