{
  "@id": "urn:uuid:2538cc63-8eb3-46a0-a9b9-9e06fa39a4b2",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-24T09:31:26.931840+00:00",
  "statements": [
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-11996 does not affect version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api. Version 9.0.50 is not vulnerable. Summary: The target repository contains a functionally equivalent fix for CVE-2020-11996. While the implementation differs from the provided patch, it addresses the same performance issue using a more efficient approach with ConcurrentNavigableMap.subMap(). [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2020-11996"
      },
      "impact_statement": "Version 9.0.50 is not vulnerable. Summary: The target repository contains a functionally equivalent fix for CVE-2020-11996. While the implementation differs from the provided patch, it addresses the same performance issue using a more efficient approach with ConcurrentNavigableMap.subMap(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-13934 does not affect version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api. CVE-2020-13934 affects Apache Tomcat 9.0.0.M5-9.0.36",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2020-13934"
      },
      "impact_statement": "CVE-2020-13934 affects Apache Tomcat 9.0.0.M5-9.0.36"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-13943 does not affect version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api. Version 9.0.50 is not vulnerable. Summary: Target repository already has the fix for CVE-2020-13943 applied. The maxConcurrentStreams check is correctly located in headersEnd() method, not in headersStart(). [terminalized not_affected from patch_application_manual/not_vulnerable]",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2020-13943"
      },
      "impact_statement": "Version 9.0.50 is not vulnerable. Summary: Target repository already has the fix for CVE-2020-13943 applied. The maxConcurrentStreams check is correctly located in headersEnd() method, not in headersStart(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2020-9484 does not affect version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api. Fix already present in baseline since 9.0.35. Verified in java/org/apache/catalina/session/FileStore.java:303 \u2014 canonicalFile.toPath().startsWith(storageDir.getCanonicalFile().toPath()) containment check is in place. Advisory range 9.0.0.M1-9.0.34; 9.0.90 is well past the fix.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2020-9484"
      },
      "impact_statement": "Fix already present in baseline since 9.0.35. Verified in java/org/apache/catalina/session/FileStore.java:303 \u2014 canonicalFile.toPath().startsWith(storageDir.getCanonicalFile().toPath()) containment check is in place. Advisory range 9.0.0.M1-9.0.34; 9.0.90 is well past the fix."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-24122 does not affect version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api. CVE-2021-24122 affects Apache Tomcat 9.0.0.M1-9.0.39",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2021-24122"
      },
      "impact_statement": "CVE-2021-24122 affects Apache Tomcat 9.0.0.M1-9.0.39"
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-42340 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2021-42340"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2021-43980 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2021-43980"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-23181 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2022-23181"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-29885 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2022-29885"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-34305 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api, and is fixed in 9.0.50-tuxcare.15.",
      "vulnerability": {
        "name": "CVE-2022-34305"
      },
      "action_statement": "Vulnerability CVE-2022-34305 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api, and is fixed in 9.0.50-tuxcare.15."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-42252 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2022-42252"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2022-45143 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2022-45143"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-24998 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2023-24998"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-28708 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2023-28708"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-28709 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2023-28709"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-41080 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2023-41080"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-42795 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2023-42795"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-44487 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2023-44487"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-45648 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2023-45648"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-46589 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2023-46589"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23672 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2024-23672"
      },
      "action_statement": "Vulnerability CVE-2024-23672 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-24549 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2024-24549"
      },
      "action_statement": "Vulnerability CVE-2024-24549 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-34750 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2024-34750"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-38286 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2024-38286"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-50379 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2024-50379"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52316 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2024-52316"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-54677 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2024-54677"
      },
      "action_statement": "Vulnerability CVE-2024-54677 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-56337 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api, and is fixed in 9.0.50-tuxcare.12.",
      "vulnerability": {
        "name": "CVE-2024-56337"
      },
