{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a443cd70-8aa8-5b9f-99c3-928ab12ba3d1",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-websocket",
      "version": "9.0.90-tuxcare.7",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:d4a47f99-1666-56a1-9ed9-641d5a793ce7",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5160049-c4d9-5e7f-87ed-31c54e59642c",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62d69ec9-c3a8-5364-89f4-d6e7c6d964e4",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-websocket. Fix for CVE-202-13943 for this version has been already backported by the original developers, so brunch 9.0.90 is not vulnerable"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33e3e463-48d3-5684-b6b9-c0f553244169",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2ed1390-d37b-58a5-9546-a978c9f82525",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5bde2c8b-e0f4-565f-a5c2-d2f22b172e5c",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01062e9b-57b6-529e-bd06-03a9d5ed0355",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38564ebe-fb91-51b0-bd79-22cf57b3b9c8",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0440269-7156-5f39-b00f-3ec810ac743b",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:795b6f0a-25de-5007-b07e-28358e10e53b",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc9bcd58-9a20-55e4-912b-a32ad6820f2c",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49f2dccc-8144-5b54-a6b2-1c1d6bb70555",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a078674-590e-5504-9b2f-ebd0aa49d84c",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d18aa59-2e85-59b7-a907-974b622b149b",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d9b41c4-4328-5f60-b212-af69bc6df29b",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcf366fa-49f3-555e-9a82-63c7177fcbe8",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b3d0319-c6d7-51d7-8dbc-e3caaa408bfb",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31651 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c14956a-1223-594a-afe2-1ae026eace7b",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31795750-1479-5f5c-be9c-1780bb635670",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a705534-0c43-5a46-bd86-2342296f0ca7",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09ff4513-05ae-563c-992c-59b2efd7c106",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:410fe1d0-d6c4-5c23-ae88-64fe01e6b912",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-49125 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc7ec79f-9a94-5854-84c3-3a8c573a06d0",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46fd3d6a-7c4c-5252-bbd7-395b6a22468b",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb62fa52-85e9-5757-8d7a-9d1231ab27c6",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5cdc75a-2bc9-512a-bed6-5cd089c7c7d3",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2c1307d-a35a-56e8-91ea-550e78f03bc1",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ea65b3c-e040-581e-88e4-1c77e73e83d4",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07254bd2-2b52-542f-8c35-b160e3181f05",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8404e7ef-1863-5d1b-8465-33f784d4e582",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b82ac7e4-076c-5795-98ec-92a876de8929",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a98a861-bdbf-5020-96a5-d9930d4c0a6e",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8be14af1-4857-5f1a-9c5b-86ce25ea01f9",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24880 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ce84569-d855-5f3c-9456-53b2bdf225ea",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6388e544-4bd9-5a80-ac1f-83a045f2fc84",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99d4d82f-48bf-5fe1-9855-5f50c6d842d2",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fee1eb56-1f35-5b28-9344-8360bc6d5f89",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:043d2901-1921-520a-90f0-34ad3e5590d8",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34483 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd324fad-d420-5dea-896a-efca4981702d",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34486 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0faef8f5-de37-5dc0-bb64-3c8cbb6e71d9",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34487 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-websocket."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.90-tuxcare.7"
    }
  ]
}