{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-55956",
        "tracking": {
            "current_release_date": "2026-08-19T09:45:12.759860Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-55956",
            "initial_release_date": "2026-06-29T21:30:08.025263Z",
            "revision_history": [
                {
                    "date": "2026-06-29T21:30:08.025263Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| CVE status created. (valid)| Description created for source.| References created (1).| CWES updated (1)."
                },
                {
                    "date": "2026-06-29T21:30:12.243622Z",
                    "number": "2",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-06-29T21:41:20.128739Z",
                    "number": "3",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| Products created (3).| Products connected (3).| References created (1).| CWES updated (1)."
                },
                {
                    "date": "2026-06-29T21:41:27.174001Z",
                    "number": "4",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-06-29T23:26:35.437320Z",
                    "number": "5",
                    "summary": "References created (1)."
                },
                {
                    "date": "2026-06-30T00:12:34.420110Z",
                    "number": "6",
                    "summary": "References created (1)."
                },
                {
                    "date": "2026-06-30T11:07:14.366512Z",
                    "number": "7",
                    "summary": "Source connected.| CVE status created. (valid)| Products connected (6).| References created (9)."
                },
                {
                    "date": "2026-06-30T11:07:16.309725Z",
                    "number": "8",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-06-30T12:45:59.253409Z",
                    "number": "9",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| Products connected (3).| Product Identifiers created (2)."
                },
                {
                    "date": "2026-06-30T12:46:02.104330Z",
                    "number": "10",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-06-30T14:53:34.031375Z",
                    "number": "11",
                    "summary": "CVSS created.| Unknown change."
                },
                {
                    "date": "2026-06-30T14:53:37.051611Z",
                    "number": "12",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-06-30T15:51:49.342923Z",
                    "number": "13",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-06-30T15:51:58.105454Z",
                    "number": "14",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-06-30T17:43:35.806956Z",
                    "number": "15",
                    "summary": "CVSS created."
                },
                {
                    "date": "2026-06-30T17:43:38.026347Z",
                    "number": "16",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-07-02T02:45:54.281007Z",
                    "number": "17",
                    "summary": "Source connected.| CVE status created. (valid)"
                },
                {
                    "date": "2026-07-02T02:45:56.644423Z",
                    "number": "18",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-07-02T19:52:51.030052Z",
                    "number": "19",
                    "summary": "Products created (3).| Product Identifiers created (3)."
                },
                {
                    "date": "2026-07-02T19:52:53.444116Z",
                    "number": "20",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-07-03T12:25:13.693612Z",
                    "number": "21",
                    "summary": "Source connected.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (5).| Product Threats created (5).| References created (2).| Vendor_assessment created."
                },
                {
                    "date": "2026-07-03T12:25:22.561020Z",
                    "number": "22",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-07-03T16:45:46.991476Z",
                    "number": "23",
                    "summary": "EPSS updated."
                },
                {
                    "date": "2026-07-03T16:45:49.560346Z",
                    "number": "24",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-07-06T18:05:52.276919Z",
                    "number": "25",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (3).| References created (3)."
                },
                {
                    "date": "2026-07-06T18:06:04.978044Z",
                    "number": "26",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-07-09T10:29:48.195904Z",
                    "number": "27",
                    "summary": "Products connected (1).| References created (1)."
                },
                {
                    "date": "2026-07-09T10:29:50.380860Z",
                    "number": "28",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-07-10T06:43:16.102818Z",
                    "number": "29",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (160).| Product Identifiers created (144).| References created (7)."
                },
                {
                    "date": "2026-07-10T06:43:32.563575Z",
                    "number": "30",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-07-14T03:09:34.409253Z",
                    "number": "31",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (4).| CWES updated (1)."
                },
                {
                    "date": "2026-07-15T08:31:12.870497Z",
                    "number": "32",
                    "summary": "Products connected (1).| References created (1)."
                },
                {
                    "date": "2026-07-15T08:31:16.700069Z",
                    "number": "33",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-07-17T08:41:41.261736Z",
                    "number": "34",
                    "summary": "Products connected (2).| References created (6)."
                },
                {
                    "date": "2026-07-17T08:42:14.848237Z",
                    "number": "35",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-07-17T12:45:41.956787Z",
                    "number": "36",
                    "summary": "Source connected.| CVE status created. (valid)| Description created for source.| Products connected (1).| References created (14)."
                },
                {
                    "date": "2026-07-17T13:00:03.715953Z",
                    "number": "37",
                    "summary": "Source connected.| CVE status created. (valid)| Description created for source.| Products connected (1).| References created (13)."
                },
                {
                    "date": "2026-07-17T18:46:36.880608Z",
                    "number": "38",
                    "summary": "Source connected.| CVE status created. (valid)| Description created for source.| Products connected (2).| References created (13)."
                },
                {
                    "date": "2026-07-17T18:46:40.694907Z",
                    "number": "39",
                    "summary": "Source connected.| CVE status created. (valid)| Description created for source.| Products connected (2).| References created (13)."
                },
                {
                    "date": "2026-07-17T18:46:49.120259Z",
                    "number": "40",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-07-17T18:46:50.820200Z",
                    "number": "41",
                    "summary": "Source connected.| CVE status created. (valid)| Description created for source.| Products connected (2).| References created (14)."
                },
                {
                    "date": "2026-07-18T12:45:44.021719Z",
                    "number": "42",
                    "summary": "Source connected.| CVE status created. (valid)| Description created for source.| Products connected (1).| References created (13)."
                },
                {
                    "date": "2026-07-20T11:24:10.884416Z",
                    "number": "43",
                    "summary": "References created (3)."
                },
                {
                    "date": "2026-07-21T07:31:49.103700Z",
                    "number": "44",
                    "summary": "Products connected (1).| References created (1)."
                },
                {
                    "date": "2026-07-21T07:31:59.597395Z",
                    "number": "45",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-07-22T11:53:36.437559Z",
                    "number": "46",
                    "summary": "References created (1)."
                },
                {
                    "date": "2026-07-22T14:46:23.319398Z",
                    "number": "47",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-07-22T18:45:53.004491Z",
                    "number": "48",
                    "summary": "Source connected.| CVE status created. (valid)| Description created for source.| Products connected (1).| References created (13)."
                },
                {
                    "date": "2026-07-23T00:47:49.011770Z",
                    "number": "49",
                    "summary": "Source connected.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (33).| Product Remediations created (66).| Product Identifiers created (6).| Product Identifiers removed (6).| References created (17).| CWES updated (1)."
                },
                {
                    "date": "2026-07-23T00:47:54.211774Z",
                    "number": "50",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-07-23T00:48:06.581503Z",
                    "number": "51",
                    "summary": "Source connected.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (1).| Product Remediations created (2).| References created (18).| CWES updated (1)."
                },
                {
                    "date": "2026-07-23T09:32:49.833122Z",
                    "number": "52",
                    "summary": "References created (2)."
                },
                {
                    "date": "2026-07-23T09:32:52.376109Z",
                    "number": "53",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-07-24T14:28:56.829317Z",
                    "number": "54",
                    "summary": "EPSS updated."
                },
                {
                    "date": "2026-07-24T14:35:35.112458Z",
                    "number": "55",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-07-26T14:21:31.026002Z",
                    "number": "56",
                    "summary": "EPSS updated."
                },
                {
                    "date": "2026-07-26T14:21:35.996541Z",
                    "number": "57",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-08-06T09:40:15.077177Z",
                    "number": "58",
                    "summary": "References created (2)."
                },
                {
                    "date": "2026-08-06T09:40:18.881426Z",
                    "number": "59",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-08-12T15:15:42.712247Z",
                    "number": "60",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-08-12T15:15:44.933012Z",
                    "number": "61",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-08-18T08:22:28.782296Z",
                    "number": "62",
                    "summary": "References created (1)."
                },
                {
                    "date": "2026-08-18T08:22:30.846287Z",
                    "number": "63",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-08-19T07:11:13.656788Z",
                    "number": "64",
                    "summary": "Source connected.| CVE status created. (valid)| Products connected (7).| References created (3)."
                },
                {
                    "date": "2026-08-19T07:11:16.154074Z",
                    "number": "65",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-08-19T09:44:55.084583Z",
                    "number": "66",
                    "summary": "Source connected.| CVE status created. (valid)"
                }
            ],
            "status": "interim",
            "version": "66"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/unknown",
                                "product": {
                                    "name": "vers:unknown/unknown",
                                    "product_id": "CSAFPID-1330296",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:amazon:linux_2:-"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Amazon Linux 2"
                    }
                ],
                "category": "vendor",
                "name": "Amazon"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:semver/10.1.0-m1|<=10.1.55",
                                "product": {
                                    "name": "vers:semver/10.1.0-m1|<=10.1.55",
                                    "product_id": "CSAFPID-8513128"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:semver/11.0.0-m1|<=11.0.22",
                                "product": {
                                    "name": "vers:semver/11.0.0-m1|<=11.0.22",
                                    "product_id": "CSAFPID-8513127"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:semver/7.0.0|<=7.0.109",
                                "product": {
                                    "name": "vers:semver/7.0.0|<=7.0.109",
                                    "product_id": "CSAFPID-6016911"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:semver/8.5.0|<=8.5.100",
                                "product": {
                                    "name": "vers:semver/8.5.0|<=8.5.100",
                                    "product_id": "CSAFPID-3039726"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:semver/9.0.0.m1|<=9.0.118",
                                "product": {
                                    "name": "vers:semver/9.0.0.m1|<=9.0.118",
                                    "product_id": "CSAFPID-8513129"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:semver/<7.0.0",
                                "product": {
                                    "name": "vers:semver/<7.0.0",
                                    "product_id": "CSAFPID-6016912"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Apache Tomcat"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<9.0.119",
                                "product": {
                                    "name": "vers:unknown/<9.0.119",
                                    "product_id": "CSAFPID-8528498",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=10.1.0|<10.1.56",
                                "product": {
                                    "name": "vers:unknown/>=10.1.0|<10.1.56",
                                    "product_id": "CSAFPID-8528499",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=11.0.0|<11.0.23",
                                "product": {
                                    "name": "vers:unknown/>=11.0.0|<11.0.23",
                                    "product_id": "CSAFPID-8528500",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "tomcat"
                    }
                ],
                "category": "vendor",
                "name": "Apache Software Foundation"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/25.2.0.0.10",
                                "product": {
                                    "name": "vers:unknown/25.2.0.0.10",
                                    "product_id": "CSAFPID-9010918",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:oracle:communications:25.2.0.0.10"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/6.1.1-7.0.0",
                                "product": {
                                    "name": "vers:unknown/6.1.1-7.0.0",
                                    "product_id": "CSAFPID-9010919",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:oracle:communications:6.1.1-7.0.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/7.4.1",
                                "product": {
                                    "name": "vers:unknown/7.4.1",
                                    "product_id": "CSAFPID-5452529",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:oracle:communications:7.4.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/7.5.0-7.5.1",
                                "product": {
                                    "name": "vers:unknown/7.5.0-7.5.1",
                                    "product_id": "CSAFPID-9010915",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:oracle:communications:7.5.0-7.5.1"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/7.6.0-7.8.0",
                                "product": {
                                    "name": "vers:unknown/7.6.0-7.8.0",
                                    "product_id": "CSAFPID-9010917",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:oracle:communications:7.6.0-7.8.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.0.0",
                                "product": {
                                    "name": "vers:unknown/8.0.0",
                                    "product_id": "CSAFPID-1351079",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:oracle:communications:8.0.0"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/8.0.1",
                                "product": {
                                    "name": "vers:unknown/8.0.1",
                                    "product_id": "CSAFPID-9010916",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/a:oracle:communications:8.0.1"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Communications"
                    }
                ],
                "category": "vendor",
                "name": "Oracle"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/unknown",
                                "product": {
                                    "name": "vers:unknown/unknown",
                                    "product_id": "CSAFPID-1317175",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:redhat:enterprise_linux:-"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/6.2",
                                        "product": {
                                            "name": "vers:rpm/6.2",
                                            "product_id": "CSAFPID-5912598",
                                            "product_identification_helper": {
                                                "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el10"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Red Hat JBoss Web Server 6.2 on RHEL 10"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/6.2",
                                        "product": {
                                            "name": "vers:rpm/6.2",
                                            "product_id": "CSAFPID-5912611",
                                            "product_identification_helper": {
                                                "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el8"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Red Hat JBoss Web Server 6.2 on RHEL 8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/6.2",
                                        "product": {
                                            "name": "vers:rpm/6.2",
                                            "product_id": "CSAFPID-5912624",
                                            "product_identification_helper": {
                                                "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2::el9"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Red Hat JBoss Web Server 6.2 on RHEL 9"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/6.2",
                                        "product": {
                                            "name": "vers:rpm/6.2",
                                            "product_id": "CSAFPID-8882584",
                                            "product_identification_helper": {
                                                "cpe": "cpe:/a:redhat:jboss_enterprise_web_server:6.2"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Red Hat JBoss Web Server 6.2.4"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/10.1.49-15.redhat_00013.1.el10jws",
                                        "product": {
                                            "name": "vers:rpm/10.1.49-15.redhat_00013.1.el10jws",
                                            "product_id": "CSAFPID-8882551",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/jws6-tomcat@10.1.49-15.redhat_00013.1.el10jws?arch=src"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/10.1.49-15.redhat_00013.1.el8jws",
                                        "product": {
                                            "name": "vers:rpm/10.1.49-15.redhat_00013.1.el8jws",
                                            "product_id": "CSAFPID-8882561",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/jws6-tomcat@10.1.49-15.redhat_00013.1.el8jws?arch=src"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/10.1.49-15.redhat_00013.1.el9jws",
                                        "product": {
                                            "name": "vers:rpm/10.1.49-15.redhat_00013.1.el9jws",
                                            "product_id": "CSAFPID-8882571",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/jws6-tomcat@10.1.49-15.redhat_00013.1.el9jws?arch=src"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "jws6-tomcat"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/10.1.49-15.redhat_00013.1.el10jws",
                                        "product": {
                                            "name": "vers:rpm/10.1.49-15.redhat_00013.1.el10jws",
