{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:caa67084-bee9-584f-a23d-d663536e0f95",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-jaspic-api",
      "version": "9.0.46-tuxcare.3",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:8ea0830a-caf7-5504-b987-905ebae98dca",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bcda0660-cc19-5da9-8fe5-4851d17548a4",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03240abc-ad43-581b-8145-9a16891a735c",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1eded632-0b72-5b22-9290-4e40c14dfb68",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9fdfc8f1-1b8f-560d-a4cc-07428120ed45",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:780fcbe0-7f05-57d1-a5eb-bb129f5c9c22",
      "id": "CVE-2021-33037",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-33037 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93595152-02a1-5edd-9cdd-37962f570839",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f3a102a-aa6c-592f-8abc-9f6b8a4482db",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efb68478-3f05-5fa4-b131-9856a80997a3",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f956bdeb-b85c-5bfa-aa88-204b430b6dde",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d91d666-d0f2-5a39-9bfe-3ebc68249996",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-34305 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d07d958-4667-5021-ba40-aa6af55ec4c6",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b987c325-7f9f-5577-a647-b5b62d84274c",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17f5b552-8e2c-5b98-9e2e-cccc5b3de8ff",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-24998 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15473aa1-00ce-5ca7-9c0d-5bea12315919",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:938ba97d-2f67-5238-97ba-b1fb7323bb4f",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f98392e-ca6b-5c37-9f10-913a5e05c2fe",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-42795 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b502d169-a1c8-56c3-ae8e-bb52f3d1d73a",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ec5b191-3f00-5d11-8fd6-bae9d8b84469",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2c8ceaa-28be-5a80-b6e3-b835cdf7f316",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46589 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4eb9b78-ebcc-588b-8b63-d19855aa6954",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38d61013-196a-5fb3-8795-0f1a9a714149",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b6a858d-cb5d-53af-96d2-b963f3c69ec1",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34750 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06ac9f1b-fe7b-5c8b-a3c0-8d1fe72cecf2",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aca8b8ad-3834-57a9-8dc7-21307df111ab",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50b4459b-65fd-571f-ab8e-aefe0b6dc250",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:193cf5c7-ded4-5408-a303-7673f1472a67",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69502d3d-92df-5ecd-af60-90d25d25343c",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56337 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:361859f6-7f07-58c8-ba6b-f74f385b17be",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec812869-01d0-52bd-b9b3-546e636a62c3",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31650 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e44fbce-4313-51c5-9760-a896dbe0c65e",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6aad3de3-3767-5bfa-9be7-ebcd5f88dfda",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58d21557-f87e-5d80-bd09-a6229090c10b",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48988 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d72ef840-8f1e-5bb1-a12e-00dcea10108e",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4c5f624-0e24-5b76-b166-0bb09ffe48a2",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e54c1f1-00d0-58a1-b743-789148f9a783",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48118a97-d05c-5642-95c6-df003123b7db",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52434 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37f57e5a-26d1-51ec-b493-69cda76ba9ec",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2995e2c9-cc2e-595c-bb74-cdb6d02074b1",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e356e3c9-8618-5086-8c45-6a4740ff44a4",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75b4222a-830a-5299-a39d-a0537d311d1b",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55752 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81e2f09e-997e-51e5-be5f-26c2bdcce830",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f74fc0c-ef00-50c1-a88b-8eb3b664824a",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df44bf71-027a-5946-8178-730dc25caf09",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c10a0ca-1590-5615-a5f7-4a9d82568699",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:304dc123-69bb-5999-8fb6-beb9e9a4d771",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02d5eaa2-2bd7-55e0-8ee6-46b04c8dc324",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:390b956d-4614-5dc4-9832-d4dca5345d02",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d226eb05-4f09-5120-a45f-fa1bb8e0d315",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:134c5eee-1289-5b87-a902-ec7c7a40c90b",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:acfc4601-014d-5223-ac76-d5db6e533541",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.46-tuxcare.3 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.46-tuxcare.3"
    }
  ]
}