{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e4291062-ae53-5b52-b9ea-73faf09592d6",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15",
      "type": "library",
      "group": "org.apache.tomcat.embed",
      "name": "tomcat-embed-jasper",
      "version": "9.0.50-tuxcare.15",
      "purl": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:bc94dac9-61ce-5902-9732-e226075721ed",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-11996 does not affect version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper. Version 9.0.50 is not vulnerable. Summary: The target repository contains a functionally equivalent fix for CVE-2020-11996. While the implementation differs from the provided patch, it addresses the same performance issue using a more efficient approach with ConcurrentNavigableMap.subMap(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:479fa698-5a7f-51f4-8928-425111759a30",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e6be1dc-95b4-560b-8358-26bfb256b9d5",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper. Version 9.0.50 is not vulnerable. Summary: Target repository already has the fix for CVE-2020-13943 applied. The maxConcurrentStreams check is correctly located in headersEnd() method, not in headersStart(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:620316fc-5cb0-548b-bd9d-0739a96893c8",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-9484 does not affect version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper. Fix already present in baseline since 9.0.35. Verified in java/org/apache/catalina/session/FileStore.java:303 \u2014 canonicalFile.toPath().startsWith(storageDir.getCanonicalFile().toPath()) containment check is in place. Advisory range 9.0.0.M1-9.0.34; 9.0.90 is well past the fix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d71c3d6-2a38-5934-a381-0bac368b137e",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc133195-5e7c-5b6e-8226-273d21e28813",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c38c325c-7536-5bbc-bc62-1f2023e24022",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3135639-019c-5137-8a0b-5de496b16da9",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0b894fd-11ae-5e0b-be6a-0bee7c7655ff",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12354a11-2712-52c5-b87c-8b225e7183e5",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-34305 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab2c0955-d3b1-53fe-b314-78be4ceafabb",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a2a204b-a940-5624-9801-43ccb36a7ca1",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:846d14fa-98df-548a-b131-b7b182a3924d",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-24998 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88863011-16aa-5907-bef9-2b543d19db6c",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6b76b66-600b-53e6-8d8c-6b3ec797edd0",
      "id": "CVE-2023-28709",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28709 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60b634e6-55a3-51db-bcef-3bbd51ce2a26",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a8eba0a-d3b2-5d63-a500-7cd5d08747d1",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42795 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50bef47b-c00f-5c05-ad9d-aa2a9c7b80ae",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5eacc61-670f-50e5-8503-05311c25d8d8",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f58acb7e-0ef2-5766-a80e-ded3d50e5704",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-46589 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f561f75-8441-5444-8b3d-a244f7bfe198",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87c335e0-5d60-51fc-a8d0-519100d8e2f0",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4796e3db-f9da-5374-9587-f425cca0ff92",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef8e3c9a-1071-5207-89c6-68a46461a5e7",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f808ded-7393-58be-9b7d-9886a6edd7f5",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f163231f-7a68-5c3e-b9e0-ce650df1b660",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6fd6341d-8ebe-532c-9268-aabd200b792a",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8643cec4-d3f5-5a6e-851a-c596b4ebe8ce",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d698fac-98d0-572f-91fc-29e37a5d9f44",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f2c9260-b685-5f1f-b0e7-d45d3acf5e81",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-31650 does not affect version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper. 9.0.50 predates HTTP/2 RFC 9218 PRIORITY_UPDATE frame support (added in 9.0.76). Advisory range per NVD/Snyk/GHSA is 9.0.76-9.0.102. Code inspection confirms: Http2Parser.processFramePriorityUpdate method and priority parsing in Stream.emitHeader do not exist in this baseline. Vulnerable code path is absent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bacbae9-3fce-56dc-8cd4-6985f1071dc4",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:548dbd1a-f4bc-5e09-b592-673033e1fb94",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8801ad26-b0ef-5c1f-a2f1-3bede5b29a14",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5dfd7993-106c-5e77-b69f-d79a8c31e2fa",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9714a5a0-4e48-52bd-9468-8b0f758ca09b",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5d15427-4671-52e7-9af1-b57d4a35df26",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca31954c-d690-52f4-bd0c-3c85946c3a24",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6871a9e6-1c24-5aee-b2d0-fd5780bb3feb",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a405e8d4-e6df-584d-9211-22cc48809737",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db80aff2-42c8-55a2-94f4-73922e59c677",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3690629f-7f6e-5430-a872-c3eed299de04",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3032cbd6-650c-59b7-8a5b-1469543c3596",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5ee7da5-b796-500c-a26c-79743dfb9b78",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f1d2b8f-f57f-5b7c-ab26-7a3136de5e35",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd0d862b-1950-5577-853f-2cc7831962c0",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2b1066b-9dca-533a-959e-155a62e8af43",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c498482-5e4d-5f24-bf03-0b5323f841e7",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c365443f-4a98-5be7-90f1-126615a5ca7f",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f467130-5dc8-56aa-a717-89f07f3dc652",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5652b19b-04fe-5395-9df3-6425cf128030",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1515e023-30e2-568c-86c2-e8a6ab298098",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34486 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b76e068b-8f21-59f9-8954-22491a41bf73",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd3b7580-a558-5b28-99f5-05eff40ee12f",
      "id": "CVE-2026-41284",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41284 affects version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06439ef2-108f-5abb-b6e8-11ed8270b16d",
      "id": "CVE-2026-41293",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41293 affects version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bfc3f5f-957f-5224-a803-1c1e805bcc47",
      "id": "CVE-2026-42498",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42498 affects version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:356e5380-4787-5796-84d9-4fe4e5976bfd",
      "id": "CVE-2026-43512",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43512 affects version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ca902cf-b16b-54c7-b20f-06a6e6760136",
      "id": "CVE-2026-43513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43513 affects version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98381c39-0286-5ad7-b0d6-edfd618b8563",
      "id": "CVE-2026-43514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43514 affects version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4867386c-8e97-52bb-b853-ea5271e05ddd",
      "id": "CVE-2026-43515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43515 affects version 9.0.50-tuxcare.15 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.50-tuxcare.15"
    }
  ]
}