{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:522461af-8edc-5d1e-83a3-882cd020ce23",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-jsp-api",
      "version": "9.0.46-tuxcare.4",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:a420ca7c-e813-537a-b1b3-1c2284d96124",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fc84dfa-1297-5e10-bf88-c46ec8e291d4",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f0adb6c-8757-5feb-821c-50fe63feb597",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed68d2d4-d043-59e1-8381-3c6669ae199f",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76a6c9f7-8830-53d6-8d1e-c63f0fe2b91f",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17b768ac-c81a-5287-b31d-262039b83218",
      "id": "CVE-2021-33037",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-33037 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98b73904-f5ad-5f76-af05-845f8b24c228",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97432b3b-f2b8-5b1e-bc62-93f36015997b",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4853b560-3dc9-589a-aef6-75f5fcef9066",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7cd3620b-b619-5d86-a324-1e386bd7424a",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56d276e0-1631-54b6-ad75-a4dccc03f28d",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-34305 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13a013b6-8d63-5701-91af-bfeb524869bb",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b529535-a9e2-56f3-b9ed-1327baac18a2",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d0fa8c5-ba2c-55ad-a03d-f588da55248a",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-24998 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ad82101-4c3d-543b-9806-0041bf2a23fd",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09e6852e-6cb1-5d8c-a2ec-07d63dc9cebf",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2532184b-1dc5-52f9-b5c5-1a12621accf3",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-42795 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63c8f296-2bcb-5233-998a-8fae999d034a",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04c5744e-41af-56a2-8b2a-dfc84422be5a",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92cf7a57-182d-5d05-8c5d-9b4995b2d1da",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46589 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aaee7c8d-d537-5d9c-a686-e43d73947fdc",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:faa5f21d-115e-5bf0-857a-cfdf8e243685",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fc90d46-fc65-5979-b89f-094202083782",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34750 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:149bdbc9-ec89-5cf0-bf59-a6606aed5722",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75e79a62-02c5-5cae-b5c7-52b7fb7af273",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8bef97a-9ed6-57b4-96e9-65d7b415ff92",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4deaa4d-8ef3-5eef-b4cb-cd7eefcdc91d",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f90991da-d3f5-5f63-8d37-84be40e8957b",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56337 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63e55d8d-8d80-5077-8ab1-72d5f2b3cfee",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a10f585-1023-5dc5-90d3-bddb7087e853",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31650 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd363272-9f52-5551-af0c-c5225608743e",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20968f30-c6c5-52f4-800e-f7ca58325a71",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c109c8b8-c9e4-532b-aa86-7ff66fbd90cb",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72a27ada-6a97-572b-abcc-bb42e5fd2f3e",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf57bb37-4418-5bf1-af95-fa71111cdf99",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd0b7f39-2f97-5ce5-8fb2-7a0447a71867",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce721058-f831-53a0-b29c-9aa7a39fa161",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52434 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce2b413d-ffa5-5472-878d-827941cb564e",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53a17d1f-6859-5def-99bc-1276a0af305b",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3ef70af-0d52-5688-83a8-107783b480d9",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6cf7dc4a-6e76-56e2-b3b4-30b62042d3ba",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55752 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52291ed4-1461-5d68-a00b-db37d5f46c18",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f96ae4c-d679-5e78-bbc3-53bb4b3898b5",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abffc441-042c-57ec-84da-1b2c3af0f1e6",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c536b086-8fe7-5d2f-a40f-4cd418a97180",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3daee12a-c1a4-5601-877e-e178fd56ef70",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:889a8eb1-8f7a-584c-a9f7-0a2f0dc4a90a",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1827884c-992f-5094-b3a1-76dad82f436b",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10feddf4-0ec9-5450-a03c-b5d60367578d",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c6c7e82-6ba7-5848-a1a0-e9a7cff6e1ae",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f33d119a-603f-5cd2-9014-bb2ed9cdc5fb",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.4"
    }
  ]
}