{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:2b687f0d-be08-5981-be0a-c6a7b6eb962d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-jasper-el",
      "version": "9.0.46-tuxcare.2",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:7096584f-510d-5909-a6de-addbbb841a22",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2fabe03-ed86-5150-8036-628889a870f3",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce7e300c-63bc-5fcb-a8f5-112f2607f680",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7e632dd-186b-524e-975f-91ba9b421d68",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0513954-f86e-592f-8831-95c3139e47d5",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60cba8e9-abd7-585f-b3fc-0fe24349c98e",
      "id": "CVE-2021-33037",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-33037 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:967aa009-91e4-5082-a237-fb982dac138e",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b318527-99a2-5883-81da-1c64a6b01f0f",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3ffd426-f7b5-5f97-b549-0dad4a495fa8",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dad92b8b-4298-55be-91f3-d3ebc8512c2e",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e604184-af4f-58e1-bf6d-2929cd317ea0",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d8ae88d-6b4b-5d0b-b45f-b954cedfad80",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a06fbc2-9359-59ef-9fb6-d11d39154f1b",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ab74438-d7ca-5c4b-b6a8-0437e9dc7414",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-24998 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:497f9c18-b045-5ef4-ac79-358921f10104",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96cb8d35-5ede-50f4-8a3d-78d4140674df",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30b06c08-facd-5ba3-9d34-451890db3b20",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-42795 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c819833d-0962-52e3-9a95-97c1cf781ab2",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3aeee7b-6aae-50be-8914-cfba08f3a26e",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34624fbe-d67f-564d-bd82-7b1353c3dd4c",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46589 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8002ce2d-4cf4-5f04-a44a-3437ac17ced4",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d47ccdeb-a32f-51ff-9052-367e2298619b",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8042e89a-ca91-5e63-a47b-e20c1b8e945a",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34750 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5bfd8bc-3945-5cf4-88ac-becc5be71099",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76be4772-3ef7-5ff2-9d3d-2d492c4a3a08",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7edaf6c2-a187-50bb-b065-4080ab32fa9d",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f80ab46-2810-57f2-9bbc-8dbcfa673db8",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79bdb74c-9315-532d-bb06-88ca02667c4d",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56337 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f7bcf11-9190-550f-9943-396c70889f3b",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c5e7a7d-486f-539a-8f47-ffbafa989ec9",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31650 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c9eea1f-b213-5fd5-a2f9-7539adbf0993",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9295bb63-541a-5f07-b86e-6d45ab68a44f",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-46701 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f469de4e-12ac-5de0-8643-1fdf7315b9db",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48988 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97e94eca-f635-56fa-a764-143cb799abc9",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d529936f-6852-52e1-b847-56007106d6f3",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2135fa51-790b-5ad1-8ed3-f5600f30e1bf",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09661d8d-f9ee-51d2-a698-12667bd2ff48",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52434 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d9d7c86-e904-5633-88cd-5b38cc2dcbcb",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0abfbf70-9317-58e1-aa95-2253eb539a86",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da7837e9-e4c9-566b-85a2-b226cb109a64",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ab6edaf-9fc9-5b98-ae3b-532a43c2d2e4",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55752 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71b58faf-1030-5eb8-a10f-cc8d499e9e52",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f72e0721-e992-5de0-bd02-e6f18ff4feb2",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d328306-ef61-5b5e-985d-f8887d61e8a7",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9384b27-0817-5aca-90ac-e0656e105ab5",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5732e51-3085-541b-9714-12c205e3347b",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c42c6b60-95f6-52ee-9130-5359310617ba",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fe89ed8-bb48-500f-9fe8-1dee56ca1f0d",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1bd2b4d-39b9-515b-9f1f-5f74f240b57a",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ed117c3-381f-5d3c-b2fb-86c868a740a6",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:814161f7-0048-548b-876c-7c8fbe3833a9",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.46-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.46-tuxcare.2"
    }
  ]
}