                                            "product_id": "CSAFPID-8882552",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/jws6-tomcat-admin-webapps@10.1.49-15.redhat_00013.1.el10jws?arch=noarch"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/10.1.49-15.redhat_00013.1.el8jws",
                                        "product": {
                                            "name": "vers:rpm/10.1.49-15.redhat_00013.1.el8jws",
                                            "product_id": "CSAFPID-8882562",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/jws6-tomcat-admin-webapps@10.1.49-15.redhat_00013.1.el8jws?arch=noarch"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/10.1.49-15.redhat_00013.1.el9jws",
                                        "product": {
                                            "name": "vers:rpm/10.1.49-15.redhat_00013.1.el9jws",
                                            "product_id": "CSAFPID-8882572",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/jws6-tomcat-admin-webapps@10.1.49-15.redhat_00013.1.el9jws?arch=noarch"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "jws6-tomcat-admin-webapps"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/10.1.49-15.redhat_00013.1.el10jws",
                                        "product": {
                                            "name": "vers:rpm/10.1.49-15.redhat_00013.1.el10jws",
                                            "product_id": "CSAFPID-8882553",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/jws6-tomcat-docs-webapp@10.1.49-15.redhat_00013.1.el10jws?arch=noarch"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/10.1.49-15.redhat_00013.1.el8jws",
                                        "product": {
                                            "name": "vers:rpm/10.1.49-15.redhat_00013.1.el8jws",
                                            "product_id": "CSAFPID-8882563",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/jws6-tomcat-docs-webapp@10.1.49-15.redhat_00013.1.el8jws?arch=noarch"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/10.1.49-15.redhat_00013.1.el9jws",
                                        "product": {
                                            "name": "vers:rpm/10.1.49-15.redhat_00013.1.el9jws",
                                            "product_id": "CSAFPID-8882573",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/jws6-tomcat-docs-webapp@10.1.49-15.redhat_00013.1.el9jws?arch=noarch"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "jws6-tomcat-docs-webapp"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/10.1.49-15.redhat_00013.1.el10jws",
                                        "product": {
                                            "name": "vers:rpm/10.1.49-15.redhat_00013.1.el10jws",
                                            "product_id": "CSAFPID-8882554",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/jws6-tomcat-el-5.0-api@10.1.49-15.redhat_00013.1.el10jws?arch=noarch"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/10.1.49-15.redhat_00013.1.el8jws",
                                        "product": {
                                            "name": "vers:rpm/10.1.49-15.redhat_00013.1.el8jws",
                                            "product_id": "CSAFPID-8882564",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/jws6-tomcat-el-5.0-api@10.1.49-15.redhat_00013.1.el8jws?arch=noarch"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/10.1.49-15.redhat_00013.1.el9jws",
                                        "product": {
                                            "name": "vers:rpm/10.1.49-15.redhat_00013.1.el9jws",
                                            "product_id": "CSAFPID-8882574",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/jws6-tomcat-el-5.0-api@10.1.49-15.redhat_00013.1.el9jws?arch=noarch"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "jws6-tomcat-el-5.0-api"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/10.1.49-15.redhat_00013.1.el10jws",
                                        "product": {
                                            "name": "vers:rpm/10.1.49-15.redhat_00013.1.el10jws",
                                            "product_id": "CSAFPID-8882555",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/jws6-tomcat-javadoc@10.1.49-15.redhat_00013.1.el10jws?arch=noarch"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/10.1.49-15.redhat_00013.1.el8jws",
                                        "product": {
                                            "name": "vers:rpm/10.1.49-15.redhat_00013.1.el8jws",
                                            "product_id": "CSAFPID-8882565",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/jws6-tomcat-javadoc@10.1.49-15.redhat_00013.1.el8jws?arch=noarch"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/10.1.49-15.redhat_00013.1.el9jws",
                                        "product": {
                                            "name": "vers:rpm/10.1.49-15.redhat_00013.1.el9jws",
                                            "product_id": "CSAFPID-8882575",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/jws6-tomcat-javadoc@10.1.49-15.redhat_00013.1.el9jws?arch=noarch"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "jws6-tomcat-javadoc"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/10.1.49-15.redhat_00013.1.el10jws",
                                        "product": {
                                            "name": "vers:rpm/10.1.49-15.redhat_00013.1.el10jws",
                                            "product_id": "CSAFPID-8882556",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/jws6-tomcat-jsp-3.1-api@10.1.49-15.redhat_00013.1.el10jws?arch=noarch"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/10.1.49-15.redhat_00013.1.el8jws",
                                        "product": {
                                            "name": "vers:rpm/10.1.49-15.redhat_00013.1.el8jws",
                                            "product_id": "CSAFPID-8882566",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/jws6-tomcat-jsp-3.1-api@10.1.49-15.redhat_00013.1.el8jws?arch=noarch"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/10.1.49-15.redhat_00013.1.el9jws",
                                        "product": {
                                            "name": "vers:rpm/10.1.49-15.redhat_00013.1.el9jws",
                                            "product_id": "CSAFPID-8882576",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/jws6-tomcat-jsp-3.1-api@10.1.49-15.redhat_00013.1.el9jws?arch=noarch"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "jws6-tomcat-jsp-3.1-api"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/10.1.49-15.redhat_00013.1.el10jws",
                                        "product": {
                                            "name": "vers:rpm/10.1.49-15.redhat_00013.1.el10jws",
                                            "product_id": "CSAFPID-8882557",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/jws6-tomcat-lib@10.1.49-15.redhat_00013.1.el10jws?arch=noarch"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/10.1.49-15.redhat_00013.1.el8jws",
                                        "product": {
                                            "name": "vers:rpm/10.1.49-15.redhat_00013.1.el8jws",
                                            "product_id": "CSAFPID-8882567",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/jws6-tomcat-lib@10.1.49-15.redhat_00013.1.el8jws?arch=noarch"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/10.1.49-15.redhat_00013.1.el9jws",
                                        "product": {
                                            "name": "vers:rpm/10.1.49-15.redhat_00013.1.el9jws",
                                            "product_id": "CSAFPID-8882577",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/jws6-tomcat-lib@10.1.49-15.redhat_00013.1.el9jws?arch=noarch"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "jws6-tomcat-lib"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/10.1.49-15.redhat_00013.1.el10jws",
                                        "product": {
                                            "name": "vers:rpm/10.1.49-15.redhat_00013.1.el10jws",
                                            "product_id": "CSAFPID-8882558",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/jws6-tomcat-selinux@10.1.49-15.redhat_00013.1.el10jws?arch=noarch"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/10.1.49-15.redhat_00013.1.el8jws",
                                        "product": {
                                            "name": "vers:rpm/10.1.49-15.redhat_00013.1.el8jws",
                                            "product_id": "CSAFPID-8882568",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/jws6-tomcat-selinux@10.1.49-15.redhat_00013.1.el8jws?arch=noarch"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/10.1.49-15.redhat_00013.1.el9jws",
                                        "product": {
                                            "name": "vers:rpm/10.1.49-15.redhat_00013.1.el9jws",
                                            "product_id": "CSAFPID-8882578",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/jws6-tomcat-selinux@10.1.49-15.redhat_00013.1.el9jws?arch=noarch"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "jws6-tomcat-selinux"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/10.1.49-15.redhat_00013.1.el10jws",
                                        "product": {
                                            "name": "vers:rpm/10.1.49-15.redhat_00013.1.el10jws",
                                            "product_id": "CSAFPID-8882559",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/jws6-tomcat-servlet-6.0-api@10.1.49-15.redhat_00013.1.el10jws?arch=noarch"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/10.1.49-15.redhat_00013.1.el8jws",
                                        "product": {
                                            "name": "vers:rpm/10.1.49-15.redhat_00013.1.el8jws",
                                            "product_id": "CSAFPID-8882569",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/jws6-tomcat-servlet-6.0-api@10.1.49-15.redhat_00013.1.el8jws?arch=noarch"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/10.1.49-15.redhat_00013.1.el9jws",
                                        "product": {
                                            "name": "vers:rpm/10.1.49-15.redhat_00013.1.el9jws",
                                            "product_id": "CSAFPID-8882579",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/jws6-tomcat-servlet-6.0-api@10.1.49-15.redhat_00013.1.el9jws?arch=noarch"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "jws6-tomcat-servlet-6.0-api"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/10.1.49-15.redhat_00013.1.el10jws",
                                        "product": {
                                            "name": "vers:rpm/10.1.49-15.redhat_00013.1.el10jws",
                                            "product_id": "CSAFPID-8882560",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/jws6-tomcat-webapps@10.1.49-15.redhat_00013.1.el10jws?arch=noarch"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/10.1.49-15.redhat_00013.1.el8jws",
                                        "product": {
                                            "name": "vers:rpm/10.1.49-15.redhat_00013.1.el8jws",
                                            "product_id": "CSAFPID-8882570",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/jws6-tomcat-webapps@10.1.49-15.redhat_00013.1.el8jws?arch=noarch"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/10.1.49-15.redhat_00013.1.el9jws",
                                        "product": {
                                            "name": "vers:rpm/10.1.49-15.redhat_00013.1.el9jws",
                                            "product_id": "CSAFPID-8882580",
                                            "product_identification_helper": {
                                                "purl": "pkg:rpm/redhat/jws6-tomcat-webapps@10.1.49-15.redhat_00013.1.el9jws?arch=noarch"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "jws6-tomcat-webapps"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat JBoss Web Server"
                    }
                ],
                "category": "vendor",
                "name": "Red Hat"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/unknown",
                                "product": {
                                    "name": "vers:unknown/unknown",
                                    "product_id": "CSAFPID-1317176",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:suse:opensuse:-"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "SUSE openSUSE"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/unknown",
                                "product": {
                                    "name": "vers:unknown/unknown",
                                    "product_id": "CSAFPID-1317174",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:suse:suse_linux:-"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "SuSE Linux"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0|<9.0.119-150200.111.1",
                                        "product": {
                                            "name": "vers:unknown/>=0|<9.0.119-150200.111.1",
                                            "product_id": "CSAFPID-8849606"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "tomcat"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0|<10.1.56-150200.5.70.1",
                                        "product": {
                                            "name": "vers:unknown/>=0|<10.1.56-150200.5.70.1",
                                            "product_id": "CSAFPID-8857448"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "tomcat10"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0|<11.0.23-150600.13.24.1",
                                        "product": {
                                            "name": "vers:unknown/>=0|<11.0.23-150600.13.24.1",
                                            "product_id": "CSAFPID-8848631"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "tomcat11"
                            }
                        ],
                        "category": "product_family",
                        "name": "SUSE:Linux Enterprise Module for Web and Scripting 15 SP7"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0|<9.0.119-160000.1.1",
                                        "product": {
                                            "name": "vers:unknown/>=0|<9.0.119-160000.1.1",
                                            "product_id": "CSAFPID-8854302"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "tomcat"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0|<10.1.56-160000.1.1",
                                        "product": {
                                            "name": "vers:unknown/>=0|<10.1.56-160000.1.1",
                                            "product_id": "CSAFPID-8854300"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "tomcat10"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0|<11.0.23-160000.1.1",
                                        "product": {
                                            "name": "vers:unknown/>=0|<11.0.23-160000.1.1",
                                            "product_id": "CSAFPID-8854314"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "tomcat11"
                            }
                        ],
                        "category": "product_family",
                        "name": "SUSE:Linux Enterprise Server 16.0"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0|<9.0.119-3.169.1",
                                        "product": {
                                            "name": "vers:unknown/>=0|<9.0.119-3.169.1",
                                            "product_id": "CSAFPID-8879897"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "tomcat"
                            }
                        ],
                        "category": "product_family",
                        "name": "SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0|<9.0.119-160000.1.1",
                                        "product": {
                                            "name": "vers:unknown/>=0|<9.0.119-160000.1.1",
                                            "product_id": "CSAFPID-8854303"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "tomcat"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0|<10.1.56-160000.1.1",
                                        "product": {
                                            "name": "vers:unknown/>=0|<10.1.56-160000.1.1",
                                            "product_id": "CSAFPID-8854301"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "tomcat10"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0|<11.0.23-160000.1.1",
                                        "product": {
                                            "name": "vers:unknown/>=0|<11.0.23-160000.1.1",
                                            "product_id": "CSAFPID-8854315"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "tomcat11"
                            }
                        ],
                        "category": "product_family",
                        "name": "SUSE:Linux Enterprise Server for SAP applications 16.0"
                    }
                ],
                "category": "vendor",
                "name": "SUSE"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:netapp/>=10.1.0-m1|<=10.1.55",
                                "product": {
                                    "name": "vers:netapp/>=10.1.0-m1|<=10.1.55",
                                    "product_id": "CSAFPID-8532144"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:netapp/>=11.0.0-m1|<=11.0.22",
                                "product": {
                                    "name": "vers:netapp/>=11.0.0-m1|<=11.0.22",
                                    "product_id": "CSAFPID-8532143"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:netapp/>=7.0.0|<=7.0.109",
                                "product": {
                                    "name": "vers:netapp/>=7.0.0|<=7.0.109",
                                    "product_id": "CSAFPID-8532148"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:netapp/>=8.5.0|<=8.5.100",
                                "product": {
                                    "name": "vers:netapp/>=8.5.0|<=8.5.100",
                                    "product_id": "CSAFPID-8532146"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:netapp/>=9.0.0.m1|<=9.0.118",
                                "product": {
                                    "name": "vers:netapp/>=9.0.0.m1|<=9.0.118",
                                    "product_id": "CSAFPID-8532147"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<10.1.37",
                                "product": {
                                    "name": "vers:unknown/<10.1.37",
                                    "product_id": "CSAFPID-8514460"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<10.1.56",
                                "product": {
                                    "name": "vers:unknown/<10.1.56",
                                    "product_id": "CSAFPID-8514463"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<11.0.23",
                                "product": {
                                    "name": "vers:unknown/<11.0.23",
                                    "product_id": "CSAFPID-8514464"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<11.0.5",
                                "product": {
                                    "name": "vers:unknown/<11.0.5",
                                    "product_id": "CSAFPID-8514461"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<9.0.101",
                                "product": {
                                    "name": "vers:unknown/<9.0.101",
                                    "product_id": "CSAFPID-8514465"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<9.0.119",
                                "product": {
                                    "name": "vers:unknown/<9.0.119",
                                    "product_id": "CSAFPID-8514462"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Tomcat"
                    }
                ],
                "category": "vendor",
                "name": "Apache"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/unknown",
                                "product": {
                                    "name": "vers:unknown/unknown",
                                    "product_id": "CSAFPID-1330299",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:canonical:ubuntu_linux:-"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Ubuntu Linux"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/10.1.35-1",
                                        "product": {
                                            "name": "vers:unknown/10.1.35-1",
                                            "product_id": "CSAFPID-7053083",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat10@10.1.35-1?arch=source&distro=questing"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/10.1.40-1",
                                        "product": {
                                            "name": "vers:unknown/10.1.40-1",
                                            "product_id": "CSAFPID-7053084",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat10@10.1.40-1?arch=source&distro=questing"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/10.1.40-1ubuntu1",
                                        "product": {
                                            "name": "vers:unknown/10.1.40-1ubuntu1",
                                            "product_id": "CSAFPID-7053085",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat10@10.1.40-1ubuntu1?arch=source&distro=questing"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/10.1.40-1ubuntu1.25.10.1",
