{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:27230dc7-720c-57c8-b15a-b10c2a9da6d5",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-el-api",
      "version": "9.0.90-tuxcare.7",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:2a04a510-5ae1-50a5-a096-696afa5aef6d",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1d4e8ef-01ce-543a-8d10-3b21213b1dab",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d3a1d31-c241-568e-8b64-046680d0f4e8",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-el-api. Fix for CVE-202-13943 for this version has been already backported by the original developers, so brunch 9.0.90 is not vulnerable"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04626c3c-c427-5c3c-b337-d02abf3ef015",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6764637e-5144-5611-a994-4cc91e6ac037",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a6803a5-b738-5819-9002-f3df4165abf3",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:228cfe08-3e93-532b-8235-0eba820a2fd8",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d601f361-c38c-5fb4-af40-d7b44bf7d095",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8aac0e83-c55d-50d9-9c1e-444048392502",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2535b765-3db8-5895-85a4-2f03a7fad74c",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:880236b6-2dcd-5c6c-9a80-77545d01b697",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a190a8c8-8fe9-5b79-ad7a-64329d7e6eb9",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf2d2ba2-bafa-581f-9b80-a111c553cc3f",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1be0d014-0122-5af6-82c9-a2b2e52aad69",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57621764-302e-5c51-81c3-15ecc684c5f6",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eed28462-b8f5-5b2f-bbe7-b127f8a38830",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff7c193e-727b-5f60-8625-2aff75b87fce",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31651 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b52b997b-aace-573b-ba0e-68f3b5c5e11a",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e10d824a-f0cf-5a56-a10e-7ccd185f2183",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09175ac1-e8d5-5668-a0a7-7eee7eba50f0",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83dc9943-d4b8-5b64-973a-bde20a2a168c",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8b62e10-b697-5a4c-9a71-4442f8e303ef",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-49125 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d59ed9d-b5d4-5089-bf40-55e4c11c0069",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6d2792b-b4a0-5e45-8748-d0272e6e3d62",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:786ec864-d4f1-5faf-a3d5-9fd3a9569ad4",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef79ec60-f154-558a-8091-6a0c454a1d68",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d74f8c0-51af-5a5c-a128-198eda766306",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10394338-7b81-5677-a418-4858b273594b",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b284673-5f72-5898-9a81-860f774b14db",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0c26610-400a-5831-af29-7df37310e76d",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:915d615a-37d4-55aa-ac8e-1cbecd0a17e3",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7128ffb7-b5cb-52ce-8235-73323e899557",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:115d491c-3e24-525a-8215-d59f39e4ec81",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24880 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c863aa2-d106-565b-9867-512b6043d035",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c297fbdb-fa4f-50be-a644-d821a1525b2e",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db0d2af6-86c8-5cf6-9a28-eeb764aa8af3",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9cc995d-43d1-5160-a04a-5a5495ede997",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0821c005-9d39-5090-934e-d1145ca9fd6c",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34483 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c35b24ee-9be9-5e94-97bb-5aa14c9663c1",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34486 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab3ac142-7117-544f-a888-aa0770a22151",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34487 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.90-tuxcare.7"
    }
  ]
}