{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:51c63c10-ee33-5eb3-8668-e1b18cbc7479",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-jasper",
      "version": "9.0.50-tuxcare.15",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:890afda1-a4c7-574f-87bc-c5f8d7f3dbfe",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-11996 does not affect version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper. Version 9.0.50 is not vulnerable. Summary: The target repository contains a functionally equivalent fix for CVE-2020-11996. While the implementation differs from the provided patch, it addresses the same performance issue using a more efficient approach with ConcurrentNavigableMap.subMap(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2b0e1b2-ae9d-5cdd-957d-63d69dd3555e",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ad168c8-945c-5fe3-9cfe-b10eb6191982",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper. Version 9.0.50 is not vulnerable. Summary: Target repository already has the fix for CVE-2020-13943 applied. The maxConcurrentStreams check is correctly located in headersEnd() method, not in headersStart(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b570d49-ff5d-5f16-979e-65365387c3bd",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-9484 does not affect version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper. Fix already present in baseline since 9.0.35. Verified in java/org/apache/catalina/session/FileStore.java:303 \u2014 canonicalFile.toPath().startsWith(storageDir.getCanonicalFile().toPath()) containment check is in place. Advisory range 9.0.0.M1-9.0.34; 9.0.90 is well past the fix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50e3eab6-62f2-5687-bc38-c3f67864da5c",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96a0d055-7a08-5a8a-9a22-9ba16984e161",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03025dc6-c6a3-56c6-bf88-27aa87a073f5",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7a88099-389c-5698-9484-138ea08bf56e",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6f68a3f-38b7-5663-8ee6-b4e0c7ea749d",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff2116b1-d6d7-5e82-9b00-024a57bb0140",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-34305 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f924878-44ee-5dcd-b71c-c31c85549d32",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ceeefea8-558c-5147-bdce-46a2d97d987e",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:316eeef4-cac8-5a4b-9e89-02b1b3b4fe91",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-24998 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:887ac092-f030-5367-8c77-a87fa15188ea",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5263170d-2e26-562f-bb8a-7c45a5dab3a1",
      "id": "CVE-2023-28709",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28709 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31e3a1b6-01ef-537e-89b0-585ef6bd893b",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1889dc72-67d8-594f-96e6-de7599f74411",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42795 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b53cbcc-4aef-5b30-8898-0418af16b557",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c8c4e4b-00cf-5c3f-812f-b40fe74fc06c",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a995fbd5-0745-5e04-8ce7-fee415a50119",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-46589 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b172848-15ca-55e3-8bb0-5f6750dc1615",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a89a0ce-b9ef-5019-a5a1-a9d8de1b2f6d",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e99755a9-03da-5376-96b5-3b0ff5ae4787",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:581a8152-d5fd-5dec-927d-180dd2cdfa43",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b202aacd-e815-5cc1-a578-7845745ae55b",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b97dfe4-9072-5003-8bc6-7aaa5186be2b",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1f6d5ad-2d3a-5f36-aa78-09413319d9e7",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3beb8d56-f8ce-547f-a434-366ae39f65a3",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f824597a-03a9-5710-be5c-baba174c2392",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3bb99306-4451-53a9-b0b9-2074c9dbbac4",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-31650 does not affect version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper. 9.0.50 predates HTTP/2 RFC 9218 PRIORITY_UPDATE frame support (added in 9.0.76). Advisory range per NVD/Snyk/GHSA is 9.0.76-9.0.102. Code inspection confirms: Http2Parser.processFramePriorityUpdate method and priority parsing in Stream.emitHeader do not exist in this baseline. Vulnerable code path is absent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d834cd8f-172f-5d6e-9dbb-7c235278a138",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11588ee9-66d3-5631-8bfd-26b414810356",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9db344ae-4690-5cb4-b04d-04dd7eaa4f55",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae64339b-90db-51f0-bf5d-01583f697760",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:159b3770-0bb1-5190-b3f1-8c636fd364c5",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ba2e7c3-c0c2-5438-8a10-5d6282317b03",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92f6604e-0eb1-520e-8589-2e4787f0bf46",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c8cfb43-49d7-55e2-b27d-41dacabf9fe4",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a75d1fd-dbf2-5932-8935-023caf1e0708",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f68ccd5d-a0e8-5471-b2d6-8cf16c2af5fb",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:167509b3-44bd-5cac-9dcd-06ff0322b7f2",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:698fcb29-f993-5d80-a027-92c05eab4a95",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:451ad590-6a3b-5278-8e19-f2758bd028c9",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:598d28d2-2f3f-5da2-b3d0-5be891a88a78",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76c7618b-5a7c-5526-9cd5-b4b2de14683e",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc246766-7742-5f42-93fe-83d173a83fc0",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3bf146d-3bcf-5272-8415-699b523ab555",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa9c0eb9-ce22-5cb8-959f-395360b07fe0",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7be270d-43c8-509e-9630-eefb8c2f9682",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f96866ac-c9a4-562b-856f-c0137904eee9",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ee0e84e-eea4-556b-8f7a-85a07d970acd",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34486 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ec72ceb-6791-5915-942a-68fa78ba5edf",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f406ea94-4f37-5a8e-9ad0-3cd95db08584",
      "id": "CVE-2026-41284",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41284 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36568db4-a7a6-51ca-a26b-81d88315a9af",
      "id": "CVE-2026-41293",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41293 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:293f7b91-51cb-578f-9bb3-5d6b05ef9ca4",
      "id": "CVE-2026-42498",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42498 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08cb80b1-1b7d-5c46-a5fc-b30282b7dc5e",
      "id": "CVE-2026-43512",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43512 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf92caa7-f9a8-5bda-9223-426950b79c85",
      "id": "CVE-2026-43513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43513 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2c6159c-04da-508b-9544-1d809cd096c9",
      "id": "CVE-2026-43514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43514 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c9596cc-405f-50ac-9ca7-f4959c86319e",
      "id": "CVE-2026-43515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43515 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.15"
    }
  ]
}