                                        "product": {
                                            "name": "vers:unknown/10.1.40-1ubuntu1.25.10.1",
                                            "product_id": "CSAFPID-8263925",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat10@10.1.40-1ubuntu1.25.10.1?arch=source&distro=questing"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-7053086"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "tomcat10"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/11.0.6-1",
                                        "product": {
                                            "name": "vers:unknown/11.0.6-1",
                                            "product_id": "CSAFPID-7053087",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat11@11.0.6-1?arch=source&distro=questing"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-7053088"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "tomcat11"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.70-2ubuntu1.1",
                                        "product": {
                                            "name": "vers:unknown/9.0.70-2ubuntu1.1",
                                            "product_id": "CSAFPID-7053089",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.70-2ubuntu1.1?arch=source&distro=questing"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.70-2ubuntu2",
                                        "product": {
                                            "name": "vers:unknown/9.0.70-2ubuntu2",
                                            "product_id": "CSAFPID-7053090",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.70-2ubuntu2?arch=source&distro=questing"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.70-2ubuntu3",
                                        "product": {
                                            "name": "vers:unknown/9.0.70-2ubuntu3",
                                            "product_id": "CSAFPID-7053091",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.70-2ubuntu3?arch=source&distro=questing"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.95-1ubuntu1",
                                        "product": {
                                            "name": "vers:unknown/9.0.95-1ubuntu1",
                                            "product_id": "CSAFPID-7053092",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.95-1ubuntu1?arch=source&distro=questing"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.95-1ubuntu1.1",
                                        "product": {
                                            "name": "vers:unknown/9.0.95-1ubuntu1.1",
                                            "product_id": "CSAFPID-8263929",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.95-1ubuntu1.1?arch=source&distro=questing"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-7053093"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "tomcat9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Ubuntu:25.10"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/10.1.40-1ubuntu1",
                                        "product": {
                                            "name": "vers:unknown/10.1.40-1ubuntu1",
                                            "product_id": "CSAFPID-7762533",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat10@10.1.40-1ubuntu1?arch=source&distro=resolute"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/10.1.40-1ubuntu1.26.04.1",
                                        "product": {
                                            "name": "vers:unknown/10.1.40-1ubuntu1.26.04.1",
                                            "product_id": "CSAFPID-8263926",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat10@10.1.40-1ubuntu1.26.04.1?arch=source&distro=resolute"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/10.1.55-1ubuntu2~26.04.1",
                                        "product": {
                                            "name": "vers:unknown/10.1.55-1ubuntu2~26.04.1",
                                            "product_id": "CSAFPID-8598247",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat10@10.1.55-1ubuntu2~26.04.1?arch=source&distro=resolute"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-7762534"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "tomcat10"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/11.0.11-1",
                                        "product": {
                                            "name": "vers:unknown/11.0.11-1",
                                            "product_id": "CSAFPID-7762536",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat11@11.0.11-1?arch=source&distro=resolute"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/11.0.15-1",
                                        "product": {
                                            "name": "vers:unknown/11.0.15-1",
                                            "product_id": "CSAFPID-7762537",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat11@11.0.15-1?arch=source&distro=resolute"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/11.0.18-1",
                                        "product": {
                                            "name": "vers:unknown/11.0.18-1",
                                            "product_id": "CSAFPID-7762538",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat11@11.0.18-1?arch=source&distro=resolute"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/11.0.18-1ubuntu0.1~esm1",
                                        "product": {
                                            "name": "vers:unknown/11.0.18-1ubuntu0.1~esm1",
                                            "product_id": "CSAFPID-8598248",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat11@11.0.18-1ubuntu0.1~esm1?arch=source&distro=resolute"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/11.0.22-2ubuntu2~26.04.1",
                                        "product": {
                                            "name": "vers:unknown/11.0.22-2ubuntu2~26.04.1",
                                            "product_id": "CSAFPID-8598249",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat11@11.0.22-2ubuntu2~26.04.1?arch=source&distro=resolute"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/11.0.6-1",
                                        "product": {
                                            "name": "vers:unknown/11.0.6-1",
                                            "product_id": "CSAFPID-7762535",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat11@11.0.6-1?arch=source&distro=resolute"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-7762539"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "tomcat11"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.111-1",
                                        "product": {
                                            "name": "vers:unknown/9.0.111-1",
                                            "product_id": "CSAFPID-7762541",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.111-1?arch=source&distro=resolute"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.115-1",
                                        "product": {
                                            "name": "vers:unknown/9.0.115-1",
                                            "product_id": "CSAFPID-7762542",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.115-1?arch=source&distro=resolute"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.115-1ubuntu0.1",
                                        "product": {
                                            "name": "vers:unknown/9.0.115-1ubuntu0.1",
                                            "product_id": "CSAFPID-8263930",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.115-1ubuntu0.1?arch=source&distro=resolute"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.118-1~26.04.1",
                                        "product": {
                                            "name": "vers:unknown/9.0.118-1~26.04.1",
                                            "product_id": "CSAFPID-8598988",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.118-1~26.04.1?arch=source&distro=resolute"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.95-1ubuntu1",
                                        "product": {
                                            "name": "vers:unknown/9.0.95-1ubuntu1",
                                            "product_id": "CSAFPID-7762540",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.95-1ubuntu1?arch=source&distro=resolute"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-7762543"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "tomcat9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Ubuntu:26.04:LTS"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/10.1.10-1",
                                        "product": {
                                            "name": "vers:unknown/10.1.10-1",
                                            "product_id": "CSAFPID-6241470",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat10@10.1.10-1?arch=source&distro=esm-apps/noble"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/10.1.14-1",
                                        "product": {
                                            "name": "vers:unknown/10.1.14-1",
                                            "product_id": "CSAFPID-6241471",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat10@10.1.14-1?arch=source&distro=esm-apps/noble"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/10.1.15-1",
                                        "product": {
                                            "name": "vers:unknown/10.1.15-1",
                                            "product_id": "CSAFPID-6241472",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat10@10.1.15-1?arch=source&distro=esm-apps/noble"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/10.1.16-1",
                                        "product": {
                                            "name": "vers:unknown/10.1.16-1",
                                            "product_id": "CSAFPID-6241473",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat10@10.1.16-1?arch=source&distro=esm-apps/noble"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/10.1.16-1ubuntu0.1~esm1",
                                        "product": {
                                            "name": "vers:unknown/10.1.16-1ubuntu0.1~esm1",
                                            "product_id": "CSAFPID-6241474",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat10@10.1.16-1ubuntu0.1~esm1?arch=source&distro=esm-apps/noble"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/10.1.16-1ubuntu0.1~esm2",
                                        "product": {
                                            "name": "vers:unknown/10.1.16-1ubuntu0.1~esm2",
                                            "product_id": "CSAFPID-6241475",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat10@10.1.16-1ubuntu0.1~esm2?arch=source&distro=esm-apps/noble"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/10.1.16-1ubuntu0.1~esm3",
                                        "product": {
                                            "name": "vers:unknown/10.1.16-1ubuntu0.1~esm3",
                                            "product_id": "CSAFPID-7053079",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat10@10.1.16-1ubuntu0.1~esm3?arch=source&distro=esm-apps/noble"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/10.1.16-1ubuntu0.1~esm4",
                                        "product": {
                                            "name": "vers:unknown/10.1.16-1ubuntu0.1~esm4",
                                            "product_id": "CSAFPID-8263924",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat10@10.1.16-1ubuntu0.1~esm4?arch=source&distro=esm-apps/noble"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-7053080"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "tomcat10"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.70-1ubuntu1",
                                        "product": {
                                            "name": "vers:unknown/9.0.70-1ubuntu1",
                                            "product_id": "CSAFPID-6243553",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.70-1ubuntu1?arch=source&distro=esm-apps/noble"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.70-2",
                                        "product": {
                                            "name": "vers:unknown/9.0.70-2",
                                            "product_id": "CSAFPID-6243554",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.70-2?arch=source&distro=esm-apps/noble"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.70-2ubuntu0.1",
                                        "product": {
                                            "name": "vers:unknown/9.0.70-2ubuntu0.1",
                                            "product_id": "CSAFPID-6243555",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.70-2ubuntu0.1?arch=source&distro=esm-apps/noble"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.70-2ubuntu0.1+esm1",
                                        "product": {
                                            "name": "vers:unknown/9.0.70-2ubuntu0.1+esm1",
                                            "product_id": "CSAFPID-6243556",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.70-2ubuntu0.1%2Besm1?arch=source&distro=esm-apps/noble"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.70-2ubuntu0.1+esm2",
                                        "product": {
                                            "name": "vers:unknown/9.0.70-2ubuntu0.1+esm2",
                                            "product_id": "CSAFPID-7053081",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.70-2ubuntu0.1%2Besm2?arch=source&distro=esm-apps/noble"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.70-2ubuntu0.1+esm3",
                                        "product": {
                                            "name": "vers:unknown/9.0.70-2ubuntu0.1+esm3",
                                            "product_id": "CSAFPID-8263932",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.70-2ubuntu0.1%2Besm3?arch=source&distro=esm-apps/noble"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-7053082"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "tomcat9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Ubuntu:Pro:24.04:LTS"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/6.0.37-1",
                                        "product": {
                                            "name": "vers:unknown/6.0.37-1",
                                            "product_id": "CSAFPID-3764266",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat6@6.0.37-1?arch=source&distro=esm-infra-legacy/trusty"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/6.0.39-1",
                                        "product": {
                                            "name": "vers:unknown/6.0.39-1",
                                            "product_id": "CSAFPID-3764267",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat6@6.0.39-1?arch=source&distro=esm-infra-legacy/trusty"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/6.0.39-1ubuntu0.1",
                                        "product": {
                                            "name": "vers:unknown/6.0.39-1ubuntu0.1",
                                            "product_id": "CSAFPID-3764268",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat6@6.0.39-1ubuntu0.1?arch=source&distro=esm-infra-legacy/trusty"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/6.0.39-1ubuntu0.1+esm1",
                                        "product": {
                                            "name": "vers:unknown/6.0.39-1ubuntu0.1+esm1",
                                            "product_id": "CSAFPID-3764269",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat6@6.0.39-1ubuntu0.1%2Besm1?arch=source&distro=esm-infra-legacy/trusty"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/6.0.39-1ubuntu0.1+esm2",
                                        "product": {
                                            "name": "vers:unknown/6.0.39-1ubuntu0.1+esm2",
                                            "product_id": "CSAFPID-3764270",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat6@6.0.39-1ubuntu0.1%2Besm2?arch=source&distro=esm-infra-legacy/trusty"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/6.0.39-1ubuntu0.1+esm3",
                                        "product": {
                                            "name": "vers:unknown/6.0.39-1ubuntu0.1+esm3",
                                            "product_id": "CSAFPID-8263923",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat6@6.0.39-1ubuntu0.1%2Besm3?arch=source&distro=esm-infra-legacy/trusty"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-3764271"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "tomcat6"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.0.42-1",
                                        "product": {
                                            "name": "vers:unknown/7.0.42-1",
                                            "product_id": "CSAFPID-3764272",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat7@7.0.42-1?arch=source&distro=esm-infra-legacy/trusty"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.0.47-1",
                                        "product": {
                                            "name": "vers:unknown/7.0.47-1",
                                            "product_id": "CSAFPID-3764273",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat7@7.0.47-1?arch=source&distro=esm-infra-legacy/trusty"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.0.50-1",
                                        "product": {
                                            "name": "vers:unknown/7.0.50-1",
                                            "product_id": "CSAFPID-3764274",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat7@7.0.50-1?arch=source&distro=esm-infra-legacy/trusty"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.0.52-1",
                                        "product": {
                                            "name": "vers:unknown/7.0.52-1",
                                            "product_id": "CSAFPID-3764275",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat7@7.0.52-1?arch=source&distro=esm-infra-legacy/trusty"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.0.52-1ubuntu0.1",
                                        "product": {
                                            "name": "vers:unknown/7.0.52-1ubuntu0.1",
                                            "product_id": "CSAFPID-3764276",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat7@7.0.52-1ubuntu0.1?arch=source&distro=esm-infra-legacy/trusty"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.0.52-1ubuntu0.10",
                                        "product": {
                                            "name": "vers:unknown/7.0.52-1ubuntu0.10",
                                            "product_id": "CSAFPID-3764282",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat7@7.0.52-1ubuntu0.10?arch=source&distro=esm-infra-legacy/trusty"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.0.52-1ubuntu0.11",
                                        "product": {
                                            "name": "vers:unknown/7.0.52-1ubuntu0.11",
                                            "product_id": "CSAFPID-3764283",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat7@7.0.52-1ubuntu0.11?arch=source&distro=esm-infra-legacy/trusty"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.0.52-1ubuntu0.13",
                                        "product": {
                                            "name": "vers:unknown/7.0.52-1ubuntu0.13",
                                            "product_id": "CSAFPID-3764284",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat7@7.0.52-1ubuntu0.13?arch=source&distro=esm-infra-legacy/trusty"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.0.52-1ubuntu0.14",
                                        "product": {
                                            "name": "vers:unknown/7.0.52-1ubuntu0.14",
                                            "product_id": "CSAFPID-3764285",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat7@7.0.52-1ubuntu0.14?arch=source&distro=esm-infra-legacy/trusty"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.0.52-1ubuntu0.15",
                                        "product": {
                                            "name": "vers:unknown/7.0.52-1ubuntu0.15",
                                            "product_id": "CSAFPID-3764286",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat7@7.0.52-1ubuntu0.15?arch=source&distro=esm-infra-legacy/trusty"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.0.52-1ubuntu0.16",
                                        "product": {
                                            "name": "vers:unknown/7.0.52-1ubuntu0.16",
                                            "product_id": "CSAFPID-3764287",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat7@7.0.52-1ubuntu0.16?arch=source&distro=esm-infra-legacy/trusty"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.0.52-1ubuntu0.16+esm1",
                                        "product": {
                                            "name": "vers:unknown/7.0.52-1ubuntu0.16+esm1",
                                            "product_id": "CSAFPID-3764288",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat7@7.0.52-1ubuntu0.16%2Besm1?arch=source&distro=esm-infra-legacy/trusty"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.0.52-1ubuntu0.16+esm2",
                                        "product": {
                                            "name": "vers:unknown/7.0.52-1ubuntu0.16+esm2",
