{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b6fd9b4e-1632-5ed5-87d1-022a500de55b",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.1",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-jasper-el",
      "version": "9.0.100-tuxcare.1",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:8d8be56d-2a65-54b9-93a4-0cbc06e99069",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e75513f-423b-578c-a32c-9aba1b34b032",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b2bcbc0-d052-58cc-b0d9-5c0e9ff8d0c7",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3ab2aa4-dd1a-55f7-a274-6cf9886f6ed2",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fb9883c-58b7-5512-80dc-fc5c829ddd6f",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7d25f1b-50c6-5979-b432-7a6540c2b9fc",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6601920d-75d2-58e1-b773-d0673ec976af",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c760bc21-103e-5d0c-99ef-be699872aece",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c35fe5b2-65a2-5a34-bf18-52ad3bacdecc",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e53f4cf-6946-5545-b716-59a144488a33",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:612a218d-49c0-5c7a-b297-3f8e62cf20c0",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52316 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:795f2bd0-f161-51e1-909e-2711e640b070",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7605d3f-7c8a-5264-8014-c44220130ff3",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3bfa7f98-be7b-5a95-8e6f-ba4fac3c631b",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1783285e-3f23-5eb3-9193-42fceabd2217",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48988 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ce53002-fa36-5969-b1e5-6cea69eca48c",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87341cf2-d537-5255-92e9-143ac05cddb3",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1dd433a3-ac75-5b31-9737-9bc896ec3fe7",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bcc7f8ce-5c9c-5589-b2df-ffb04e3aa004",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18c1fa8a-a399-5b6a-9ebd-95b41a81a97d",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c881dcb-bfe3-575c-8657-11a1f469e750",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6bd535a1-e3be-56a2-aae8-f4dc847ac5a5",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71bb12be-6b35-5ab4-9591-92133c7b0d80",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37d42374-2254-5a7b-9ce6-369ff38b4d23",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a308e9a-ed7a-5274-9683-8222381686c2",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7665eae7-bebd-581f-9d78-79ef9f3d291b",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44d5a301-1c29-5f24-bc2b-a853321c4b81",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:791b2da1-063b-5020-bba2-30468201f970",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d60da818-8941-5270-aa56-240de67b0b4f",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c01c9be4-77a0-5f9b-b566-521f8c547890",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ec7d871-013f-55f9-aee8-e4fdf147f829",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29ea6e5d-8523-502a-98e0-e20b751941be",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39a84bb4-72e9-58a2-87f5-09efeda911dc",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f57a5918-c88a-5ffc-9a0b-ea42413d0a91",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b127c1c8-eb1e-59bc-b1b8-fe727115f9a8",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0035d1c-9854-5259-92fc-7e9001342df2",
      "id": "CVE-2026-34500",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34500 affects version 9.0.100-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.1"
    }
  ]
}