      "action_statement": "Vulnerability CVE-2024-56337 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api, and is fixed in 9.0.50-tuxcare.12."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-24813 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2025-24813"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31650 does not affect version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api. 9.0.50 predates HTTP/2 RFC 9218 PRIORITY_UPDATE frame support (added in 9.0.76). Advisory range per NVD/Snyk/GHSA is 9.0.76-9.0.102. Code inspection confirms: Http2Parser.processFramePriorityUpdate method and priority parsing in Stream.emitHeader do not exist in this baseline. Vulnerable code path is absent.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2025-31650"
      },
      "impact_statement": "9.0.50 predates HTTP/2 RFC 9218 PRIORITY_UPDATE frame support (added in 9.0.76). Advisory range per NVD/Snyk/GHSA is 9.0.76-9.0.102. Code inspection confirms: Http2Parser.processFramePriorityUpdate method and priority parsing in Stream.emitHeader do not exist in this baseline. Vulnerable code path is absent."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-31651 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2025-31651"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-46701 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2025-46701"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48988 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2025-48988"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-48989 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api, and is fixed in 9.0.50-tuxcare.14.",
      "vulnerability": {
        "name": "CVE-2025-48989"
      },
      "action_statement": "Vulnerability CVE-2025-48989 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api, and is fixed in 9.0.50-tuxcare.14."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-49124 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2025-49124"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-49125 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2025-49125"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-52434 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2025-52434"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-52520 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2025-52520"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53506 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2025-53506"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-55668 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2025-55668"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-55752 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2025-55752"
      },
      "action_statement": "Vulnerability CVE-2025-55752 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-55754 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2025-55754"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-61795 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2025-61795"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-66614 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2025-66614"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24733 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2026-24733"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-24880 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2026-24880"
      },
      "action_statement": "Vulnerability CVE-2026-24880 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-25854 is fixed in version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2026-25854"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-29146 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api, and is fixed in 9.0.50-tuxcare.13.",
      "vulnerability": {
        "name": "CVE-2026-29146"
      },
      "action_statement": "Vulnerability CVE-2026-29146 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api, and is fixed in 9.0.50-tuxcare.13."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-32990 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2026-32990"
      },
      "action_statement": "Vulnerability CVE-2026-32990 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34483 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2026-34483"
      },
      "action_statement": "Vulnerability CVE-2026-34483 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34486 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api, and is fixed in 9.0.50-tuxcare.13.",
      "vulnerability": {
        "name": "CVE-2026-34486"
      },
      "action_statement": "Vulnerability CVE-2026-34486 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api, and is fixed in 9.0.50-tuxcare.13."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34487 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2026-34487"
      },
      "action_statement": "Vulnerability CVE-2026-34487 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41284 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2026-41284"
      },
      "action_statement": "Vulnerability CVE-2026-41284 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41293 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2026-41293"
      },
      "action_statement": "Vulnerability CVE-2026-41293 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-42498 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2026-42498"
      },
      "action_statement": "Vulnerability CVE-2026-42498 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-43512 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2026-43512"
      },
      "action_statement": "Vulnerability CVE-2026-43512 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-43513 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2026-43513"
      },
      "action_statement": "Vulnerability CVE-2026-43513 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-43514 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2026-43514"
      },
      "action_statement": "Vulnerability CVE-2026-43514 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-43515 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2026-43515"
      },
      "action_statement": "Vulnerability CVE-2026-43515 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-65182 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2026-65182"
      },
      "action_statement": "Vulnerability CVE-2026-65182 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-65905 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2026-65905"
      },
      "action_statement": "Vulnerability CVE-2026-65905 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11",
          "identifiers": {
            "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.50-tuxcare.11"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-68525 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api.",
      "vulnerability": {
        "name": "CVE-2026-68525"
      },
      "action_statement": "Vulnerability CVE-2026-68525 affects version 9.0.50-tuxcare.11 of org.apache.tomcat:tomcat-jaspic-api."
    }
  ]
}