                                            "product_id": "CSAFPID-8263927",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat7@7.0.52-1ubuntu0.16%2Besm2?arch=source&distro=esm-infra-legacy/trusty"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.0.52-1ubuntu0.3",
                                        "product": {
                                            "name": "vers:unknown/7.0.52-1ubuntu0.3",
                                            "product_id": "CSAFPID-3764277",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat7@7.0.52-1ubuntu0.3?arch=source&distro=esm-infra-legacy/trusty"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.0.52-1ubuntu0.6",
                                        "product": {
                                            "name": "vers:unknown/7.0.52-1ubuntu0.6",
                                            "product_id": "CSAFPID-3764278",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat7@7.0.52-1ubuntu0.6?arch=source&distro=esm-infra-legacy/trusty"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.0.52-1ubuntu0.7",
                                        "product": {
                                            "name": "vers:unknown/7.0.52-1ubuntu0.7",
                                            "product_id": "CSAFPID-3764279",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat7@7.0.52-1ubuntu0.7?arch=source&distro=esm-infra-legacy/trusty"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.0.52-1ubuntu0.8",
                                        "product": {
                                            "name": "vers:unknown/7.0.52-1ubuntu0.8",
                                            "product_id": "CSAFPID-3764280",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat7@7.0.52-1ubuntu0.8?arch=source&distro=esm-infra-legacy/trusty"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.0.52-1ubuntu0.9",
                                        "product": {
                                            "name": "vers:unknown/7.0.52-1ubuntu0.9",
                                            "product_id": "CSAFPID-3764281",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat7@7.0.52-1ubuntu0.9?arch=source&distro=esm-infra-legacy/trusty"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-3764289"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "tomcat7"
                            }
                        ],
                        "category": "product_family",
                        "name": "Ubuntu:Pro:14.04:LTS"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.0.64-1",
                                        "product": {
                                            "name": "vers:unknown/7.0.64-1",
                                            "product_id": "CSAFPID-3764314",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat7@7.0.64-1?arch=source&distro=esm-apps-legacy/xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.0.68-1",
                                        "product": {
                                            "name": "vers:unknown/7.0.68-1",
                                            "product_id": "CSAFPID-3764315",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat7@7.0.68-1?arch=source&distro=esm-apps-legacy/xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.0.68-1ubuntu0.1",
                                        "product": {
                                            "name": "vers:unknown/7.0.68-1ubuntu0.1",
                                            "product_id": "CSAFPID-3764316",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat7@7.0.68-1ubuntu0.1?arch=source&distro=esm-apps-legacy/xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.0.68-1ubuntu0.3",
                                        "product": {
                                            "name": "vers:unknown/7.0.68-1ubuntu0.3",
                                            "product_id": "CSAFPID-3764317",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat7@7.0.68-1ubuntu0.3?arch=source&distro=esm-apps-legacy/xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.0.68-1ubuntu0.4",
                                        "product": {
                                            "name": "vers:unknown/7.0.68-1ubuntu0.4",
                                            "product_id": "CSAFPID-3764318",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat7@7.0.68-1ubuntu0.4?arch=source&distro=esm-apps-legacy/xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.0.68-1ubuntu0.4+esm1",
                                        "product": {
                                            "name": "vers:unknown/7.0.68-1ubuntu0.4+esm1",
                                            "product_id": "CSAFPID-3764319",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat7@7.0.68-1ubuntu0.4%2Besm1?arch=source&distro=esm-apps-legacy/xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.0.68-1ubuntu0.4+esm2",
                                        "product": {
                                            "name": "vers:unknown/7.0.68-1ubuntu0.4+esm2",
                                            "product_id": "CSAFPID-3764320",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat7@7.0.68-1ubuntu0.4%2Besm2?arch=source&distro=esm-apps-legacy/xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.0.68-1ubuntu0.4+esm3",
                                        "product": {
                                            "name": "vers:unknown/7.0.68-1ubuntu0.4+esm3",
                                            "product_id": "CSAFPID-3764321",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat7@7.0.68-1ubuntu0.4%2Besm3?arch=source&distro=esm-apps-legacy/xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/7.0.68-1ubuntu0.4+esm4",
                                        "product": {
                                            "name": "vers:unknown/7.0.68-1ubuntu0.4+esm4",
                                            "product_id": "CSAFPID-8263928",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat7@7.0.68-1ubuntu0.4%2Besm4?arch=source&distro=esm-apps-legacy/xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-3764322"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "tomcat7"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/8.0.26-1",
                                        "product": {
                                            "name": "vers:unknown/8.0.26-1",
                                            "product_id": "CSAFPID-3764290",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat8@8.0.26-1?arch=source&distro=esm-infra/xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/8.0.28-1",
                                        "product": {
                                            "name": "vers:unknown/8.0.28-1",
                                            "product_id": "CSAFPID-3764291",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat8@8.0.28-1?arch=source&distro=esm-infra/xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/8.0.30-1",
                                        "product": {
                                            "name": "vers:unknown/8.0.30-1",
                                            "product_id": "CSAFPID-3764292",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat8@8.0.30-1?arch=source&distro=esm-infra/xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/8.0.32-1",
                                        "product": {
                                            "name": "vers:unknown/8.0.32-1",
                                            "product_id": "CSAFPID-3764293",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat8@8.0.32-1?arch=source&distro=esm-infra/xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/8.0.32-1ubuntu1",
                                        "product": {
                                            "name": "vers:unknown/8.0.32-1ubuntu1",
                                            "product_id": "CSAFPID-3764294",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat8@8.0.32-1ubuntu1?arch=source&distro=esm-infra/xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/8.0.32-1ubuntu1.1",
                                        "product": {
                                            "name": "vers:unknown/8.0.32-1ubuntu1.1",
                                            "product_id": "CSAFPID-3764295",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat8@8.0.32-1ubuntu1.1?arch=source&distro=esm-infra/xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/8.0.32-1ubuntu1.10",
                                        "product": {
                                            "name": "vers:unknown/8.0.32-1ubuntu1.10",
                                            "product_id": "CSAFPID-3764304",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat8@8.0.32-1ubuntu1.10?arch=source&distro=esm-infra/xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/8.0.32-1ubuntu1.11",
                                        "product": {
                                            "name": "vers:unknown/8.0.32-1ubuntu1.11",
                                            "product_id": "CSAFPID-3764305",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat8@8.0.32-1ubuntu1.11?arch=source&distro=esm-infra/xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/8.0.32-1ubuntu1.13",
                                        "product": {
                                            "name": "vers:unknown/8.0.32-1ubuntu1.13",
                                            "product_id": "CSAFPID-3764306",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat8@8.0.32-1ubuntu1.13?arch=source&distro=esm-infra/xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/8.0.32-1ubuntu1.13+esm1",
                                        "product": {
                                            "name": "vers:unknown/8.0.32-1ubuntu1.13+esm1",
                                            "product_id": "CSAFPID-3764307",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat8@8.0.32-1ubuntu1.13%2Besm1?arch=source&distro=esm-infra/xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/8.0.32-1ubuntu1.2",
                                        "product": {
                                            "name": "vers:unknown/8.0.32-1ubuntu1.2",
                                            "product_id": "CSAFPID-3764296",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat8@8.0.32-1ubuntu1.2?arch=source&distro=esm-infra/xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/8.0.32-1ubuntu1.3",
                                        "product": {
                                            "name": "vers:unknown/8.0.32-1ubuntu1.3",
                                            "product_id": "CSAFPID-3764297",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat8@8.0.32-1ubuntu1.3?arch=source&distro=esm-infra/xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/8.0.32-1ubuntu1.4",
                                        "product": {
                                            "name": "vers:unknown/8.0.32-1ubuntu1.4",
                                            "product_id": "CSAFPID-3764298",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat8@8.0.32-1ubuntu1.4?arch=source&distro=esm-infra/xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/8.0.32-1ubuntu1.5",
                                        "product": {
                                            "name": "vers:unknown/8.0.32-1ubuntu1.5",
                                            "product_id": "CSAFPID-3764299",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat8@8.0.32-1ubuntu1.5?arch=source&distro=esm-infra/xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/8.0.32-1ubuntu1.6",
                                        "product": {
                                            "name": "vers:unknown/8.0.32-1ubuntu1.6",
                                            "product_id": "CSAFPID-3764300",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat8@8.0.32-1ubuntu1.6?arch=source&distro=esm-infra/xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/8.0.32-1ubuntu1.7",
                                        "product": {
                                            "name": "vers:unknown/8.0.32-1ubuntu1.7",
                                            "product_id": "CSAFPID-3764301",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat8@8.0.32-1ubuntu1.7?arch=source&distro=esm-infra/xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/8.0.32-1ubuntu1.8",
                                        "product": {
                                            "name": "vers:unknown/8.0.32-1ubuntu1.8",
                                            "product_id": "CSAFPID-3764302",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat8@8.0.32-1ubuntu1.8?arch=source&distro=esm-infra/xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/8.0.32-1ubuntu1.9",
                                        "product": {
                                            "name": "vers:unknown/8.0.32-1ubuntu1.9",
                                            "product_id": "CSAFPID-3764303",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat8@8.0.32-1ubuntu1.9?arch=source&distro=esm-infra/xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-3764308"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "tomcat8"
                            }
                        ],
                        "category": "product_family",
                        "name": "Ubuntu:Pro:16.04:LTS"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/8.5.21-1ubuntu1",
                                        "product": {
                                            "name": "vers:unknown/8.5.21-1ubuntu1",
                                            "product_id": "CSAFPID-3764326",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat8@8.5.21-1ubuntu1?arch=source&distro=esm-apps/bionic"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/8.5.29-1",
                                        "product": {
                                            "name": "vers:unknown/8.5.29-1",
                                            "product_id": "CSAFPID-3764327",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat8@8.5.29-1?arch=source&distro=esm-apps/bionic"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/8.5.30-1",
                                        "product": {
                                            "name": "vers:unknown/8.5.30-1",
                                            "product_id": "CSAFPID-3764328",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat8@8.5.30-1?arch=source&distro=esm-apps/bionic"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/8.5.30-1ubuntu1",
                                        "product": {
                                            "name": "vers:unknown/8.5.30-1ubuntu1",
                                            "product_id": "CSAFPID-3764329",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat8@8.5.30-1ubuntu1?arch=source&distro=esm-apps/bionic"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/8.5.30-1ubuntu1.2",
                                        "product": {
                                            "name": "vers:unknown/8.5.30-1ubuntu1.2",
                                            "product_id": "CSAFPID-3764330",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat8@8.5.30-1ubuntu1.2?arch=source&distro=esm-apps/bionic"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/8.5.30-1ubuntu1.3",
                                        "product": {
                                            "name": "vers:unknown/8.5.30-1ubuntu1.3",
                                            "product_id": "CSAFPID-3764331",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat8@8.5.30-1ubuntu1.3?arch=source&distro=esm-apps/bionic"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/8.5.30-1ubuntu1.4",
                                        "product": {
                                            "name": "vers:unknown/8.5.30-1ubuntu1.4",
                                            "product_id": "CSAFPID-3764332",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat8@8.5.30-1ubuntu1.4?arch=source&distro=esm-apps/bionic"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/8.5.39-1ubuntu1~18.04.1",
                                        "product": {
                                            "name": "vers:unknown/8.5.39-1ubuntu1~18.04.1",
                                            "product_id": "CSAFPID-3764333",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat8@8.5.39-1ubuntu1~18.04.1?arch=source&distro=esm-apps/bionic"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/8.5.39-1ubuntu1~18.04.2",
                                        "product": {
                                            "name": "vers:unknown/8.5.39-1ubuntu1~18.04.2",
                                            "product_id": "CSAFPID-3764334",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat8@8.5.39-1ubuntu1~18.04.2?arch=source&distro=esm-apps/bionic"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/8.5.39-1ubuntu1~18.04.3",
                                        "product": {
                                            "name": "vers:unknown/8.5.39-1ubuntu1~18.04.3",
                                            "product_id": "CSAFPID-3764335",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat8@8.5.39-1ubuntu1~18.04.3?arch=source&distro=esm-apps/bionic"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/8.5.39-1ubuntu1~18.04.3+esm1",
                                        "product": {
                                            "name": "vers:unknown/8.5.39-1ubuntu1~18.04.3+esm1",
                                            "product_id": "CSAFPID-3764336",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat8@8.5.39-1ubuntu1~18.04.3%2Besm1?arch=source&distro=esm-apps/bionic"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/8.5.39-1ubuntu1~18.04.3+esm2",
                                        "product": {
                                            "name": "vers:unknown/8.5.39-1ubuntu1~18.04.3+esm2",
                                            "product_id": "CSAFPID-3764337",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat8@8.5.39-1ubuntu1~18.04.3%2Besm2?arch=source&distro=esm-apps/bionic"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/8.5.39-1ubuntu1~18.04.3+esm3",
                                        "product": {
                                            "name": "vers:unknown/8.5.39-1ubuntu1~18.04.3+esm3",
                                            "product_id": "CSAFPID-3764338",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat8@8.5.39-1ubuntu1~18.04.3%2Besm3?arch=source&distro=esm-apps/bionic"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/8.5.39-1ubuntu1~18.04.3+esm4",
                                        "product": {
                                            "name": "vers:unknown/8.5.39-1ubuntu1~18.04.3+esm4",
                                            "product_id": "CSAFPID-3764339",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat8@8.5.39-1ubuntu1~18.04.3%2Besm4?arch=source&distro=esm-apps/bionic"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/8.5.39-1ubuntu1~18.04.3+esm5",
                                        "product": {
                                            "name": "vers:unknown/8.5.39-1ubuntu1~18.04.3+esm5",
                                            "product_id": "CSAFPID-3764340",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat8@8.5.39-1ubuntu1~18.04.3%2Besm5?arch=source&distro=esm-apps/bionic"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-3764341"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "tomcat8"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.16-3ubuntu0.18.04.1",
                                        "product": {
                                            "name": "vers:unknown/9.0.16-3ubuntu0.18.04.1",
                                            "product_id": "CSAFPID-3764343",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.16-3ubuntu0.18.04.1?arch=source&distro=esm-apps/bionic"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.16-3ubuntu0.18.04.2",
                                        "product": {
                                            "name": "vers:unknown/9.0.16-3ubuntu0.18.04.2",
                                            "product_id": "CSAFPID-3764344",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.16-3ubuntu0.18.04.2?arch=source&distro=esm-apps/bionic"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.16-3ubuntu0.18.04.2+esm1",
                                        "product": {
                                            "name": "vers:unknown/9.0.16-3ubuntu0.18.04.2+esm1",
                                            "product_id": "CSAFPID-3764345",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.16-3ubuntu0.18.04.2%2Besm1?arch=source&distro=esm-apps/bionic"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.16-3ubuntu0.18.04.2+esm2",
                                        "product": {
                                            "name": "vers:unknown/9.0.16-3ubuntu0.18.04.2+esm2",
                                            "product_id": "CSAFPID-3764346",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.16-3ubuntu0.18.04.2%2Besm2?arch=source&distro=esm-apps/bionic"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.16-3ubuntu0.18.04.2+esm3",
                                        "product": {
                                            "name": "vers:unknown/9.0.16-3ubuntu0.18.04.2+esm3",
                                            "product_id": "CSAFPID-3764347",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.16-3ubuntu0.18.04.2%2Besm3?arch=source&distro=esm-apps/bionic"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.16-3ubuntu0.18.04.2+esm4",
                                        "product": {
                                            "name": "vers:unknown/9.0.16-3ubuntu0.18.04.2+esm4",
