{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:261e0d73-8a7d-507f-9fc0-15e7e68a885b",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6",
      "type": "library",
      "group": "org.apache.tomcat.embed",
      "name": "tomcat-embed-el",
      "version": "9.0.87-tuxcare.6",
      "purl": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:c5565487-77fe-5e78-a7e4-e9e44831a8ee",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.87-tuxcare.6 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fda3c6a6-9083-55ba-b6b6-f4fafca242bd",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.87-tuxcare.6 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ba4bd5a-0b20-5bb2-9e93-bed10ad52b96",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.87-tuxcare.6 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:377dc875-0827-544e-a985-c2e9fe51e47c",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.87-tuxcare.6 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:137cb6d1-1fee-5478-92ff-0cd2a8df72c7",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.87-tuxcare.6 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bf742f7-d786-50f0-8344-842dadf4d728",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.87-tuxcare.6 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:676cbe82-444a-525d-a6d0-ed881e91c887",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.87-tuxcare.6 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f07bc63-2c86-58ef-8e4f-415b7b2ac5e5",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.87-tuxcare.6 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea9c9a47-2e00-5a53-b835-26ce37973425",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.87-tuxcare.6 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bef254a4-3357-5376-85fb-7dd963d74ad5",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.87-tuxcare.6 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb7a4706-d5fe-5cfb-9712-3ea8efbabd4e",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.87-tuxcare.6 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1033071e-5ee5-58a2-a26c-c34469e2262d",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.87-tuxcare.6 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da0c1e37-fb42-5927-aaa6-d2726cc46f08",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.87-tuxcare.6 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77459817-1b75-5e93-80ce-0e62cf3a4eb8",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.87-tuxcare.6 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62948498-8ce5-5478-8256-f0d201c0b45d",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.87-tuxcare.6 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a63ab2d0-1fd2-5593-8e78-f9bbf6200473",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.87-tuxcare.6 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e476229-4d0d-5e39-8a5b-4ccc5cfad9aa",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.87-tuxcare.6 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8ca8c98-60d2-525d-ae93-8f14e1c0281d",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.87-tuxcare.6 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d508ad7-2673-5e32-9cb8-bff1cc203d8b",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.87-tuxcare.6 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2205f7d-0741-5d20-beca-8b21fda92173",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.87-tuxcare.6 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:952bdb1a-a429-5d4c-97d7-e3dcd03d86da",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.87-tuxcare.6 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:884a3bcf-2dab-551f-a1b7-3fe86dbf1a6f",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.87-tuxcare.6 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9fa0dad-3e5d-583a-a4b5-d47d798e746b",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.87-tuxcare.6 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f62f82f-bbdb-5caf-83aa-f83c7b98ab44",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.87-tuxcare.6 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cebae89c-fc1f-52eb-91c4-da107800c528",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.87-tuxcare.6 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d1b25f6-313d-5bc3-ad40-237419f4be33",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52520 affects version 9.0.87-tuxcare.6 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:081f46dd-1365-5d34-9cfb-67e3d7dc3193",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.87-tuxcare.6 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7929fe51-0cb0-5880-b371-f3e2fed78bb9",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.87-tuxcare.6 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb3aec14-f2f4-5d2d-bc26-40a2707ff99c",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55752 is fixed in version 9.0.87-tuxcare.6 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89f35a51-5277-5087-af46-b9024b60eb93",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.87-tuxcare.6 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0cfee08-f3a8-5da3-8f07-ddf69751e872",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.87-tuxcare.6 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6345f87e-a4f1-5063-938e-82fe816b3ecc",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.87-tuxcare.6 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37ed2f60-fdb0-551b-a25d-762294186b97",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.87-tuxcare.6 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0555a78a-34c6-50ec-81ca-cce010c3f109",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.87-tuxcare.6 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84bb36ee-f127-582e-a9c4-c9b70420768c",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.87-tuxcare.6 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e29c072-fcd4-5d95-9b72-127a21b3dcba",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.87-tuxcare.6 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14c8418e-050c-50fc-a0f3-ea08e9fb2dcb",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.87-tuxcare.6 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0067264e-7b8b-5388-97f0-2bf7c5d0bbb1",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 9.0.87-tuxcare.6 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:883edc82-9bd8-58c4-b495-cb4c1a050118",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.87-tuxcare.6 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2a9b096-c757-5d52-b4b8-b0cdc5b4133d",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34483 is fixed in version 9.0.87-tuxcare.6 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd6cbcc5-a993-5464-906e-482170113cee",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34486 affects version 9.0.87-tuxcare.6 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6451071a-66fa-51cc-ab84-c60b9fb82f48",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.87-tuxcare.6 of org.apache.tomcat.embed:tomcat-embed-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@9.0.87-tuxcare.6"
    }
  ]
}