{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a790c743-4e02-5a78-afd3-ebafde1df5d5",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-servlet-api",
      "version": "9.0.90-tuxcare.7",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:50ea9735-304d-5da6-af20-bd8638f3ce94",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b677c656-e73b-507c-9930-2d4bb7c93983",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d4ab844-0ea2-5ba5-ab0d-a9c236d2d22a",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-servlet-api. Fix for CVE-202-13943 for this version has been already backported by the original developers, so brunch 9.0.90 is not vulnerable"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c1a0ce8-a238-54dd-8246-e08cc4930f22",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2790ae66-c47b-5bd7-a23d-0d3f52aa94f8",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6c58021-c124-5a28-9e7f-f9b4b44a978b",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d55ac8c2-a044-5db7-b779-14426cdff85d",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32dcaedf-0e4f-54d5-8710-aea177b6cc79",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9fdbcf8-24b3-5ceb-9ba3-65d91462af86",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbcf904e-1ad8-5b24-9cea-148578442b64",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ecf31c2-b34d-5716-ae95-eaf19ff2b3cc",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:338c6c1c-e953-5569-afec-73ec7b7aa06b",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e20f8988-32ed-51cd-a853-213259cefb74",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1e56dbe-fbf6-5303-8b9b-59c679f9d288",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:116c34c9-ee02-595e-94d2-bf70783b5191",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c223e9f6-4f1e-5452-acc4-a931879f16fc",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c0877ab-6ced-54dd-95f9-b8a51990cb4a",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31651 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:019ac6f8-cac1-512d-9984-7dbc0a824da4",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a961fa1f-cafb-56e0-b671-5f8a78313379",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94369b1a-9943-5726-a211-9912125a3308",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d888c3b5-7e66-5eb0-981f-a4d8c6b22187",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f35feef2-e8a9-55ea-8f3d-3b9264cf45d8",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-49125 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5cb6eb18-26bc-56e7-8c93-8bd54f8c3599",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e65413cf-2918-5a78-a805-08747b75b38b",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:358f61eb-58b6-5040-b81b-cd0919266006",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3e6b444-7d7e-5fde-b9c7-b2a749e5bb4b",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a449dda-a0cc-55d2-8dd7-cbe01c070893",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02db3ed7-4519-533a-bbb3-126729e41243",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd2f0808-3726-5c6c-bf53-51d7e682b082",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e41bb9c5-b51a-5bd0-8f58-80ff3e19bd1a",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72ac7bf1-37fc-5984-9fd1-2b0e1eef22af",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5bc3c29f-a7ee-5988-be0f-86dc1dc002cd",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31beb4d8-154b-568c-9784-e581db3d6a4c",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24880 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:667911ce-56aa-5bab-b084-6f786bed7866",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d50d86d8-79c0-5982-b1b5-95f6cbeb9095",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71a3e5ed-4d34-5cd5-b840-12330b6e6217",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27bd07ba-037c-549f-a62d-ec71021d1fed",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5557e47-2fcf-5b0e-a80f-62e5acdfb4a6",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34483 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2b7d37b-d566-5985-a113-320e064b666e",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34486 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99a71907-f68c-58d5-84c8-8b542b689afc",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34487 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-servlet-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-servlet-api@9.0.90-tuxcare.7"
    }
  ]
}