                                            "product_id": "CSAFPID-3764348",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.16-3ubuntu0.18.04.2%2Besm4?arch=source&distro=esm-apps/bionic"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.16-3ubuntu0.18.04.2+esm5",
                                        "product": {
                                            "name": "vers:unknown/9.0.16-3ubuntu0.18.04.2+esm5",
                                            "product_id": "CSAFPID-3764349",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.16-3ubuntu0.18.04.2%2Besm5?arch=source&distro=esm-apps/bionic"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.16-3ubuntu0.18.04.2+esm6",
                                        "product": {
                                            "name": "vers:unknown/9.0.16-3ubuntu0.18.04.2+esm6",
                                            "product_id": "CSAFPID-3764350",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.16-3ubuntu0.18.04.2%2Besm6?arch=source&distro=esm-apps/bionic"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.16-3ubuntu0.18.04.2+esm7",
                                        "product": {
                                            "name": "vers:unknown/9.0.16-3ubuntu0.18.04.2+esm7",
                                            "product_id": "CSAFPID-3764351",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.16-3ubuntu0.18.04.2%2Besm7?arch=source&distro=esm-apps/bionic"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.16-3ubuntu0.18.04.2+esm8",
                                        "product": {
                                            "name": "vers:unknown/9.0.16-3ubuntu0.18.04.2+esm8",
                                            "product_id": "CSAFPID-8263920",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.16-3ubuntu0.18.04.2%2Besm8?arch=source&distro=esm-apps/bionic"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.16-3~18.04.1",
                                        "product": {
                                            "name": "vers:unknown/9.0.16-3~18.04.1",
                                            "product_id": "CSAFPID-3764342",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.16-3~18.04.1?arch=source&distro=esm-apps/bionic"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-3764352"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "tomcat9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Ubuntu:Pro:18.04:LTS"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.24-1",
                                        "product": {
                                            "name": "vers:unknown/9.0.24-1",
                                            "product_id": "CSAFPID-3764353",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.24-1?arch=source&distro=esm-apps/focal"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.27-1",
                                        "product": {
                                            "name": "vers:unknown/9.0.27-1",
                                            "product_id": "CSAFPID-3764354",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.27-1?arch=source&distro=esm-apps/focal"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.31-1",
                                        "product": {
                                            "name": "vers:unknown/9.0.31-1",
                                            "product_id": "CSAFPID-3764355",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.31-1?arch=source&distro=esm-apps/focal"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.31-1ubuntu0.1",
                                        "product": {
                                            "name": "vers:unknown/9.0.31-1ubuntu0.1",
                                            "product_id": "CSAFPID-3764356",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.31-1ubuntu0.1?arch=source&distro=esm-apps/focal"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.31-1ubuntu0.2",
                                        "product": {
                                            "name": "vers:unknown/9.0.31-1ubuntu0.2",
                                            "product_id": "CSAFPID-3764357",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.31-1ubuntu0.2?arch=source&distro=esm-apps/focal"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.31-1ubuntu0.3",
                                        "product": {
                                            "name": "vers:unknown/9.0.31-1ubuntu0.3",
                                            "product_id": "CSAFPID-3764358",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.31-1ubuntu0.3?arch=source&distro=esm-apps/focal"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.31-1ubuntu0.4",
                                        "product": {
                                            "name": "vers:unknown/9.0.31-1ubuntu0.4",
                                            "product_id": "CSAFPID-3764359",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.31-1ubuntu0.4?arch=source&distro=esm-apps/focal"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.31-1ubuntu0.5",
                                        "product": {
                                            "name": "vers:unknown/9.0.31-1ubuntu0.5",
                                            "product_id": "CSAFPID-3764360",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.31-1ubuntu0.5?arch=source&distro=esm-apps/focal"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.31-1ubuntu0.6",
                                        "product": {
                                            "name": "vers:unknown/9.0.31-1ubuntu0.6",
                                            "product_id": "CSAFPID-3764361",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.31-1ubuntu0.6?arch=source&distro=esm-apps/focal"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.31-1ubuntu0.7",
                                        "product": {
                                            "name": "vers:unknown/9.0.31-1ubuntu0.7",
                                            "product_id": "CSAFPID-3764362",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.31-1ubuntu0.7?arch=source&distro=esm-apps/focal"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.31-1ubuntu0.8",
                                        "product": {
                                            "name": "vers:unknown/9.0.31-1ubuntu0.8",
                                            "product_id": "CSAFPID-3764363",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.31-1ubuntu0.8?arch=source&distro=esm-apps/focal"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.31-1ubuntu0.9",
                                        "product": {
                                            "name": "vers:unknown/9.0.31-1ubuntu0.9",
                                            "product_id": "CSAFPID-3764364",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.31-1ubuntu0.9?arch=source&distro=esm-apps/focal"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.31-1ubuntu0.9+esm1",
                                        "product": {
                                            "name": "vers:unknown/9.0.31-1ubuntu0.9+esm1",
                                            "product_id": "CSAFPID-3764365",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.31-1ubuntu0.9%2Besm1?arch=source&distro=esm-apps/focal"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.31-1ubuntu0.9+esm2",
                                        "product": {
                                            "name": "vers:unknown/9.0.31-1ubuntu0.9+esm2",
                                            "product_id": "CSAFPID-3764366",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.31-1ubuntu0.9%2Besm2?arch=source&distro=esm-apps/focal"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.31-1ubuntu0.9+esm3",
                                        "product": {
                                            "name": "vers:unknown/9.0.31-1ubuntu0.9+esm3",
                                            "product_id": "CSAFPID-8263921",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.31-1ubuntu0.9%2Besm3?arch=source&distro=esm-apps/focal"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-3764367"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "tomcat9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Ubuntu:Pro:20.04:LTS"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.43-3",
                                        "product": {
                                            "name": "vers:unknown/9.0.43-3",
                                            "product_id": "CSAFPID-6243297",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.43-3?arch=source&distro=esm-apps/jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.54-1",
                                        "product": {
                                            "name": "vers:unknown/9.0.54-1",
                                            "product_id": "CSAFPID-6243298",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.54-1?arch=source&distro=esm-apps/jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.55-1",
                                        "product": {
                                            "name": "vers:unknown/9.0.55-1",
                                            "product_id": "CSAFPID-6243299",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.55-1?arch=source&distro=esm-apps/jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.58-1",
                                        "product": {
                                            "name": "vers:unknown/9.0.58-1",
                                            "product_id": "CSAFPID-6243300",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.58-1?arch=source&distro=esm-apps/jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.58-1ubuntu0.1",
                                        "product": {
                                            "name": "vers:unknown/9.0.58-1ubuntu0.1",
                                            "product_id": "CSAFPID-6243301",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.58-1ubuntu0.1?arch=source&distro=esm-apps/jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.58-1ubuntu0.1+esm1",
                                        "product": {
                                            "name": "vers:unknown/9.0.58-1ubuntu0.1+esm1",
                                            "product_id": "CSAFPID-6243302",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.58-1ubuntu0.1%2Besm1?arch=source&distro=esm-apps/jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.58-1ubuntu0.1+esm2",
                                        "product": {
                                            "name": "vers:unknown/9.0.58-1ubuntu0.1+esm2",
                                            "product_id": "CSAFPID-6243545",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.58-1ubuntu0.1%2Besm2?arch=source&distro=esm-apps/jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.58-1ubuntu0.1+esm3",
                                        "product": {
                                            "name": "vers:unknown/9.0.58-1ubuntu0.1+esm3",
                                            "product_id": "CSAFPID-6243546",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.58-1ubuntu0.1%2Besm3?arch=source&distro=esm-apps/jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.58-1ubuntu0.1+esm4",
                                        "product": {
                                            "name": "vers:unknown/9.0.58-1ubuntu0.1+esm4",
                                            "product_id": "CSAFPID-6243547",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.58-1ubuntu0.1%2Besm4?arch=source&distro=esm-apps/jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.58-1ubuntu0.2",
                                        "product": {
                                            "name": "vers:unknown/9.0.58-1ubuntu0.2",
                                            "product_id": "CSAFPID-6243548",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.58-1ubuntu0.2?arch=source&distro=esm-apps/jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.58-1ubuntu0.2+esm1",
                                        "product": {
                                            "name": "vers:unknown/9.0.58-1ubuntu0.2+esm1",
                                            "product_id": "CSAFPID-6243549",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.58-1ubuntu0.2%2Besm1?arch=source&distro=esm-apps/jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.58-1ubuntu0.2+esm2",
                                        "product": {
                                            "name": "vers:unknown/9.0.58-1ubuntu0.2+esm2",
                                            "product_id": "CSAFPID-6243550",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.58-1ubuntu0.2%2Besm2?arch=source&distro=esm-apps/jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.58-1ubuntu0.2+esm3",
                                        "product": {
                                            "name": "vers:unknown/9.0.58-1ubuntu0.2+esm3",
                                            "product_id": "CSAFPID-7053077",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.58-1ubuntu0.2%2Besm3?arch=source&distro=esm-apps/jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.0.58-1ubuntu0.2+esm4",
                                        "product": {
                                            "name": "vers:unknown/9.0.58-1ubuntu0.2+esm4",
                                            "product_id": "CSAFPID-8263922",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/tomcat9@9.0.58-1ubuntu0.2%2Besm4?arch=source&distro=esm-apps/jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-7053078"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "tomcat9"
                            }
                        ],
                        "category": "product_family",
                        "name": "Ubuntu:Pro:22.04:LTS"
                    }
                ],
                "category": "vendor",
                "name": "Ubuntu"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=0|<9.0.119",
                                "product": {
                                    "name": "vers:unknown/>=0|<9.0.119",
                                    "product_id": "CSAFPID-8537259"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=10.1.0|<10.1.56",
                                "product": {
                                    "name": "vers:unknown/>=10.1.0|<10.1.56",
                                    "product_id": "CSAFPID-8537260"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=11.0.0|<11.0.23",
                                "product": {
                                    "name": "vers:unknown/>=11.0.0|<11.0.23",
                                    "product_id": "CSAFPID-8537261"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "tomcat"
                    }
                ],
                "category": "vendor",
                "name": "Bitnami"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:deb/unknown",
                                        "product": {
                                            "name": "vers:deb/unknown",
                                            "product_id": "CSAFPID-2454482"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "tomcat10"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:deb/9.0.70-2",
                                        "product": {
                                            "name": "vers:deb/9.0.70-2",
                                            "product_id": "CSAFPID-2454484",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/debian/tomcat9@9.0.70-2?distro=bookworm"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "tomcat9"
                            }
                        ],
                        "category": "product_family",
                        "name": "bookworm"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:deb/9.0.70-2",
                                        "product": {
                                            "name": "vers:deb/9.0.70-2",
                                            "product_id": "CSAFPID-3052056",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/debian/tomcat9@9.0.70-2?distro=bullseye"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "tomcat9"
                            }
                        ],
                        "category": "product_family",
                        "name": "bullseye"
                    }
                ],
                "category": "vendor",
                "name": "Debian"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-55956",
            "cwe": {
                "id": "CWE-551",
                "name": "Incorrect Behavior Order: Authorization Before Parsing and Canonicalization"
            },
            "notes": [
                {
                    "category": "description",
                    "text": "Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that have reached end of support may also be affected.\n\nUsers are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.",
                    "title": "nvd - https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-55956"
                },
                {
                    "category": "description",
                    "text": "Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that have reached end of support may also be affected.\n\nUsers are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.",
                    "title": "cveprojectv5 - https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/55xxx/CVE-2026-55956.json"
                },
                {
                    "category": "description",
                    "text": "Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint.  This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that have reached end of support may also be affected.  Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.",
                    "title": "debian - https://security-tracker.debian.org/tracker/CVE-2026-55956"
                },
                {
                    "category": "description",
                    "text": "Apache Tomcat versions 11.0.0-M1 through 11.0.22, 10.1.0-M1 through 10.1.55, 9.0.0.M1 through 9.0.118, 8.5.0 through 8.5.100, 7.0.0 through 7.0.109 are susceptible to vulnerabilities which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data.",
                    "title": "netapp - https://security.netapp.com/advisory/ntap-20260703-0016"
                },
                {
                    "category": "description",
                    "text": "Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint.\n\nThis issue affects Apache Tomcat: from 11.0.0 through 11.0.22, from 10.1.0 through 10.1.55, from 9.0.0 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that have reached end of support may also be affected.\n\nUsers are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Bitnami%2FBIT-tomcat-2026-55956.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Ubuntu%2FUBUNTU-CVE-2026-55956.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that have reached end of support may also be affected.\n\nUsers are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-55956.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "This update for tomcat fixes the following issues\n\nUpdate to Tomcat 9.0.119.\n\nSecurity issues fixed:\n\n- CVE-2026-50229: improper neutralization of script-related HTML tags in the number guess example (bsc#1269791).\n- CVE-2026-53404: always-incorrect control flow implementation in the rewrite valve caused non-OR conditions to be\n  skipped if the first condition in an OR chain matched (bsc#1269910).\n- CVE-2026-53434: error condition not handled when configuring CRLs for a FFM based connector (bsc#1269824).\n- CVE-2026-55276: always-incorrect control flow implementation caused special roles and empty authorization constraints\n  to not be included when the effective web.xml was logged (bsc#1269909).\n- CVE-2026-55955: improper authentication allows a replay attack against the EncryptionInterceptor in the cluster\n  component (bsc#1269908).\n- CVE-2026-55956: improper authorization leads to security constraints specified for the default servlet ignoring any\n  method or method omission configured as part of the constraint (bsc#1269907).\n\nOther updates and bugfixes:\n\n- Tomcat 9.0.119:\n  * Catalina\n    + Add: Add support for literal '%' characters in access log output. Based on\n      pull request #1002 by Fabian Hahn. (markt)\n    + Fix: Prevent duplicate log messages when clustering JARs are not present\n      on startup. (csutherl)\n    + Code: Remove unnecessary code from the SSI processing engine that was\n      duplicating some of the normalisation checks. (markt)\n    + Fix: Cleaner handling of invalid SPNEGO tokens. (remm)\n    + Fix: Avoid some NPEs in the Connector class on an uninitialize protocol.\n      (remm)\n    + Fix: Incorrect session average life calculation. (remm)\n    + Fix: Improve robustness on using Pipeline.setBasic on a running pipeline.\n      (remm)\n    + Fix: Avoid any init parameter updates when conflicts are found for\n      filters, similar to what is done for servlets, as required by the servlet\n      specification. (remm)\n    + Fix: Fix container event cleanups in some edge cases. (remm)\n    + Fix: Check for last-modified header in ExpiresFilter when a servlet uses\n      addDateHeader to avoid wrongly considering it has been set. (remm)\n    + Fix: Fix hour unit used by ExpiresFilter. (remm)\n    + Fix: Remove exception swallowing in DataSourceStore to align it with\n      FileStore and avoid session loss on errors. (remm)\n    + Fix: Add support for single-quote escaped literal as well as quoted\n      literals in DateFormatCache. (schultz)\n    + Fix: On JAAS logout, clear out role principals on the subject that were\n      added on commit, as recommended by the JAAS specification. (remm)\n    + Fix: MemoryRealm should not add a dummy role when none is specified in the\n      configuration. (remm)\n    + Fix: DataSourceUserDatabase should return a null principal on a non\n      existing user. (remm)\n    + Fix: Fix shared lock expiration in WebDAV. (remm)\n    + Fix: Inaccurate session exipration statistics when using the persistent\n      manager. (remm)\n    + Fix: Skip BOM when serving files with UTF-32 encoding. (remm)\n    + Fix: Mixup of WrapperListener and WrapperLifecycle elements in\n      storeconfig. (remm)\n    + Fix: Incorrect processing of modified users in DataSourceUserDatabase.