{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:966b06e1-5a58-5333-972c-ddaf6e950878",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-jsp-api",
      "version": "9.0.50-tuxcare.15",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:6041d063-bc1b-5909-9544-34754b3345ec",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-11996 does not affect version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api. Version 9.0.50 is not vulnerable. Summary: The target repository contains a functionally equivalent fix for CVE-2020-11996. While the implementation differs from the provided patch, it addresses the same performance issue using a more efficient approach with ConcurrentNavigableMap.subMap(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28f61524-5eeb-50c2-9997-b98c2a9a3fc6",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdc1c0bb-ceab-534b-8a21-91a1945dce6b",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api. Version 9.0.50 is not vulnerable. Summary: Target repository already has the fix for CVE-2020-13943 applied. The maxConcurrentStreams check is correctly located in headersEnd() method, not in headersStart(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bae41b3-035f-5a7b-a843-548165a12005",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-9484 does not affect version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api. Fix already present in baseline since 9.0.35. Verified in java/org/apache/catalina/session/FileStore.java:303 \u2014 canonicalFile.toPath().startsWith(storageDir.getCanonicalFile().toPath()) containment check is in place. Advisory range 9.0.0.M1-9.0.34; 9.0.90 is well past the fix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86d2e8f9-87d1-584a-8c12-c7692e1ba6b5",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ac3c5b3-02f1-508f-8507-d37ae72ab5b8",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2081b02f-dc34-5bf3-8534-2edb6dab6657",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8da21bb5-0e94-5257-a503-cc72c08d183e",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50334ec2-f065-50b1-a41f-3ea2a300335f",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:addb6310-3ffd-5a32-b09a-6ad3da6a1b59",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-34305 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8357ec47-5060-5e73-8234-a68b939985a3",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2795c064-ec08-5247-b92b-7099173c3c30",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:446a7f9e-4dc6-5869-9c85-2fa5a59b2b86",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-24998 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15ddc6c9-4ef4-572b-b892-38556df99239",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62363e5a-7f45-552d-b49d-6777ab0782cb",
      "id": "CVE-2023-28709",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28709 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba325341-d2e6-5ef8-adb5-6885fd541822",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f073374-9964-50e9-9fe3-87032758a45f",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42795 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a34698c5-dba0-5eed-8902-17bfe857a5da",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53f52d2c-966e-592b-834d-5adbcbbaa6fe",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee663ce6-4685-5b17-a3fc-2072437ccaa7",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-46589 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:768d5a73-bc46-5664-bf52-d06f61653b9f",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a09477f5-624c-5318-ad32-543288f1fd28",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09c364a2-f81f-5c4a-9b1e-96741e134815",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20623439-a9b6-543f-b3b7-7ae2392ba7e7",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2260fd7-ccd1-513b-b6c7-c2f320141a71",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1dadfe8f-e7fb-5815-a27b-2bf66c7b5e52",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1b2aba6-030e-5662-a704-f91610035ebf",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9500ed92-a76d-52e2-bc31-e5d6ffa2aeea",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3cd0086e-a0bb-5893-a6cd-40854b104e07",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc30fc9b-f8b9-5e37-8522-bd3b2c70e88f",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-31650 does not affect version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api. 9.0.50 predates HTTP/2 RFC 9218 PRIORITY_UPDATE frame support (added in 9.0.76). Advisory range per NVD/Snyk/GHSA is 9.0.76-9.0.102. Code inspection confirms: Http2Parser.processFramePriorityUpdate method and priority parsing in Stream.emitHeader do not exist in this baseline. Vulnerable code path is absent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6872ed2f-c4de-5803-b862-93b0c86cfe9b",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50b7f5fe-aa32-5369-bc50-bae73102611b",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a10d763b-b2d8-5dc5-9399-0ca59b8701be",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42cdf8ea-2767-5efb-8b97-7db8c3e93043",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc753737-f49e-5834-b2d5-04988428fdc9",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:892420d2-9a8f-5134-b016-bfcee36d7332",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb1e035d-b40c-5db4-8211-9ac5ed2f1e27",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c23676f9-0221-5699-bdc2-5a101e8ba7d8",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e171ced-c8f9-596d-ab11-140012392023",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:742aa444-7116-50fb-8295-f510c364b44f",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e9ff650-2915-567e-9caa-cf0c3005b4d4",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46ff4345-d61b-528f-bf94-5b1f12c1ee3e",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfd74613-b258-502e-8e26-9e6054ec5adc",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ec1c4e6-ee10-5ac0-8fa4-e5105da7bcd2",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4e95cd8-dedc-5204-b86a-ff03fa1a8e55",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37c4f3b9-5002-5465-b303-9d1b29ab0207",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82eba409-222c-5c15-b179-783dec435e58",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62d10a5c-9b65-5bcd-af69-dc46c5e4aa0b",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1daf1a8-c574-5020-b15d-4bb0af57962f",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e88d952-00f0-5418-b9b2-32df06241a35",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de84126c-1614-58ab-9739-2956f82524a6",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34486 is fixed in version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:706893ef-5b56-5fae-ba0f-03b71e3da9b2",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47fda7f5-8622-5271-ad2a-20410011a048",
      "id": "CVE-2026-41284",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41284 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:511f8f8d-6b7a-5182-b3a1-0f319d51adde",
      "id": "CVE-2026-41293",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41293 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93663e06-187f-5a0a-8a7f-ed1dc23d1857",
      "id": "CVE-2026-42498",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42498 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e92c0e03-3f27-5dd2-bd67-7c5cc3eb789b",
      "id": "CVE-2026-43512",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43512 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d736e8c7-2e0c-5934-af76-1dd4f554c9cd",
      "id": "CVE-2026-43513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43513 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5225cc55-ea22-5333-87b5-72e932a77cdb",
      "id": "CVE-2026-43514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43514 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db8c8128-bb35-53c6-8b41-4004c03d9f82",
      "id": "CVE-2026-43515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43515 affects version 9.0.50-tuxcare.15 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.15"
    }
  ]
}