{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:0362aff5-bd4c-5fcf-b663-f474587cb43f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-jsp-api",
      "version": "9.0.50-tuxcare.12",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:01bec8e0-bddc-5c36-b696-ca576b8345cc",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-11996 does not affect version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api. Version 9.0.50 is not vulnerable. Summary: The target repository contains a functionally equivalent fix for CVE-2020-11996. While the implementation differs from the provided patch, it addresses the same performance issue using a more efficient approach with ConcurrentNavigableMap.subMap(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81c2a954-536f-56dd-a121-cb0e04793fb7",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb5c4caf-5a8c-5350-8bb2-847984d141ed",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api. Version 9.0.50 is not vulnerable. Summary: Target repository already has the fix for CVE-2020-13943 applied. The maxConcurrentStreams check is correctly located in headersEnd() method, not in headersStart(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7459621-1f4b-544d-bfbc-d985ea4dfb59",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-9484 does not affect version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api. Fix already present in baseline since 9.0.35. Verified in java/org/apache/catalina/session/FileStore.java:303 \u2014 canonicalFile.toPath().startsWith(storageDir.getCanonicalFile().toPath()) containment check is in place. Advisory range 9.0.0.M1-9.0.34; 9.0.90 is well past the fix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:081002e7-a687-5121-b47a-bc36f0f377ef",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b07adfa-9b2c-575c-a1c9-a36dd86bc053",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0b5e1c6-16ac-5b7d-87f9-1809da875877",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca47eb3a-6336-520e-b989-617bfcd57c16",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:012b8813-87c6-54a6-840b-a756a3ab31e7",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8024b63b-7337-5cd4-a456-4449929a8a09",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8a5c805-b707-5a43-b651-7f781f724707",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c510a147-7f6d-530c-a095-0fb3a2721ae1",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb48ed9f-7f48-51ce-90bd-333d9a1e8221",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-24998 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1340fa3-b135-5d0d-8a64-00e22b5b9d2a",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:122ea695-ab7f-5187-a7cb-dda0fb68e3b4",
      "id": "CVE-2023-28709",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28709 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ecf06575-44d0-59bc-8214-2b57fb09d338",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b95b85a9-bc86-511e-a66c-bb95a9a47101",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42795 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d750fcf-e206-5b62-8ed0-9a74a39efaab",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a72b320-3841-5524-9ed0-46c2c0cd8a59",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d789a70-78e3-5cb0-9f03-97e352d4f95e",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-46589 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e23c40e-a50e-560e-85c8-2a846888514b",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8735fe4f-01bf-5631-ac54-da1805d99c56",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef415273-80f7-58b1-a7d6-e1e2ee33e964",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efe7e4c6-8e43-5faa-b56e-0f810d2ac5c0",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e0c2c8e-4e32-537d-a380-1a566d74565c",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2552036-46a0-5f70-ae42-8cd6338b74b1",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15868b6d-4f7f-5bbe-a5d2-9a3e76c4df67",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86e5c45d-56b9-5b2f-aa1a-ab11d8e45717",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:526aa3d0-bc26-5bdf-8f71-ca47aa199158",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9970f0c-4f54-5cae-9c3a-7d8ac00530b3",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-31650 does not affect version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api. 9.0.50 predates HTTP/2 RFC 9218 PRIORITY_UPDATE frame support (added in 9.0.76). Advisory range per NVD/Snyk/GHSA is 9.0.76-9.0.102. Code inspection confirms: Http2Parser.processFramePriorityUpdate method and priority parsing in Stream.emitHeader do not exist in this baseline. Vulnerable code path is absent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd83cd2d-d861-57fd-9606-c182250d7a84",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0bd53a20-e031-582e-a485-057f6c57e044",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19bf338d-5341-56e5-a1a2-15c6aadd7780",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14104836-11f3-5a12-b05a-7105dd29135d",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48989 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcf6ecf8-939d-5e10-85cd-c596937ab3c5",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1b66424-ebba-5668-8480-353375d0023b",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c4b1c60-a9d7-542f-b07b-f7f3e3e4a48a",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00c955c2-9d4a-5d57-a3d9-fdf4b1713dae",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31adc0fe-7497-5705-b42d-5841159268a6",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75e893aa-9265-5ab4-ae5f-450d6a000317",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd4087d2-ac78-5222-8f9e-8a380b7ce8d2",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e01ec43-930d-54fd-8e96-cafc40ea72dd",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48ce85a3-3c34-5bfb-b432-a8c50d66bf3a",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69ea6e45-2895-559e-a457-25cdfecd58c7",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afd513fc-62c2-581c-af13-07d115377c98",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e3873ff-7fe4-5d6f-84e9-24b92e7fe9f1",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2df8c96-bb4a-5f19-a828-ccfd91c77251",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a87d4dc-ce2f-5414-ad95-617885740515",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9fcd08b8-5fe0-51f8-b480-5901cfc204e0",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86bff979-2394-5de2-8b7e-5ac7141ce678",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6822eb4a-2080-5fd8-980e-4e04fce3378b",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34486 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4135e522-0b71-5ae5-897c-2aff6c0a721a",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1eba25c6-bf5f-5a08-a370-6c00935966fe",
      "id": "CVE-2026-41284",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41284 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:574a198d-5caa-56f3-90f1-5b2f53d07411",
      "id": "CVE-2026-41293",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41293 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9ad25b9-2e68-52ab-9d1e-5e119dab4414",
      "id": "CVE-2026-42498",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42498 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe99d107-2398-5f19-8697-22a7d0772b6d",
      "id": "CVE-2026-43512",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43512 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f4b2cca-d215-5be3-9c33-93cd44a4db64",
      "id": "CVE-2026-43513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43513 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55746581-6d9c-56d8-b82f-e3757cd7d01b",
      "id": "CVE-2026-43514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43514 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:518ca196-fd0b-5504-8572-bf7d682d7148",
      "id": "CVE-2026-43515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43515 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.50-tuxcare.12"
    }
  ]
}