\n      (remm)\n    + Update: Clarify behavior in the UserDatabase for user, role and group\n      creation that it does not immediately override existing elements. Removal\n      (or update) needs to be used instead. (remm)\n    + Fix: 70049: Align the web application class loader with parent class\n      loaders and swallow any errors caused by invalid paths when looking up\n      resources and behave as if the resources were not found in that case.\n      (markt)\n    + Fix: Improve validation of Range and Content-Range parsers so invalid\n      ranges trigger a 4xx response rather than a 500 response. Pull request\n      #1012 provided by Sahana Surendra Bogar. (markt)\n    + Fix: Fix connection leak in ProxyErrorReportValve. (remm)\n    + Fix: When using the RewriteValve, %{SSL:HTTPS} now returns on or off\n      rather than true or false to align with httpd. (markt)\n    + Fix: Reset the encoding used for query string parameters between requests\n      in case an application changed the encoding in a previous request. (markt)\n    + Fix: When encoding URLs with the CsrfPreventionFilter, don't add the nonce\n      to URLs that are known not to require it. (markt)\n    + Fix: Fix CombinedRealm isAvailable, it allows authentication if at least\n      one sub realm is available. (remm)\n    + Fix: 70048: Correctly handle asynchronous requests in PersistentValve.\n      (markt)\n    + Fix: Improve the detection of cross-context dispatches when using a\n      RequestDispatcher. (markt)\n    + Fix: Fix various instances of double decoding of URL patterns configured\n      either programmatically or in web.xml. (remm/markt)\n    + Fix: Align the rewrite conditions ornext flag processing with mod_rewrite,\n      which follows a purely sequential evaluation strategy. (remm)\n    + Fix: Change the default for the useRedirect attribute of the\n      ProxyErrorReportValve from true to false. (markt)\n    + Add: Add support for the showReport attribute in JsonErrorReportValve and\n      ProxyErrorReportValve. When set to false, detailed error information\n      (message, description, stack trace) is suppressed from error responses.\n      (dsoumis)\n    + Fix: Avoid a NoClassDefFoundError at startup when catalina-tribes.jar is\n      removed but catalina-ha.jar is present and the Cluster element is enabled\n      in server.xml. Cluster digester rules are now fully conditional on both\n      JARs being available. (dsoumis)\n    + Fix: Fix a potential deadlock when copying resources using WebDAV. (markt)\n    + Fix: Add jakarta., org.apache.catalina. and org.apache.tomcat.to the list\n      of reserved prefixes for SSI variables and request attributes. (markt)\n    + Fix: Missing URL decoding when processing addMapping on a Servlet\n      registration. (remm)\n    + Fix: The Timeout WebDAV header allows comma separated values (according to\n      the examples in the RFC). Use the first acceptable value. (remm)\n    + Fix: Fix various issues when logging the effective web.xml for a web\n      application. Empty sections are no longer logged. Special roles and empty\n      authorisation constraints are included. (markt)\n    + Fix: Expand the write lock for the save process in the MemoryUserDatabase\n      to avoid concurrency issues with the file save operations. (markt)\n    + Fix: Ensure atomic session persistence in FileStore. Based on pull request\n      #1016 by sahvx655-wq. (markt)\n    + Fix: Do not ignore methods configured on security constraints that map to\n      the default servlet. (markt)\n  * Cluster\n    + Fix: Expand wording and increase visibility of log message when cloud\n      membership is configured without a trust store as all certificates will be\n      trusted in this configuration. (markt)\n    + Fix: Ensure listeners are correctly added and removed when configuring the\n      channel coordinator. (markt)\n    + Fix: Fix some concurrency issues in FragmentationInterceptor. (markt)\n    + Fix: Fix some concurrency issues in OrderInterceptor. (markt)\n    + Fix: Fix some concurrency issues in TwoPhaseCommitInterceptor. (markt)\n    + Fix: Fix concurrency issues generating MD5 digests in the\n      CloudMembershipProvider implementations. (markt)\n    + Add: Add replay protection to the EncryptInterceptor. This is a breaking\n      change for the EncryptInterceptor. (markt)\n  * Coyote\n    + Add: Log a suitable warning if an encrypted PEM file is detected using an\n      insecure form for encryption. (markt)\n    + Fix: If TLS groups have been configured, use the configured groups rather\n      than using OpenSSL's default TLS groups when using Tomcat Native with\n      OpenSSL based connectors. (markt)\n    + Fix: For HTTP/2, ensure that any in progress request body reads are\n      cancelled if the container resets the associated stream. This prevents\n      delays waiting for reads to time out when it is known that no more data\n      will be received. (markt)\n    + Fix: Ensure that malformed HTTP/2 messages that should trigger a stream\n      reset do so, rather than triggered a connection close. (markt)\n    + Fix: Improve enforcement of header trailer allow list for HTTP/2. (remm)\n    + Fix: 70050: Avoid NPE when no header frame is processed in HTTP/2,\n      following refactor clean-up of header buffer. (remm)\n    + Fix: Properly use pollerThreadPriority for the NIO poller thread. (remm)\n    + Fix: Fix MessageByte.equals if called on a null MB. (remm)\n    + Fix: Call the delegate key manager in JSSE to retrieve the server key.\n      (remm)\n    + Fix: Avoid overflow scenarios in Asn1Parser. (remm)\n    + Fix: 70091: Add a new attribute, allowSchemeMismatch to Http2Protocol that\n      allows the consistency check for the scheme provided by the user agent to\n      be bypassed. (markt)\n    + Fix: isTrailerFieldsReady was always returning true. (remm)\n    + Fix: Align OpenSSL/Panama TLS implementation with other implementations\n      and throw an exception if there is an error loading the provided CRL(s).\n      (markt)\n    + Fix: Parsing of OpenSSL format cipher expressions incorrectly stopped if\n      @STRENGTH was encountered, ignoring any subsequent expressions. (markt)\n    + Fix: Handle the case where the HTTP/2 payload length is insufficient for\n      the mandatory data required by the flags set in the header. (markt)\n    + Fix: 70102: Correct expected size of ticket keys when calling\n      setSessionTicketKeys with an FFM connector. (markt)\n    + Fix: 69988: Fix post handshake authentication for TLS 1.3. It was broken\n      by a breaking change in OpenSSL between 1.1.1 and 3.0.0. (markt)\n    + Fix: When processing an OpenSSL cipher specification, fully align the\n      order of the resulting ciphers with the order produced by OpenSSL. (markt)\n    + Add: Add support for Brainpool TLS groups. Patch provided by YStankov.\n      (schultz)\n    + Update: Update both the minimum and recommended version for Tomcat Native\n      1.x to 1.3.8. (markt)\n  * Jasper\n    + Fix: Fix possible EL argument mismatch when it was set to null. (remm)\n    + Fix: Fix thread safety of TagPluginManager. (remm)\n    + Fix: Correctly use flush on JSP include. (remm)\n  * Web applications\n    + Add: Manager: Add checks to ensure that any uploaded files are uploaded to\n      the expected location. (markt)\n    + Add: Manager: Add checks to ensure that the requested context path for a\n      deployed WAR, directory or descriptor file is valid. (markt)\n    + Add: Documentation: Expand the description of some of the attributes of\n      the CrawlerSessionManagerValve. (markt)\n    + Fix: Documentation: Clearer description and correct documented default for\n      ocspSoftFail. (markt)\n    + Fix: Fix double escaping in the context names for the JSON mode of the\n      manager servlet. (remm)\n    + Fix: Manager: Ensure automatic deployment does not trigger an undeployment\n      during a Manager triggered web application reload. (markt)\n    + Fix: Documentation: Provide better documentation for the scheme and secure\n      attributes of a Connector. (markt)\n  * Websocket\n    + Fix: Incorrect Future.isDone() return by AsyncChannelWrapperSecure. (remm)\n    + Fix: Trigger standard WebSocket error handling if a call to\n      Endpoint.onOpen() fails for a programmatic endpoint. (markt)\n    + Fix: 70110: Fix memory leak if a call to Endpoint.onOpen() fails for a\n      programmatic endpoint. Test case provided by uabdur. (markt)\n    + Fix: If a client presents invalid parameters when negotiating a WebSocket\n      extension, decline the negotiation offer that includes the invalid\n      parameters rather than failing the connection. Pull request #1019 provided\n      by sahvx655-wq. (markt)\n  * Other\n    + Fix: Wrong references to jakarta instead of javax. (remm)\n    + Fix: Restore default authenticator to nullafter executing an Ant task.\n      (remm)\n    + Update: Update Commons Daemon to 1.6.1. (markt)\n    + Update: Improvements to French translations. (remm)\n    + Update: Improvements to Japanese translations provided by tak7iji. (markt)\n    + Update: Update Tomcat Native to 1.3.8. (markt)\n",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/SUSE%2FSUSE-SU-2026:3088-1.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "This update for tomcat11 fixes the following issues\n\nUpdate to Tomcat 11.0.23.\n\nSecurity issues fixed:\n\n- CVE-2026-50229: improper neutralization of script-related HTML tags in the number guess example (bsc#1269791).\n- CVE-2026-53404: always-incorrect control flow implementation in the rewrite valve caused non-OR conditions to be\n  skipped if the first condition in an OR chain matched (bsc#1269910).\n- CVE-2026-53434: error condition not handled when configuring CRLs for a FFM based connector (bsc#1269824).\n- CVE-2026-55276: always-incorrect control flow implementation caused special roles and empty authorization constraints\n  to not be included when the effective web.xml was logged (bsc#1269909).\n- CVE-2026-55955: improper authentication allows a replay attack against the EncryptionInterceptor in the cluster\n  component (bsc#1269908).\n- CVE-2026-55956: improper authorization leads to security constraints specified for the default servlet ignoring any\n  method or method omission configured as part of the constraint (bsc#1269907).\n\nOther updates and bugfixes:\n\n- Upgrade libtcnative to v2 (bsc#1232390).\n- Tomcat 11.0.23:\n  * Catalina\n    + Add: Add support for literal '%' characters in access log output. Based on\n      pull request #1002 by Fabian Hahn. (markt)\n    + Fix: Lower the log level to debug when OpenSSL initialization fails in\n      OpenSSLLifecycleListener to avoid stack traces when libssl.so is not\n      present and to align the behavior of the isAvailable() check with the\n      AprLifecycleListener and gracefully fail when natives are not present.\n      (csutherl)\n    + Fix: 70038: Cookie.clone() should also clone the internal attribute map.\n      (markt)\n    + Code: Remove unnecessary code from the SSI processing engine that was\n      duplicating some of the normalisation checks. (markt)\n    + Fix: Cleaner handling of invalid SPNEGO tokens. (remm)\n    + Fix: Avoid some NPEs in the Connector class on an uninitialize protocol.\n      (remm)\n    + Fix: Incorrect session average life calculation. (remm)\n    + Fix: Improve robustness on using Pipeline.setBasic on a running pipeline.\n      (remm)\n    + Fix: Avoid any init parameter updates when conflicts are found for\n      filters, similar to what is done for servlets, as required by the servlet\n      specification. (remm)\n    + Fix: Fix container event cleanups in some edge cases. (remm)\n    + Fix: Check for last-modified header in ExpiresFilter when a servlet uses\n      addDateHeader to avoid wrongly considering it has been set. (remm)\n    + Fix: Fix hour unit used by ExpiresFilter. (remm)\n    + Fix: Remove exception swallowing in DataSourceStore to align it with\n      FileStore and avoid session loss on errors. (remm)\n    + Fix: Add support for single-quote escaped literal as well as quoted\n      literals in DateFormatCache. (schultz)\n    + Fix: On JAAS logout, clear out role principals on the subject that were\n      added on commit, as recommended by the JAAS specification. (remm)\n    + Fix: MemoryRealm should not add a dummy role when none is specified in the\n      configuration. (remm)\n    + Fix: DataSourceUserDatabase should return a null principal on a non\n      existing user. (remm)\n    + Fix: Fix shared lock expiration in WebDAV. (remm)\n    + Fix: Inaccurate session exipration statistics when using the persistent\n      manager. (remm)\n    + Fix: Skip BOM when serving files with UTF-32 encoding. (remm)\n    + Fix: Mixup of WrapperListener and WrapperLifecycle elements in\n      storeconfig. (remm)\n    + Fix: Incorrect processing of modified users in DataSourceUserDatabase.\n      (remm)\n    + Update: Clarify behavior in the UserDatabase for user, role and group\n      creation that it does not immediately override existing elements. Removal\n      (or update) needs to be used instead. (remm)\n    + Fix: 70049: Align the web application class loader with parent class\n      loaders and swallow any errors caused by invalid paths when looking up\n      resources and behave as if the resources were not found in that case.\n      (markt)\n    + Fix: Improve validation of Range and Content-Range parsers so invalid\n      ranges trigger a 4xx response rather than a 500 response. Pull request\n      #1012 provided by Sahana Surendra Bogar. (markt)\n    + Fix: Fix connection leak in ProxyErrorReportValve. (remm)\n    + Fix: When using the RewriteValve, %{SSL:HTTPS} now returns on or off\n      rather than true or false to align with httpd. (markt)\n    + Fix: Reset the encoding used for query string parameters between requests\n      in case an application changed the encoding in a previous request. (markt)\n    + Fix: When encoding URLs with the CsrfPreventionFilter, don't add the nonce\n      to URLs that are known not to require it. (markt)\n    + Fix: Fix SSO cookie partitioned configuration. (remm)\n    + Fix: Fix CombinedRealm isAvailable, it allows authentication if at least\n      one sub realm is available. (remm)\n    + Fix: 70048: Correctly handle asynchronous requests in PersistentValve.\n      (markt)\n    + Fix: Improve the detection of cross-context dispatches when using a\n      RequestDispatcher. (markt)\n    + Fix: Fix various instances of double decoding of URL patterns configured\n      either programmatically or in web.xml. (remm/markt)\n    + Fix: Align the rewrite conditions ornext flag processing with mod_rewrite,\n      which follows a purely sequential evaluation strategy. (remm)\n    + Fix: Update default web.xml version to match supported Servlet\n      specification version. (markt)\n    + Fix: Change the default for the useRedirect attribute of the\n      ProxyErrorReportValve from true to false. (markt)\n    + Add: Add support for the showReport attribute in JsonErrorReportValve and\n      ProxyErrorReportValve. When set to false, detailed error information\n      (message, description, stack trace) is suppressed from error responses.\n      (dsoumis)\n    + Fix: Avoid a NoClassDefFoundError at startup when catalina-tribes.jar is\n      removed but catalina-ha.jar is present and the Cluster element is enabled\n      in server.xml. Cluster digester rules are now fully conditional on both\n      JARs being available. (dsoumis)\n    + Fix: Fix a potential deadlock when copying resources using WebDAV. (markt)\n    + Fix: Add jakarta., org.apache.catalina. and org.apache.tomcat.to the list\n      of reserved prefixes for SSI variables and request attributes. (markt)\n    + Fix: Missing URL decoding when processing addMapping on a Servlet\n      registration. (remm)\n    + Fix: The Timeout WebDAV header allows comma separated values (according to\n      the examples in the RFC). Use the first acceptable value. (remm)\n    + Fix: Fix various issues when logging the effective web.xml for a web\n      application. Empty sections are no longer logged. Special roles and empty\n      authorisation constraints are included. All session cookie attributes are\n      included. (markt)\n    + Fix: Expand the write lock for the save process in the MemoryUserDatabase\n      to avoid concurrency issues with the file save operations. (markt)\n    + Fix: Ensure atomic session persistence in FileStore. Based on pull request\n      #1016 by sahvx655-wq. (markt)\n    + Fix: Do not ignore methods configured on security constraints that map to\n      the default servlet. (markt)\n  * Cluster\n    + Fix: Expand wording and increase visibility of log message when cloud\n      membership is configured without a trust store as all certificates will be\n      trusted in this configuration. (markt)\n    + Fix: Ensure listeners are correctly added and removed when configuring the\n      channel coordinator. (markt)\n    + Fix: Fix some concurrency issues in FragmentationInterceptor. (markt)\n    + Fix: Fix some concurrency issues in OrderInterceptor. (markt)\n    + Fix: Fix some concurrency issues in TwoPhaseCommitInterceptor. (markt)\n    + Fix: Fix concurrency issues generating MD5 digests in the\n      CloudMembershipProvider implementations. (markt)\n    + Add: Add replay protection to the EncryptInterceptor. This us a breaking\n      change for the EncryptInterceptor.(markt)\n  * Coyote\n    + Add: Log a suitable warning if an encrypted PEM file is detected using an\n      insecure form for encryption. (markt)\n    + Fix: If TLS groups have been configured, use the configured groups rather\n      than using OpenSSL's default TLS groups when using Tomcat Native with\n      OpenSSL based connectors. (markt)\n    + Fix: For HTTP/2, ensure that any in progress request body reads are\n      cancelled if the container resets the associated stream. This prevents\n      delays waiting for reads to time out when it is known that no more data\n      will be received. (markt)\n    + Fix: Ensure that malformed HTTP/2 messages that should trigger a stream\n      reset do so, rather than triggered a connection close. (markt)\n    + Fix: Improve enforcement of header trailer allow list for HTTP/2. (remm)\n    + Fix: 70050: Avoid NPE when no header frame is processed in HTTP/2,\n      following refactor clean-up of header buffer. (remm)\n    + Fix: Properly use pollerThreadPriority for the NIO poller thread. (remm)\n    + Fix: Fix MessageByte.equals if called on a null MB. (remm)\n    + Fix: Call the delegate key manager in JSSE to retrieve the server key.\n      (remm)\n    + Fix: Avoid overflow scenarios in Asn1Parser. (remm)\n    + Fix: 70091: Add a new attribute, allowSchemeMismatch to Http2Protocol that\n      allows the consistency check for the scheme provided by the user agent to\n      be bypassed. (markt)\n    + Fix: isTrailerFieldsReady was always returning true. (remm)\n    + Fix: Align OpenSSL/Panama TLS implementation with other implementations\n      and throw an exception if there is an error loading the provided CRL(s).\n      (markt)\n    + Fix: Parsing of OpenSSL format cipher expressions incorrectly stopped if\n      @STRENGTH was encountered, ignoring any subsequent expressions. (markt)\n    + Fix: Handle the case where the HTTP/2 payload length is insufficient for\n      the mandatory data required by the flags set in the header. (markt)\n    + Fix: 70102: Correct expected size of ticket keys when calling\n      setSessionTicketKeys with an FFM connector. (markt)\n    + Fix: 69988: Fix post handshake authentication for TLS 1.3. It was broken\n      by a breaking change in OpenSSL between 1.1.1 and 3.0.0. (markt)\n    + Fix: When processing an OpenSSL cipher specification, fully align the\n      order of the resulting ciphers with the order produced by OpenSSL. (markt)\n    + Add: Add support for Brainpool TLS groups. Patch provided by YStankov.\n      (schultz)\n    + Update: Update both the minimum and recommended version for Tomcat Native\n      2.x to 2.0.15. (markt)\n    + Update: Update the minimum version for Tomcat Native 1.x to 1.3.8. (markt)\n  * Jasper\n    + Fix: Fix possible EL argument mismatch when it was set to null. (remm)\n    + Fix: Fix thread safety of TagPluginManager. (remm)\n    + Fix: Correctly use flush on JSP include. (remm)\n  * Web applications\n    + Add: Manager: Add checks to ensure that any uploaded files are uploaded to\n      the expected location. (markt)\n    + Add: Manager: Add checks to ensure that the requested context path for a\n      deployed WAR, directory or descriptor file is valid. (markt)\n    + Add: Documentation: Expand the description of some of the attributes of\n      the CrawlerSessionManagerValve. (markt)\n    + Fix: Documentation: Clearer description and correct documented default for\n      ocspSoftFail. (markt)\n    + Fix: Fix double escaping in the context names for the JSON mode of the\n      manager servlet. (remm)\n    + Fix: Manager: Ensure automatic deployment does not trigger an undeployment\n      during a Manager triggered web application reload. (markt)\n    + Fix: Documentation: Provide better documentation for the scheme and secure\n      attributes of a Connector. (markt)\n  * Websocket\n    + Fix: Incorrect Future.isDone() return by AsyncChannelWrapperSecure. (remm)\n    + Fix: Trigger standard WebSocket error handling if a call to\n      Endpoint.onOpen() fails for a programmatic endpoint. (markt)\n    + Fix: 70110: Fix memory leak if a call to Endpoint.onOpen() fails for a\n      programmatic endpoint. Test case provided by uabdur. (markt)\n    + Fix: If a client presents invalid parameters when negotiating a WebSocket\n      extension, decline the negotiation offer that includes the invalid\n      parameters rather than failing the connection. Pull request #1019 provided\n      by sahvx655-wq. (markt)\n  * Other\n    + Fix: Use per connection authenticator when executing an Ant task.