{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:52d1162a-d7ec-591e-8090-9cf8cf57b5d7",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-jasper",
      "version": "9.0.50-tuxcare.3",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:ba5e8a3a-a91f-5679-b688-d5963bce6650",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2f932d6-33ba-542c-8e87-2ec726cdaa15",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2a1477f-7237-51dd-9fc3-fa73b754b8ca",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95e18eab-f3f0-592b-9760-9297637afe63",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ebf4f03-bcda-5051-990b-1da771e93b4f",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2dc8e429-ecaa-553c-b6a2-976bb02e4603",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89d3c4f8-eb40-55da-a5ac-210958bf0589",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31cd933d-e716-5b3a-8796-9e1ea58de15c",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:262447a1-011f-5108-82b4-eadd24ee8d8f",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-29885 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a13eb515-2c8c-54fc-aa7f-9a6c56ae8c3f",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9692d85-9b6d-59c2-a682-94a05b917dca",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc1afb70-60fd-5303-a6ff-70660b292d53",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:615238c9-f25f-5097-a599-a8ba5203f013",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-24998 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73dbf946-48f9-524f-be79-7dba39f0be85",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ab8fdb7-b3e6-59c8-94a6-15d93b582737",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0a91a18-88f4-5490-807c-52081abe6ed2",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42795 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1df714db-e0aa-52cd-b1f0-13f35cf21431",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f36dfc69-46fe-5ba7-940d-4166545b8c91",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e58f5a66-1410-55fb-a0bb-4287447e7183",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46589 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75b3878b-e73d-5e56-8149-b53237c03ebd",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:769cfe59-14a5-5e75-b112-206564ad12d1",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:327d0ee4-3997-5564-a78c-56b4fb2aae39",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34750 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:969d4169-89f8-5c82-aac2-c34fbff160e0",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03b89007-b4f2-5638-b618-05111702d50d",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0465f900-2ad5-5079-87f1-04c4a3274d86",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23227772-86f2-5f95-851c-e47c08b0b9fe",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f1380fa-7128-5ffb-b8e4-30f61a455ca2",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56337 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fda3b437-e252-5227-acba-eb06a3eac1fe",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1dd8a83-4675-5086-8d00-23f03850c23b",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31650 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b75887b7-3981-5661-b376-c3c539c89950",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31651 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81163c0e-1e3f-5e77-b165-184e83839585",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-46701 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52e82534-d52f-5edb-9798-04782fbd9e78",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58e1643c-1370-543b-a876-7fcdf8242aa5",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48989 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d6130b8-9069-5470-b61b-c702cfafea15",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f4b9bfa-8a8d-59e1-83ec-f6995de67c5c",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2174133e-d78a-5515-b269-a1fe48f32f91",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52434 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a791f971-4f7d-5114-99fb-92c269fc4561",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d90f155-6a38-5efd-8a31-69d0bb024784",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0469fd9-c882-5d4c-a7f4-cf4a1f7111be",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:793e5528-814f-581f-97f6-6c1929f1a204",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16c6e8f9-c9db-5634-8f0a-0fe995db0481",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9dbe034e-3c72-5732-bc30-6543814629cb",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7920bbfb-71b7-571c-bdb0-3461a26ae92e",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd01bc2f-cb79-57e4-a479-00183adf4f32",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a63c4557-0329-5eda-9ea0-3a83c9cf2533",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e94a4f71-a976-553a-b245-2a9589034636",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe95d657-7fa7-5fd2-be15-f8f03ec06a1b",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bcf16bb3-94d2-5c32-9329-05ee2c76a878",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abba5eb2-b2c3-507a-a6d6-8fbc004b9d9c",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08aadd38-71e7-5c52-989a-c0e86a6eb139",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.50-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.50-tuxcare.3"
    }
  ]
}