{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:862b14e2-d257-52a3-8b24-c3e2306ea81c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-jasper",
      "version": "9.0.46-tuxcare.7",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:2b88da8d-c2bb-5edb-b7da-0121d9e48d9d",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2fbb14a-9770-5fc9-8d92-f51d9981f72e",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9996ac3-fcf9-5bf6-b226-b885ef947ec1",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17de9a7c-4868-50c1-9c18-e4507728ecdd",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3a750ee-f7da-565d-829a-85c1a2f9e8ff",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10247b67-c99e-519d-a4ed-f60cdc089a31",
      "id": "CVE-2021-33037",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-33037 is fixed in version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3aac1af4-a550-51ef-9adc-0c79750d8db6",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:754a5152-4b01-58ac-b571-a88a846727d9",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:911e6e9a-a0cc-54e7-836c-15fe8878ac48",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c566edf-dc77-598a-b26d-f1d0f058ed22",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a499feb-fca1-55d4-ac24-50fea451dcbe",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-34305 is fixed in version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f9b45b4-835e-549c-8040-3d56395c5b34",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2da9cbc8-bae6-5014-9505-ddf9c92c5dc6",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b4e125e-e26d-5315-a81b-aafa4ff184f4",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-24998 affects version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c04c53b-3bbc-5f29-8107-de44fa569b92",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4fdd772-cb1d-558e-921d-40b00372ed6b",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e6ca6ba-86b4-5af0-9319-f8b591b86bd8",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42795 is fixed in version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac428fd0-e04e-5b63-b90e-bbd37666cc59",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9ca9031-5922-538e-9193-cf5f6e53210f",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab4acc25-f511-5700-a3d6-6c7f81cba231",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46589 affects version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fbf1ea0-47aa-5d1b-9942-8273e63d8b70",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbb86ed1-14f9-5c76-8aa2-fed2a369e015",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2690d6f5-d3e8-5537-beb4-7699970b8105",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34750 affects version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4811b0fe-60c2-5dbc-887f-88323f2ca0d1",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d43e386-8675-51be-ad69-3e859798931e",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9289b60-361f-5c34-b96e-48f52399fb06",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec501a69-6c0c-5e4f-bb69-ac1f1ef2bc14",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2033a99d-3f52-5ea3-b901-1cdb262e582f",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56337 affects version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a87cf7d8-5e9c-5283-b4d8-f26af8e605dc",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00cd0d66-78fb-5918-8cf1-a22932669f6d",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31650 affects version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1846fc38-5f99-5273-8e72-243a4a291511",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f0d0497-ac49-5f57-aede-75befa5202e7",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64de3832-6354-5917-8a9b-5cf22d2fc772",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d4bfda5-9ae6-5a3a-b761-089ae0f6d86c",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a96ca183-e500-5637-a33f-bafed6da6d1c",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:901aaf32-119a-5067-9539-62083d160ab1",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:482210b2-9ced-58f4-b7b5-ff4496d9291a",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efc38f84-7e37-56ce-aeff-4273aca4dc84",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:092d8931-b875-5858-b21e-a1beaa4de48d",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4db25012-c31f-5066-a4c5-d0649994d891",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9fece4d-68cc-5bc3-b0e8-1d04f6fcaa9c",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55752 is fixed in version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ce8641b-84d3-52ad-a6a8-c72cfba2a6c7",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83d745ec-b4bd-50c6-9989-992870486423",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74ad892c-b624-50e7-b0a0-2ff62a5f67f8",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3bef5af3-0db2-5004-b530-fd9a82098761",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9261cb8-b246-5a7b-8aa7-911d83ce7c6f",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c315f47-fbae-54a7-a1f6-ae973187bceb",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d91383d7-f701-531e-bfc4-57e0c4ef1aca",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74d3566c-47ae-57ae-8217-620853ba0e48",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5c88b24-b7b2-5f37-88fe-d1c810636a06",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5769b34a-329b-5522-ac1c-418fe9e2fa23",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34486 affects version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71c343ce-91fe-5042-8d63-5dcfdad9e713",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa61adf5-3dc7-5fbe-bafa-494e54192cf7",
      "id": "CVE-2026-41284",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41284 affects version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83803ebb-245c-5de1-a762-4fdb6dd98fdb",
      "id": "CVE-2026-41293",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41293 affects version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05a0e435-b0b0-5507-b8ee-c726db014a66",
      "id": "CVE-2026-42498",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42498 affects version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33237a97-4772-534a-b709-e2d937418585",
      "id": "CVE-2026-43512",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43512 affects version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01188421-e5df-501d-b6b7-4b79e6a1474a",
      "id": "CVE-2026-43513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43513 affects version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b448add6-73b5-5396-97e5-71624b86a3d5",
      "id": "CVE-2026-43514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43514 affects version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d33c7ac-e993-5ec7-b72d-942717c95f2d",
      "id": "CVE-2026-43515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43515 affects version 9.0.46-tuxcare.7 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.46-tuxcare.7"
    }
  ]
}