\n      (remm/markt)\n    + Update: Update Commons Daemon to 1.6.1. (markt)\n    + Fix: Prevent duplicate log messages when clustering JARs are not present\n      on startup. (csutherl)\n    + Update: Improvements to French translations. (remm)\n    + Update: Improvements to Japanese translations provided by tak7iji. (markt)\n    + Update: Update the packaged version of the Tomcat Migration Tool for\n      Jakarta EE to 1.0.12. (markt)\n    + Update: Update Tomcat Native to 2.0.15. (markt)\n",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/SUSE%2FSUSE-SU-2026:3087-1.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "This update for tomcat10 fixes the following issues\n\nUpdate to Tomcat 10.1.56.\n\nSecurity issues fixed:\n\n- CVE-2026-50229: improper neutralization of script-related HTML tags in the number guess example (bsc#1269791).\n- CVE-2026-53404: always-incorrect control flow implementation in the rewrite valve caused non-OR conditions to be\n  skipped if the first condition in an OR chain matched (bsc#1269910).\n- CVE-2026-53434: error condition not handled when configuring CRLs for a FFM based connector (bsc#1269824).\n- CVE-2026-55276: always-incorrect control flow implementation caused special roles and empty authorization constraints\n  to not be included when the effective web.xml was logged (bsc#1269909).\n- CVE-2026-55955: improper authentication allows a replay attack against the EncryptionInterceptor in the cluster\n  component (bsc#1269908).\n- CVE-2026-55956: improper authorization leads to security constraints specified for the default servlet ignoring any\n  method or method omission configured as part of the constraint (bsc#1269907).\n\nOther updates and bugfixes:\n\n- Tomcat 10.1.56:\n  * Catalina\n    + Add: Add support for literal '%' characters in access log output. Based on\n      pull request #1002 by Fabian Hahn. (markt)\n    + Fix: Prevent duplicate log messages when clustering JARs are not present\n      on startup. (csutherl)\n    + Fix: 70038: Cookie.clone() should also clone the internal attribute map.\n      (markt)\n    + Code: Remove unnecessary code from the SSI processing engine that was\n      duplicating some of the normalisation checks. (markt)\n    + Fix: Cleaner handling of invalid SPNEGO tokens. (remm)\n    + Fix: Avoid some NPEs in the Connector class on an uninitialize protocol.\n      (remm)\n    + Fix: Incorrect session average life calculation. (remm)\n    + Fix: Improve robustness on using Pipeline.setBasic on a running pipeline.\n      (remm)\n    + Fix: Avoid any init parameter updates when conflicts are found for\n      filters, similar to what is done for servlets, as required by the servlet\n      specification. (remm)\n    + Fix: Fix container event cleanups in some edge cases. (remm)\n    + Fix: Check for last-modified header in ExpiresFilter when a servlet uses\n      addDateHeader to avoid wrongly considering it has been set. (remm)\n    + Fix: Fix hour unit used by ExpiresFilter. (remm)\n    + Fix: Remove exception swallowing in DataSourceStore to align it with\n      FileStore and avoid session loss on errors. (remm)\n    + Fix: Add support for single-quote escaped literal as well as quoted\n      literals in DateFormatCache. (schultz)\n    + Fix: On JAAS logout, clear out role principals on the subject that were\n      added on commit, as recommended by the JAAS specification. (remm)\n    + Fix: MemoryRealm should not add a dummy role when none is specified in the\n      configuration. (remm)\n    + Fix: DataSourceUserDatabase should return a null principal on a non\n      existing user. (remm)\n    + Fix: Fix shared lock expiration in WebDAV. (remm)\n    + Fix: Inaccurate session exipration statistics when using the persistent\n      manager. (remm)\n    + Fix: Skip BOM when serving files with UTF-32 encoding. (remm)\n    + Fix: Mixup of WrapperListener and WrapperLifecycle elements in\n      storeconfig. (remm)\n    + Fix: Incorrect processing of modified users in DataSourceUserDatabase.\n      (remm)\n    + Update: Clarify behavior in the UserDatabase for user, role and group\n      creation that it does not immediately override existing elements. Removal\n      (or update) needs to be used instead. (remm)\n    + Fix: 70049: Align the web application class loader with parent class\n      loaders and swallow any errors caused by invalid paths when looking up\n      resources and behave as if the resources were not found in that case.\n      (markt)\n    + Fix: Improve validation of Range and Content-Range parsers so invalid\n      ranges trigger a 4xx response rather than a 500 response. Pull request\n      #1012 provided by Sahana Surendra Bogar. (markt)\n    + Fix: Fix connection leak in ProxyErrorReportValve. (remm)\n    + Fix: When using the RewriteValve, %{SSL:HTTPS} now returns on or off\n      rather than true or false to align with httpd. (markt)\n    + Fix: Reset the encoding used for query string parameters between requests\n      in case an application changed the encoding in a previous request. (markt)\n    + Fix: When encoding URLs with the CsrfPreventionFilter, don't add the nonce\n      to URLs that are known not to require it. (markt)\n    + Fix: Fix CombinedRealm isAvailable, it allows authentication if at least\n      one sub realm is available. (remm)\n    + Fix: 70048: Correctly handle asynchronous requests in PersistentValve.\n      (markt)\n    + Fix: Improve the detection of cross-context dispatches when using a\n      RequestDispatcher. (markt)\n    + Fix: Fix various instances of double decoding of URL patterns configured\n      either programmatically or in web.xml. (remm/markt)\n    + Fix: Align the rewrite conditions ornext flag processing with mod_rewrite,\n      which follows a purely sequential evaluation strategy. (remm)\n    + Fix: Change the default for the useRedirect attribute of the\n      ProxyErrorReportValve from true to false. (markt)\n    + Add: Add support for the showReport attribute in JsonErrorReportValve and\n      ProxyErrorReportValve. When set to false, detailed error information\n      (message, description, stack trace) is suppressed from error responses.\n      (dsoumis)\n    + Fix: Avoid a NoClassDefFoundError at startup when catalina-tribes.jar is\n      removed but catalina-ha.jar is present and the Cluster element is enabled\n      in server.xml. Cluster digester rules are now fully conditional on both\n      JARs being available. (dsoumis)\n    + Fix: Fix a potential deadlock when copying resources using WebDAV. (markt)\n    + Fix: Add jakarta., org.apache.catalina. and org.apache.tomcat.to the list\n      of reserved prefixes for SSI variables and request attributes. (markt)\n    + Fix: Missing URL decoding when processing addMapping on a Servlet\n      registration. (remm)\n    + Fix: The Timeout WebDAV header allows comma separated values (according to\n      the examples in the RFC). Use the first acceptable value. (remm)\n    + Fix: Fix various issues when logging the effective web.xml for a web\n      application. Empty sections are no longer logged. Special roles and empty\n      authorisation constraints are included. All session cookie attributes are\n      included. (markt)\n    + Fix: Expand the write lock for the save process in the MemoryUserDatabase\n      to avoid concurrency issues with the file save operations. (markt)\n    + Fix: Ensure atomic session persistence in FileStore. Based on pull request\n      #1016 by sahvx655-wq. (markt)\n    + Fix: Do not ignore methods configured on security constraints that map to\n      the default servlet. (markt)\n  * Cluster\n    + Fix: Expand wording and increase visibility of log message when cloud\n      membership is configured without a trust store as all certificates will be\n      trusted in this configuration. (markt)\n    + Fix: Ensure listeners are correctly added and removed when configuring the\n      channel coordinator. (markt)\n    + Fix: Fix some concurrency issues in FragmentationInterceptor. (markt)\n    + Fix: Fix some concurrency issues in OrderInterceptor. (markt)\n    + Fix: Fix some concurrency issues in TwoPhaseCommitInterceptor. (markt)\n    + Fix: Fix concurrency issues generating MD5 digests in the\n      CloudMembershipProvider implementations. (markt)\n    + Add: Add replay protection to the EncryptInterceptor. This is a breaking\n      change for the EncryptInterceptor. (markt)\n  * Coyote\n    + Add: Log a suitable warning if an encrypted PEM file is detected using an\n      insecure form for encryption. (markt)\n    + Fix: If TLS groups have been configured, use the configured groups rather\n      than using OpenSSL's default TLS groups when using Tomcat Native with\n      OpenSSL based connectors. (markt)\n    + Fix: For HTTP/2, ensure that any in progress request body reads are\n      cancelled if the container resets the associated stream. This prevents\n      delays waiting for reads to time out when it is known that no more data\n      will be received. (markt)\n    + Fix: Ensure that malformed HTTP/2 messages that should trigger a stream\n      reset do so, rather than triggered a connection close. (markt)\n    + Fix: Improve enforcement of header trailer allow list for HTTP/2. (remm)\n    + Fix: 70050: Avoid NPE when no header frame is processed in HTTP/2,\n      following refactor clean-up of header buffer. (remm)\n    + Fix: Properly use pollerThreadPriority for the NIO poller thread. (remm)\n    + Fix: Fix MessageByte.equals if called on a null MB. (remm)\n    + Fix: Call the delegate key manager in JSSE to retrieve the server key.\n      (remm)\n    + Fix: Avoid overflow scenarios in Asn1Parser. (remm)\n    + Fix: 70091: Add a new attribute, allowSchemeMismatch to Http2Protocol that\n      allows the consistency check for the scheme provided by the user agent to\n      be bypassed. (markt)\n    + Fix: isTrailerFieldsReady was always returning true. (remm)\n    + Fix: Align OpenSSL/Panama TLS implementation with other implementations\n      and throw an exception if there is an error loading the provided CRL(s).\n      (markt)\n    + Fix: Parsing of OpenSSL format cipher expressions incorrectly stopped if\n      @STRENGTH was encountered, ignoring any subsequent expressions. (markt)\n    + Fix: Handle the case where the HTTP/2 payload length is insufficient for\n      the mandatory data required by the flags set in the header. (markt)\n    + Fix: 70102: Correct expected size of ticket keys when calling\n      setSessionTicketKeys with an FFM connector. (markt)\n    + Fix: 69988: Fix post handshake authentication for TLS 1.3. It was broken\n      by a breaking change in OpenSSL between 1.1.1 and 3.0.0. (markt)\n    + Fix: When processing an OpenSSL cipher specification, fully align the\n      order of the resulting ciphers with the order produced by OpenSSL. (markt)\n    + Add: Add support for Brainpool TLS groups. Patch provided by YStankov.\n      (schultz)\n    + Update: Update both the minimum and recommended version for Tomcat Native\n      2.x to 2.0.15. (markt)\n    + Update: Update the minimum version for Tomcat Native 1.x to 1.3.8. (markt)\n  * Jasper\n    + Fix: Fix possible EL argument mismatch when it was set to null. (remm)\n    + Fix: Fix thread safety of TagPluginManager. (remm)\n    + Fix: Correctly use flush on JSP include. (remm)\n  * Web applications\n    + Add: Manager: Add checks to ensure that any uploaded files are uploaded to\n      the expected location. (markt)\n    + Add: Manager: Add checks to ensure that the requested context path for a\n      deployed WAR, directory or descriptor file is valid. (markt)\n    + Add: Documentation: Expand the description of some of the attributes of\n      the CrawlerSessionManagerValve. (markt)\n    + Fix: Documentation: Clearer description and correct documented default for\n      ocspSoftFail. (markt)\n    + Fix: Fix double escaping in the context names for the JSON mode of the\n      manager servlet. (remm)\n    + Fix: Manager: Ensure automatic deployment does not trigger an undeployment\n      during a Manager triggered web application reload. (markt)\n    + Fix: Documentation: Provide better documentation for the scheme and secure\n      attributes of a Connector. (markt)\n  * Websocket\n    + Fix: Incorrect Future.isDone() return by AsyncChannelWrapperSecure. (remm)\n    + Fix: Trigger standard WebSocket error handling if a call to\n      Endpoint.onOpen() fails for a programmatic endpoint. (markt)\n    + Fix: 70110: Fix memory leak if a call to Endpoint.onOpen() fails for a\n      programmatic endpoint. Test case provided by uabdur. (markt)\n    + Fix: If a client presents invalid parameters when negotiating a WebSocket\n      extension, decline the negotiation offer that includes the invalid\n      parameters rather than failing the connection. Pull request #1019 provided\n      by sahvx655-wq. (markt)\n  * Other\n    + Fix: Use per connection authenticator when executing an Ant task.\n      (remm/markt)\n    + Update: Update Commons Daemon to 1.6.1. (markt)\n    + Update: Improvements to French translations. (remm)\n    + Update: Improvements to Japanese translations provided by tak7iji. (markt)\n    + Update: Update the packaged version of the Tomcat Migration Tool for\n      Jakarta EE to 1.0.12. (markt)\n    + Update: Update Tomcat Native to 2.0.15. (markt)\n",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/SUSE%2FSUSE-SU-2026:22647-1.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "This update for tomcat fixes the following issues\n\nUpdate to Tomcat 9.0.119.\n\nSecurity issues fixed:\n\n- CVE-2026-50229: improper neutralization of script-related HTML tags in the number guess example (bsc#1269791).\n- CVE-2026-53404: always-incorrect control flow implementation in the rewrite valve caused non-OR conditions to be\n  skipped if the first condition in an OR chain matched (bsc#1269910).\n- CVE-2026-53434: error condition not handled when configuring CRLs for a FFM based connector (bsc#1269824).\n- CVE-2026-55276: always-incorrect control flow implementation caused special roles and empty authorization constraints\n  to not be included when the effective web.xml was logged (bsc#1269909).\n- CVE-2026-55955: improper authentication allows a replay attack against the EncryptionInterceptor in the cluster\n  component (bsc#1269908).\n- CVE-2026-55956: improper authorization leads to security constraints specified for the default servlet ignoring any\n  method or method omission configured as part of the constraint (bsc#1269907).\n\nOther updates and bugfixes:\n\n- Tomcat 9.0.119:\n  * Catalina\n    + Add: Add support for literal '%' characters in access log output. Based on\n      pull request #1002 by Fabian Hahn. (markt)\n    + Fix: Prevent duplicate log messages when clustering JARs are not present\n      on startup. (csutherl)\n    + Code: Remove unnecessary code from the SSI processing engine that was\n      duplicating some of the normalisation checks. (markt)\n    + Fix: Cleaner handling of invalid SPNEGO tokens. (remm)\n    + Fix: Avoid some NPEs in the Connector class on an uninitialize protocol.\n      (remm)\n    + Fix: Incorrect session average life calculation. (remm)\n    + Fix: Improve robustness on using Pipeline.setBasic on a running pipeline.\n      (remm)\n    + Fix: Avoid any init parameter updates when conflicts are found for\n      filters, similar to what is done for servlets, as required by the servlet\n      specification. (remm)\n    + Fix: Fix container event cleanups in some edge cases. (remm)\n    + Fix: Check for last-modified header in ExpiresFilter when a servlet uses\n      addDateHeader to avoid wrongly considering it has been set. (remm)\n    + Fix: Fix hour unit used by ExpiresFilter. (remm)\n    + Fix: Remove exception swallowing in DataSourceStore to align it with\n      FileStore and avoid session loss on errors. (remm)\n    + Fix: Add support for single-quote escaped literal as well as quoted\n      literals in DateFormatCache. (schultz)\n    + Fix: On JAAS logout, clear out role principals on the subject that were\n      added on commit, as recommended by the JAAS specification. (remm)\n    + Fix: MemoryRealm should not add a dummy role when none is specified in the\n      configuration. (remm)\n    + Fix: DataSourceUserDatabase should return a null principal on a non\n      existing user. (remm)\n    + Fix: Fix shared lock expiration in WebDAV. (remm)\n    + Fix: Inaccurate session exipration statistics when using the persistent\n      manager. (remm)\n    + Fix: Skip BOM when serving files with UTF-32 encoding. (remm)\n    + Fix: Mixup of WrapperListener and WrapperLifecycle elements in\n      storeconfig. (remm)\n    + Fix: Incorrect processing of modified users in DataSourceUserDatabase.\n      (remm)\n    + Update: Clarify behavior in the UserDatabase for user, role and group\n      creation that it does not immediately override existing elements. Removal\n      (or update) needs to be used instead. (remm)\n    + Fix: 70049: Align the web application class loader with parent class\n      loaders and swallow any errors caused by invalid paths when looking up\n      resources and behave as if the resources were not found in that case.\n      (markt)\n    + Fix: Improve validation of Range and Content-Range parsers so invalid\n      ranges trigger a 4xx response rather than a 500 response. Pull request\n      #1012 provided by Sahana Surendra Bogar. (markt)\n    + Fix: Fix connection leak in ProxyErrorReportValve. (remm)\n    + Fix: When using the RewriteValve, %{SSL:HTTPS} now returns on or off\n      rather than true or false to align with httpd. (markt)\n    + Fix: Reset the encoding used for query string parameters between requests\n      in case an application changed the encoding in a previous request. (markt)\n    + Fix: When encoding URLs with the CsrfPreventionFilter, don't add the nonce\n      to URLs that are known not to require it. (markt)\n    + Fix: Fix CombinedRealm isAvailable, it allows authentication if at least\n      one sub realm is available. (remm)\n    + Fix: 70048: Correctly handle asynchronous requests in PersistentValve.\n      (markt)\n    + Fix: Improve the detection of cross-context dispatches when using a\n      RequestDispatcher. (markt)\n    + Fix: Fix various instances of double decoding of URL patterns configured\n      either programmatically or in web.xml. (remm/markt)\n    + Fix: Align the rewrite conditions ornext flag processing with mod_rewrite,\n      which follows a purely sequential evaluation strategy. (remm)\n    + Fix: Change the default for the useRedirect attribute of the\n      ProxyErrorReportValve from true to false. (markt)\n    + Add: Add support for the showReport attribute in JsonErrorReportValve and\n      ProxyErrorReportValve. When set to false, detailed error information\n      (message, description, stack trace) is suppressed from error responses.\n      (dsoumis)\n    + Fix: Avoid a NoClassDefFoundError at startup when catalina-tribes.jar is\n      removed but catalina-ha.jar is present and the Cluster element is enabled\n      in server.xml. Cluster digester rules are now fully conditional on both\n      JARs being available. (dsoumis)\n    + Fix: Fix a potential deadlock when copying resources using WebDAV. (markt)\n    + Fix: Add jakarta., org.apache.catalina. and org.apache.tomcat.to the list\n      of reserved prefixes for SSI variables and request attributes. (markt)\n    + Fix: Missing URL decoding when processing addMapping on a Servlet\n      registration. (remm)\n    + Fix: The Timeout WebDAV header allows comma separated values (according to\n      the examples in the RFC). Use the first acceptable value. (remm)\n    + Fix: Fix various issues when logging the effective web.xml for a web\n      application. Empty sections are no longer logged. Special roles and empty\n      authorisation constraints are included. (markt)\n    + Fix: Expand the write lock for the save process in the MemoryUserDatabase\n      to avoid concurrency issues with the file save operations. (markt)\n    + Fix: Ensure atomic session persistence in FileStore. Based on pull request\n      #1016 by sahvx655-wq. (markt)\n    + Fix: Do not ignore methods configured on security constraints that map to\n      the default servlet. (markt)\n  * Cluster\n    + Fix: Expand wording and increase visibility of log message when cloud\n      membership is configured without a trust store as all certificates will be\n      trusted in this configuration. (markt)\n    + Fix: Ensure listeners are correctly added and removed when configuring the\n      channel coordinator. (markt)\n    + Fix: Fix some concurrency issues in FragmentationInterceptor. (markt)\n    + Fix: Fix some concurrency issues in OrderInterceptor. (markt)\n    + Fix: Fix some concurrency issues in TwoPhaseCommitInterceptor. (markt)\n    + Fix: Fix concurrency issues generating MD5 digests in the\n      CloudMembershipProvider implementations. (markt)\n    + Add: Add replay protection to the EncryptInterceptor. This is a breaking\n      change for the EncryptInterceptor. (markt)\n  * Coyote\n    + Add: Log a suitable warning if an encrypted PEM file is detected using an\n      insecure form for encryption. (markt)\n    + Fix: If TLS groups have been configured, use the configured groups rather\n      than using OpenSSL's default TLS groups when using Tomcat Native with\n      OpenSSL based connectors. (markt)\n    + Fix: For HTTP/2, ensure that any in progress request body reads are\n      cancelled if the container resets the associated stream. This prevents\n      delays waiting for reads to time out when it is known that no more data\n      will be received. (markt)\n    + Fix: Ensure that malformed HTTP/2 messages that should trigger a stream\n      reset do so, rather than triggered a connection close. (markt)\n    + Fix: Improve enforcement of header trailer allow list for HTTP/2. (remm)\n    + Fix: 70050: Avoid NPE when no header frame is processed in HTTP/2,\n      following refactor clean-up of header buffer. (remm)\n    + Fix: Properly use pollerThreadPriority for the NIO poller thread. (remm)\n    + Fix: Fix MessageByte.equals if called on a null MB. (remm)\n    + Fix: Call the delegate key manager in JSSE to retrieve the server key.