{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:cb3efd05-bdc1-574c-960c-02ea0fa965e6",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-el-api",
      "version": "9.0.50-tuxcare.14",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:7e5964f5-6a10-57c5-b743-922755e7ea8d",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-11996 does not affect version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api. Version 9.0.50 is not vulnerable. Summary: The target repository contains a functionally equivalent fix for CVE-2020-11996. While the implementation differs from the provided patch, it addresses the same performance issue using a more efficient approach with ConcurrentNavigableMap.subMap(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a02da0ef-039e-5165-bc43-cd42470349b4",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:788c46ac-212b-5285-9599-f2ff5c9a857a",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api. Version 9.0.50 is not vulnerable. Summary: Target repository already has the fix for CVE-2020-13943 applied. The maxConcurrentStreams check is correctly located in headersEnd() method, not in headersStart(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5af39bde-26e5-548f-af63-5ff9cb178561",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-9484 does not affect version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api. Fix already present in baseline since 9.0.35. Verified in java/org/apache/catalina/session/FileStore.java:303 \u2014 canonicalFile.toPath().startsWith(storageDir.getCanonicalFile().toPath()) containment check is in place. Advisory range 9.0.0.M1-9.0.34; 9.0.90 is well past the fix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1e4cc55-703e-5d94-8c9b-6011a024cbea",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7e387c6-6332-5217-a552-7bcc725e3289",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f6484c2-313c-5fb0-b265-bfec3ee658f2",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d783ef5e-5855-5ee3-a5fb-ce67c61eb672",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4dbae313-4a4d-535e-9678-3e02a1e42086",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab5c10f1-0b33-5e6d-a139-7487dab9c429",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5319d3ce-08c3-5c5f-8465-19c08c313c51",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8aae8f82-ab53-5bf7-89d7-4a36c0852415",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b7aa8e5-85e5-5c27-998d-bfd74802f6f0",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-24998 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ede5e551-96e1-5631-bb9f-894c526c00bb",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f95bfcf-a718-5676-9936-ec3aa2c2827c",
      "id": "CVE-2023-28709",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28709 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f44d9de-f76b-5118-b6d7-2c61e048d6f0",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92759d7b-f074-592a-bc3d-19d8f151f957",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42795 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8802e468-5c46-562a-88f3-326190be11fe",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ff8c6f2-e8d2-57aa-bf19-d5b1ec32b7f0",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da8445fa-1aee-5399-8a67-0cd26c858b16",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-46589 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2afe1a41-7f21-508c-a420-57caba787d36",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7e25858-6b86-5d98-9f70-646a8ac49e2f",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3b9fbff-a7e5-5eca-a16f-b5c3103efba7",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0d346f8-ebea-5097-b991-10c4e6ea10b4",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e0896df-ad9e-526c-8ad1-e4b565854a6c",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:579b9575-82e7-5248-8eec-b0b2b647a8ee",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bfe8917-0958-5173-ac83-79d8c548f520",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83c05af9-58e1-5f26-97d2-6b43a8c53354",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a29f76b1-5123-5368-8b27-8de90f4d13a7",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0264338-46de-5de5-953d-bba5cb227dbd",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-31650 does not affect version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api. 9.0.50 predates HTTP/2 RFC 9218 PRIORITY_UPDATE frame support (added in 9.0.76). Advisory range per NVD/Snyk/GHSA is 9.0.76-9.0.102. Code inspection confirms: Http2Parser.processFramePriorityUpdate method and priority parsing in Stream.emitHeader do not exist in this baseline. Vulnerable code path is absent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56e2cf5d-0b0e-58ea-b34a-cd6cb1f94ba4",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cdfa834e-ca4c-5f97-bb57-626497fb8508",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a8d774c-c3be-559d-812f-ac71384245a0",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6902854d-d7ab-5911-bc70-9a4cef85378b",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21155d9b-9471-55dc-8ae0-5cd4f3060c74",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f99660d-f7d1-5304-bb3c-a8cfc004091f",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3203f49-f15e-5131-b285-709ab0f32cab",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97b7c2ef-aa57-5ad1-88bd-693d29083501",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7cbecb0-6035-5dee-a71d-6cb724dcab6d",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:830dd7fb-834f-5c14-aed7-8f2ee3353add",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25bc7612-2427-5600-b762-62cf6ca3ca6e",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebabdde8-73a6-5a99-907f-24367a841143",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1610db75-cf6c-5ad6-80ab-58341b4638ca",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6202520c-f744-511f-b97d-39112d3c2b1e",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b75bc5a9-4d07-59f0-b73f-05d7ac05462a",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7930fb29-e7a0-5e83-a3d3-91e670c3efd4",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d9548b4-5b2a-5e59-b915-362f214b1653",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66f10ee2-6beb-56a4-99bb-adb9a346a3f0",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:350c5449-ae03-5359-9460-d1a3903629e5",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59cdef12-7799-5796-87cd-56f370f4eb72",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58dd168e-6dfc-5070-bfc1-8f7853cbe6a5",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34486 is fixed in version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c7c93e0-5b31-5b28-9ee5-7b231bf39918",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48422beb-6ac4-56d7-8fa1-fcd6885bb77f",
      "id": "CVE-2026-41284",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41284 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e800c2e-0ea0-5b5c-abc9-a73011df6e14",
      "id": "CVE-2026-41293",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41293 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3ec6886-0b46-5c6a-b491-32dc7f3dae7b",
      "id": "CVE-2026-42498",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42498 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ef89543-431b-545c-9584-f2dd899cc8bc",
      "id": "CVE-2026-43512",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43512 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e79c564-8b56-59fd-9767-34614c4b1891",
      "id": "CVE-2026-43513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43513 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41ebd33a-f894-5456-977f-19c3d9bb3d23",
      "id": "CVE-2026-43514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43514 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3d04945-53a9-55a6-a1b7-43133c0082f3",
      "id": "CVE-2026-43515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43515 affects version 9.0.50-tuxcare.14 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.50-tuxcare.14"
    }
  ]
}