{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:01f782cc-1d53-5394-b50b-b480b7319159",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-jsp-api",
      "version": "9.0.46-tuxcare.5",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:de3a6955-5595-5cb5-8a4c-450ac673afbe",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a95b199a-677f-5b9d-8f58-c2c19b0ca790",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cef13630-6359-5b13-81c1-54307b630a4a",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2c30c2e-d7e4-5799-ae42-ea2e99c439f6",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4cd64517-64c3-53eb-b576-20545c01d514",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abbb3917-7e32-5f18-83f1-239b861ed4aa",
      "id": "CVE-2021-33037",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-33037 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3731312f-5bdb-5453-bab3-5fe000679642",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24578be3-41ea-523e-b765-21f7cd154038",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d4be996-3d07-5cd2-9a88-372c6dddae6b",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a46f5f5e-0432-5bfa-9b62-ed8cfd36b271",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-34305 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ed27bd0-9591-5c9b-9b82-9e24e8c2920b",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b18ecc2-3060-585a-8e6c-b3b70b3e270c",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd389dce-d0f4-54a3-9bef-a8a77c8b209e",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-24998 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1d860d2-128c-55fb-8b36-a016b386b115",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec1ea688-1358-5549-b049-3a9d2d262781",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7927ed95-183e-5b5a-ab6e-ee29c7098988",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-42795 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94856613-41f5-588f-a522-84a5f877d6b9",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13881c13-8200-590e-b674-645fb1a9c0f6",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ada70a9-b575-5e2a-9ee9-4de899739c34",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46589 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5166e4ed-5a8f-5473-8c28-98c70d92011d",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85cf1cf7-a082-5a98-a0ab-9a6854d8665d",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7dd7459-e185-5ab4-b80b-7f7646730d16",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34750 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:deb6b0ab-5b8e-56ca-adb8-e5daa2b8c768",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a269ffba-4564-52c1-bd67-ef6330d4090e",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d0aaa38-0020-5dc1-b932-6c111c422ee5",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e17fd99-819e-5615-a939-acb2e7bb55c8",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5cd213b9-1711-5791-9330-df8d4dd08034",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56337 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:210737c3-c10b-5c52-b1a9-8bc907b558ac",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b64df98d-1b31-5fd7-93a2-b223fd6e2d66",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31650 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:909f3ea7-e77e-547e-8ac6-3e5895c2c127",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d00d0aa-253c-5a1e-8fac-ab34f9074aa1",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14c0ba2b-8ad9-5bd2-8a50-d14495b8e77c",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:487d9d05-a5c0-544f-92e0-b054ed7ff6a7",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38b8547f-6400-5e44-b326-6729abc42f14",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4741f655-698f-5a85-b6c4-23af18c70a95",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75861574-b8fb-57bd-920e-f84f07fe3651",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52434 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:615ba382-c413-5558-861b-766576288809",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed64ffbb-fcd1-54bd-a1f4-f5f416c144d9",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:751d742b-a6c5-58c9-a843-3202ec13d869",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09ff7848-232f-53e9-8378-39e166cc616f",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55752 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e11f8a73-4853-503f-a40b-96e6d5ddbb95",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b993e44a-5f56-524e-8610-ae5bb85b4aae",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a55f20a8-1637-5824-aaf8-9f7845accd3b",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf10402b-0e09-5208-a61d-2b26bb191d6e",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abd1365c-efbf-5e42-8e3c-8712d546fd22",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e60046b3-5f26-5cb4-a505-4d3dff6daedd",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1b59cf9-dbca-56c9-b05d-5205d8184b66",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c288f90-cb7b-523c-aa9b-0b2744bd5d18",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5cea634e-e4e1-5f81-a6d7-fea039b120a4",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fbf56a7-52cd-50b2-b059-2870a15e62ee",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34486 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9acdbbca-9f0e-5d22-84ee-0cd99ae77ed9",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-jsp-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-jsp-api@9.0.46-tuxcare.5"
    }
  ]
}