{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4a3cabb3-11a6-542a-9ee9-4a91578da447",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-el-api",
      "version": "9.0.46-tuxcare.6",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:bc9dd8ca-31fe-58d8-a7bb-899139c5df5b",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74eccbe3-2caf-5dca-b1c8-02592df1dff5",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:779a940d-46ee-5e75-be9f-947f5b7e2ebb",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:240f22e2-d1e1-57ad-ad38-09ac0f0a8543",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c0928c9-f4d7-5d33-a2e8-dad232cc3431",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55577692-05a8-583e-8aff-ada68a242c62",
      "id": "CVE-2021-33037",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-33037 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:266c37a5-cfa7-52c6-9fb6-0b3a1bd8423a",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4e8a25b-0097-5d2a-90a1-b648f4a91ff0",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82f0278d-ea68-519f-bec0-5f0f76bd2188",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8adca05e-49ad-5a35-b1f3-1aa6558c0e56",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6348129-e764-55ae-baa1-407f17f5cbcf",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-34305 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b0498df-2b15-5429-afd2-05341d436d2a",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:908800e9-158e-5301-af95-4b4e6d6b26a0",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f526207a-9d9d-5054-8305-3f44d51a9ddf",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-24998 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a016a334-f1a3-537c-84a2-b08ffe9cba4c",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f2e8a48-60f7-5922-81a0-596eedb7efa0",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d61a2584-175c-51c0-b15d-992d69193ad1",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42795 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa6b2568-2cb0-5581-8a2f-f358831ec1b6",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dae0eb07-f6b0-5f67-a341-7f93c18f2483",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49a8f40d-7f38-55e9-bd62-ea640c8d8f87",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46589 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:205d20a3-0712-5b65-9381-ca3fb9a4a653",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b39ad6c8-9f19-586e-8963-3dc91e859e62",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb8fbdc6-13ec-57db-90d2-15f7241ef6bc",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34750 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d46ce1b8-e3a1-5ea2-a80a-65a4c999a479",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ae0b1df-fe37-53c5-9e78-2cf8f565fb80",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6861d72-40c0-5cfc-9dc8-1c2692cee7cc",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5cea5c40-d179-5e71-bda9-b0c8669765f2",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a321b8ea-aedc-5fcc-9944-02d219b24ee3",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56337 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4f1904e-4199-5bb9-90b8-b6430c2ee9d6",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c181a99b-9996-52a5-a35b-e820a7faa7f5",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31650 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:996c03b6-942d-5928-ab5c-6ffc773e5a8c",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90818806-90d0-517f-b440-af011c9b8763",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51062557-29bb-5b17-afa9-897191ea36d8",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25927dfc-08b9-53f5-8229-a3211c2ab80d",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17b19b10-ed92-5ba0-8dec-2001ef26e61b",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c87685bd-5834-53b9-90ef-b9bf1028abbe",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9f424ed-7db6-5fb7-9b4c-76e7abdd2e17",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52434 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19c39f33-67a4-5b63-8627-e3ead67297ec",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54389b15-e510-5f58-a9eb-89eca9e9e916",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9f3d777-4325-5a03-99a5-d9eb2931d578",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:288931f1-e433-5c62-b8ff-e4a45ce75364",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55752 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3aee0586-7cdc-5f1e-a563-68766429c385",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:588319e0-45bc-57b0-a62f-9ec62201e275",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9e581d3-5816-55b2-a3b9-3f92fcfc3c3f",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e0db6e9-f291-5979-a517-c64a8eeeeba7",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1d11260-cca8-5981-a09c-00d5484a908c",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a44b34fe-4f37-5f14-b86a-19c4c4066518",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b0f5d3d-63aa-5804-a073-eeb19ba78f05",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:957bdd74-d92a-5033-a2e3-d91fef3cc78d",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:068d5944-3056-5f40-b01c-204a13d1c312",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8b582e6-6c0b-5016-ab40-b170efb029b1",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34486 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4ab4677-b003-5fc5-8458-9379d864f4a8",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.46-tuxcare.6 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@9.0.46-tuxcare.6"
    }
  ]
}