\n      (remm)\n    + Fix: Avoid overflow scenarios in Asn1Parser. (remm)\n    + Fix: 70091: Add a new attribute, allowSchemeMismatch to Http2Protocol that\n      allows the consistency check for the scheme provided by the user agent to\n      be bypassed. (markt)\n    + Fix: isTrailerFieldsReady was always returning true. (remm)\n    + Fix: Align OpenSSL/Panama TLS implementation with other implementations\n      and throw an exception if there is an error loading the provided CRL(s).\n      (markt)\n    + Fix: Parsing of OpenSSL format cipher expressions incorrectly stopped if\n      @STRENGTH was encountered, ignoring any subsequent expressions. (markt)\n    + Fix: Handle the case where the HTTP/2 payload length is insufficient for\n      the mandatory data required by the flags set in the header. (markt)\n    + Fix: 70102: Correct expected size of ticket keys when calling\n      setSessionTicketKeys with an FFM connector. (markt)\n    + Fix: 69988: Fix post handshake authentication for TLS 1.3. It was broken\n      by a breaking change in OpenSSL between 1.1.1 and 3.0.0. (markt)\n    + Fix: When processing an OpenSSL cipher specification, fully align the\n      order of the resulting ciphers with the order produced by OpenSSL. (markt)\n    + Add: Add support for Brainpool TLS groups. Patch provided by YStankov.\n      (schultz)\n    + Update: Update both the minimum and recommended version for Tomcat Native\n      1.x to 1.3.8. (markt)\n  * Jasper\n    + Fix: Fix possible EL argument mismatch when it was set to null. (remm)\n    + Fix: Fix thread safety of TagPluginManager. (remm)\n    + Fix: Correctly use flush on JSP include. (remm)\n  * Web applications\n    + Add: Manager: Add checks to ensure that any uploaded files are uploaded to\n      the expected location. (markt)\n    + Add: Manager: Add checks to ensure that the requested context path for a\n      deployed WAR, directory or descriptor file is valid. (markt)\n    + Add: Documentation: Expand the description of some of the attributes of\n      the CrawlerSessionManagerValve. (markt)\n    + Fix: Documentation: Clearer description and correct documented default for\n      ocspSoftFail. (markt)\n    + Fix: Fix double escaping in the context names for the JSON mode of the\n      manager servlet. (remm)\n    + Fix: Manager: Ensure automatic deployment does not trigger an undeployment\n      during a Manager triggered web application reload. (markt)\n    + Fix: Documentation: Provide better documentation for the scheme and secure\n      attributes of a Connector. (markt)\n  * Websocket\n    + Fix: Incorrect Future.isDone() return by AsyncChannelWrapperSecure. (remm)\n    + Fix: Trigger standard WebSocket error handling if a call to\n      Endpoint.onOpen() fails for a programmatic endpoint. (markt)\n    + Fix: 70110: Fix memory leak if a call to Endpoint.onOpen() fails for a\n      programmatic endpoint. Test case provided by uabdur. (markt)\n    + Fix: If a client presents invalid parameters when negotiating a WebSocket\n      extension, decline the negotiation offer that includes the invalid\n      parameters rather than failing the connection. Pull request #1019 provided\n      by sahvx655-wq. (markt)\n  * Other\n    + Fix: Wrong references to jakarta instead of javax. (remm)\n    + Fix: Restore default authenticator to nullafter executing an Ant task.\n      (remm)\n    + Update: Update Commons Daemon to 1.6.1. (markt)\n    + Update: Improvements to French translations. (remm)\n    + Update: Improvements to Japanese translations provided by tak7iji. (markt)\n    + Update: Update Tomcat Native to 1.3.8. (markt)\n",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/SUSE%2FSUSE-SU-2026:22646-1.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "This update for tomcat11 fixes the following issues\n\nUpdate to Tomcat 11.0.23.\n\nSecurity issues fixed:\n\n- CVE-2026-50229: improper neutralization of script-related HTML tags in the number guess example (bsc#1269791).\n- CVE-2026-53404: always-incorrect control flow implementation in the rewrite valve caused non-OR conditions to be\n  skipped if the first condition in an OR chain matched (bsc#1269910).\n- CVE-2026-53434: error condition not handled when configuring CRLs for a FFM based connector (bsc#1269824).\n- CVE-2026-55276: always-incorrect control flow implementation caused special roles and empty authorization constraints\n  to not be included when the effective web.xml was logged (bsc#1269909).\n- CVE-2026-55955: improper authentication allows a replay attack against the EncryptionInterceptor in the cluster\n  component (bsc#1269908).\n- CVE-2026-55956: improper authorization leads to security constraints specified for the default servlet ignoring any\n  method or method omission configured as part of the constraint (bsc#1269907).\n\nOther updates and bugfixes:\n\n- Upgrade libtcnative to v2 (bsc#1232390)\n- Tomcat 11.0.23:\n  * Catalina\n    + Add: Add support for literal '%' characters in access log output. Based on\n      pull request #1002 by Fabian Hahn. (markt)\n    + Fix: Lower the log level to debug when OpenSSL initialization fails in\n      OpenSSLLifecycleListener to avoid stack traces when libssl.so is not\n      present and to align the behavior of the isAvailable() check with the\n      AprLifecycleListener and gracefully fail when natives are not present.\n      (csutherl)\n    + Fix: 70038: Cookie.clone() should also clone the internal attribute map.\n      (markt)\n    + Code: Remove unnecessary code from the SSI processing engine that was\n      duplicating some of the normalisation checks. (markt)\n    + Fix: Cleaner handling of invalid SPNEGO tokens. (remm)\n    + Fix: Avoid some NPEs in the Connector class on an uninitialize protocol.\n      (remm)\n    + Fix: Incorrect session average life calculation. (remm)\n    + Fix: Improve robustness on using Pipeline.setBasic on a running pipeline.\n      (remm)\n    + Fix: Avoid any init parameter updates when conflicts are found for\n      filters, similar to what is done for servlets, as required by the servlet\n      specification. (remm)\n    + Fix: Fix container event cleanups in some edge cases. (remm)\n    + Fix: Check for last-modified header in ExpiresFilter when a servlet uses\n      addDateHeader to avoid wrongly considering it has been set. (remm)\n    + Fix: Fix hour unit used by ExpiresFilter. (remm)\n    + Fix: Remove exception swallowing in DataSourceStore to align it with\n      FileStore and avoid session loss on errors. (remm)\n    + Fix: Add support for single-quote escaped literal as well as quoted\n      literals in DateFormatCache. (schultz)\n    + Fix: On JAAS logout, clear out role principals on the subject that were\n      added on commit, as recommended by the JAAS specification. (remm)\n    + Fix: MemoryRealm should not add a dummy role when none is specified in the\n      configuration. (remm)\n    + Fix: DataSourceUserDatabase should return a null principal on a non\n      existing user. (remm)\n    + Fix: Fix shared lock expiration in WebDAV. (remm)\n    + Fix: Inaccurate session exipration statistics when using the persistent\n      manager. (remm)\n    + Fix: Skip BOM when serving files with UTF-32 encoding. (remm)\n    + Fix: Mixup of WrapperListener and WrapperLifecycle elements in\n      storeconfig. (remm)\n    + Fix: Incorrect processing of modified users in DataSourceUserDatabase.\n      (remm)\n    + Update: Clarify behavior in the UserDatabase for user, role and group\n      creation that it does not immediately override existing elements. Removal\n      (or update) needs to be used instead. (remm)\n    + Fix: 70049: Align the web application class loader with parent class\n      loaders and swallow any errors caused by invalid paths when looking up\n      resources and behave as if the resources were not found in that case.\n      (markt)\n    + Fix: Improve validation of Range and Content-Range parsers so invalid\n      ranges trigger a 4xx response rather than a 500 response. Pull request\n      #1012 provided by Sahana Surendra Bogar. (markt)\n    + Fix: Fix connection leak in ProxyErrorReportValve. (remm)\n    + Fix: When using the RewriteValve, %{SSL:HTTPS} now returns on or off\n      rather than true or false to align with httpd. (markt)\n    + Fix: Reset the encoding used for query string parameters between requests\n      in case an application changed the encoding in a previous request. (markt)\n    + Fix: When encoding URLs with the CsrfPreventionFilter, don't add the nonce\n      to URLs that are known not to require it. (markt)\n    + Fix: Fix SSO cookie partitioned configuration. (remm)\n    + Fix: Fix CombinedRealm isAvailable, it allows authentication if at least\n      one sub realm is available. (remm)\n    + Fix: 70048: Correctly handle asynchronous requests in PersistentValve.\n      (markt)\n    + Fix: Improve the detection of cross-context dispatches when using a\n      RequestDispatcher. (markt)\n    + Fix: Fix various instances of double decoding of URL patterns configured\n      either programmatically or in web.xml. (remm/markt)\n    + Fix: Align the rewrite conditions ornext flag processing with mod_rewrite,\n      which follows a purely sequential evaluation strategy. (remm)\n    + Fix: Update default web.xml version to match supported Servlet\n      specification version. (markt)\n    + Fix: Change the default for the useRedirect attribute of the\n      ProxyErrorReportValve from true to false. (markt)\n    + Add: Add support for the showReport attribute in JsonErrorReportValve and\n      ProxyErrorReportValve. When set to false, detailed error information\n      (message, description, stack trace) is suppressed from error responses.\n      (dsoumis)\n    + Fix: Avoid a NoClassDefFoundError at startup when catalina-tribes.jar is\n      removed but catalina-ha.jar is present and the Cluster element is enabled\n      in server.xml. Cluster digester rules are now fully conditional on both\n      JARs being available. (dsoumis)\n    + Fix: Fix a potential deadlock when copying resources using WebDAV. (markt)\n    + Fix: Add jakarta., org.apache.catalina. and org.apache.tomcat.to the list\n      of reserved prefixes for SSI variables and request attributes. (markt)\n    + Fix: Missing URL decoding when processing addMapping on a Servlet\n      registration. (remm)\n    + Fix: The Timeout WebDAV header allows comma separated values (according to\n      the examples in the RFC). Use the first acceptable value. (remm)\n    + Fix: Fix various issues when logging the effective web.xml for a web\n      application. Empty sections are no longer logged. Special roles and empty\n      authorisation constraints are included. All session cookie attributes are\n      included. (markt)\n    + Fix: Expand the write lock for the save process in the MemoryUserDatabase\n      to avoid concurrency issues with the file save operations. (markt)\n    + Fix: Ensure atomic session persistence in FileStore. Based on pull request\n      #1016 by sahvx655-wq. (markt)\n    + Fix: Do not ignore methods configured on security constraints that map to\n      the default servlet. (markt)\n  * Cluster\n    + Fix: Expand wording and increase visibility of log message when cloud\n      membership is configured without a trust store as all certificates will be\n      trusted in this configuration. (markt)\n    + Fix: Ensure listeners are correctly added and removed when configuring the\n      channel coordinator. (markt)\n    + Fix: Fix some concurrency issues in FragmentationInterceptor. (markt)\n    + Fix: Fix some concurrency issues in OrderInterceptor. (markt)\n    + Fix: Fix some concurrency issues in TwoPhaseCommitInterceptor. (markt)\n    + Fix: Fix concurrency issues generating MD5 digests in the\n      CloudMembershipProvider implementations. (markt)\n    + Add: Add replay protection to the EncryptInterceptor. This us a breaking\n      change for the EncryptInterceptor.(markt)\n  * Coyote\n    + Add: Log a suitable warning if an encrypted PEM file is detected using an\n      insecure form for encryption. (markt)\n    + Fix: If TLS groups have been configured, use the configured groups rather\n      than using OpenSSL's default TLS groups when using Tomcat Native with\n      OpenSSL based connectors. (markt)\n    + Fix: For HTTP/2, ensure that any in progress request body reads are\n      cancelled if the container resets the associated stream. This prevents\n      delays waiting for reads to time out when it is known that no more data\n      will be received. (markt)\n    + Fix: Ensure that malformed HTTP/2 messages that should trigger a stream\n      reset do so, rather than triggered a connection close. (markt)\n    + Fix: Improve enforcement of header trailer allow list for HTTP/2. (remm)\n    + Fix: 70050: Avoid NPE when no header frame is processed in HTTP/2,\n      following refactor clean-up of header buffer. (remm)\n    + Fix: Properly use pollerThreadPriority for the NIO poller thread. (remm)\n    + Fix: Fix MessageByte.equals if called on a null MB. (remm)\n    + Fix: Call the delegate key manager in JSSE to retrieve the server key.\n      (remm)\n    + Fix: Avoid overflow scenarios in Asn1Parser. (remm)\n    + Fix: 70091: Add a new attribute, allowSchemeMismatch to Http2Protocol that\n      allows the consistency check for the scheme provided by the user agent to\n      be bypassed. (markt)\n    + Fix: isTrailerFieldsReady was always returning true. (remm)\n    + Fix: Align OpenSSL/Panama TLS implementation with other implementations\n      and throw an exception if there is an error loading the provided CRL(s).\n      (markt)\n    + Fix: Parsing of OpenSSL format cipher expressions incorrectly stopped if\n      @STRENGTH was encountered, ignoring any subsequent expressions. (markt)\n    + Fix: Handle the case where the HTTP/2 payload length is insufficient for\n      the mandatory data required by the flags set in the header. (markt)\n    + Fix: 70102: Correct expected size of ticket keys when calling\n      setSessionTicketKeys with an FFM connector. (markt)\n    + Fix: 69988: Fix post handshake authentication for TLS 1.3. It was broken\n      by a breaking change in OpenSSL between 1.1.1 and 3.0.0. (markt)\n    + Fix: When processing an OpenSSL cipher specification, fully align the\n      order of the resulting ciphers with the order produced by OpenSSL. (markt)\n    + Add: Add support for Brainpool TLS groups. Patch provided by YStankov.\n      (schultz)\n    + Update: Update both the minimum and recommended version for Tomcat Native\n      2.x to 2.0.15. (markt)\n    + Update: Update the minimum version for Tomcat Native 1.x to 1.3.8. (markt)\n  * Jasper\n    + Fix: Fix possible EL argument mismatch when it was set to null. (remm)\n    + Fix: Fix thread safety of TagPluginManager. (remm)\n    + Fix: Correctly use flush on JSP include. (remm)\n  * Web applications\n    + Add: Manager: Add checks to ensure that any uploaded files are uploaded to\n      the expected location. (markt)\n    + Add: Manager: Add checks to ensure that the requested context path for a\n      deployed WAR, directory or descriptor file is valid. (markt)\n    + Add: Documentation: Expand the description of some of the attributes of\n      the CrawlerSessionManagerValve. (markt)\n    + Fix: Documentation: Clearer description and correct documented default for\n      ocspSoftFail. (markt)\n    + Fix: Fix double escaping in the context names for the JSON mode of the\n      manager servlet. (remm)\n    + Fix: Manager: Ensure automatic deployment does not trigger an undeployment\n      during a Manager triggered web application reload. (markt)\n    + Fix: Documentation: Provide better documentation for the scheme and secure\n      attributes of a Connector. (markt)\n  * Websocket\n    + Fix: Incorrect Future.isDone() return by AsyncChannelWrapperSecure. (remm)\n    + Fix: Trigger standard WebSocket error handling if a call to\n      Endpoint.onOpen() fails for a programmatic endpoint. (markt)\n    + Fix: 70110: Fix memory leak if a call to Endpoint.onOpen() fails for a\n      programmatic endpoint. Test case provided by uabdur. (markt)\n    + Fix: If a client presents invalid parameters when negotiating a WebSocket\n      extension, decline the negotiation offer that includes the invalid\n      parameters rather than failing the connection. Pull request #1019 provided\n      by sahvx655-wq. (markt)\n  * Other\n    + Fix: Use per connection authenticator when executing an Ant task.\n      (remm/markt)\n    + Update: Update Commons Daemon to 1.6.1. (markt)\n    + Fix: Prevent duplicate log messages when clustering JARs are not present\n      on startup. (csutherl)\n    + Update: Improvements to French translations. (remm)\n    + Update: Improvements to Japanese translations provided by tak7iji. (markt)\n    + Update: Update the packaged version of the Tomcat Migration Tool for\n      Jakarta EE to 1.0.12. (markt)\n    + Update: Update Tomcat Native to 2.0.15. (markt)\n",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/SUSE%2FSUSE-SU-2026:22648-1.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "This update for tomcat10 fixes the following issues\n\nUpdate to Tomcat 10.1.56.\n\nSecurity issues fixed:\n\n- CVE-2026-50229: improper neutralization of script-related HTML tags in the number guess example (bsc#1269791).\n- CVE-2026-53404: always-incorrect control flow implementation in the rewrite valve caused non-OR conditions to be\n  skipped if the first condition in an OR chain matched (bsc#1269910).\n- CVE-2026-53434: error condition not handled when configuring CRLs for a FFM based connector (bsc#1269824).\n- CVE-2026-55276: always-incorrect control flow implementation caused special roles and empty authorization constraints\n  to not be included when the effective web.xml was logged (bsc#1269909).\n- CVE-2026-55955: improper authentication allows a replay attack against the EncryptionInterceptor in the cluster\n  component (bsc#1269908).\n- CVE-2026-55956: improper authorization leads to security constraints specified for the default servlet ignoring any\n  method or method omission configured as part of the constraint (bsc#1269907).\n\nOther updates and bugfixes:\n\n- Tomcat 10.1.56:\n  * Catalina\n    + Add: Add support for literal '%' characters in access log output. Based on\n      pull request #1002 by Fabian Hahn. (markt)\n    + Fix: Prevent duplicate log messages when clustering JARs are not present\n      on startup. (csutherl)\n    + Fix: 70038: Cookie.clone() should also clone the internal attribute map.\n      (markt)\n    + Code: Remove unnecessary code from the SSI processing engine that was\n      duplicating some of the normalisation checks. (markt)\n    + Fix: Cleaner handling of invalid SPNEGO tokens. (remm)\n    + Fix: Avoid some NPEs in the Connector class on an uninitialize protocol.\n      (remm)\n    + Fix: Incorrect session average life calculation. (remm)\n    + Fix: Improve robustness on using Pipeline.setBasic on a running pipeline.\n      (remm)\n    + Fix: Avoid any init parameter updates when conflicts are found for\n      filters, similar to what is done for servlets, as required by the servlet\n      specification. (remm)\n    + Fix: Fix container event cleanups in some edge cases. (remm)\n    + Fix: Check for last-modified header in ExpiresFilter when a servlet uses\n      addDateHeader to avoid wrongly considering it has been set. (remm)\n    + Fix: Fix hour unit used by ExpiresFilter. (remm)\n    + Fix: Remove exception swallowing in DataSourceStore to align it with\n      FileStore and avoid session loss on errors. (remm)\n    + Fix: Add support for single-quote escaped literal as well as quoted\n      literals in DateFormatCache. (schultz)\n    + Fix: On JAAS logout, clear out role principals on the subject that were\n      added on commit, as recommended by the JAAS specification. (remm)\n    + Fix: MemoryRealm should not add a dummy role when none is specified in the\n      configuration. (remm)\n    + Fix: DataSourceUserDatabase should return a null principal on a non\n      existing user. (remm)\n    + Fix: Fix shared lock expiration in WebDAV. (remm)\n    + Fix: Inaccurate session exipration statistics when using the persistent\n      manager. (remm)\n    + Fix: Skip BOM when serving files with UTF-32 encoding. (remm)\n    + Fix: Mixup of WrapperListener and WrapperLifecycle elements in\n      storeconfig. (remm)\n    + Fix: Incorrect processing of modified users in DataSourceUserDatabase.\n      (remm)\n    + Update: Clarify behavior in the UserDatabase for user, role and group\n      creation that it does not immediately override existing elements. Removal\n      (or update) needs to be used instead. (remm)\n    + Fix: 70049: Align the web application class loader with parent class\n      loaders and swallow any errors caused by invalid paths when looking up\n      resources and behave as if the resources were not found in that case.\n      (markt)\n    + Fix: Improve validation of Range and Content-Range parsers so invalid\n      ranges trigger a 4xx response rather than a 500 response. Pull request\n      #1012 provided by Sahana Surendra Bogar. (markt)\n    + Fix: Fix connection leak in ProxyErrorReportValve. (remm)\n    + Fix: When using the RewriteValve, %{SSL:HTTPS} now returns on or off\n      rather than true or false to align with httpd. (markt)\n    + Fix: Reset the encoding used for query string parameters between requests\n      in case an application changed the encoding in a previous request. (markt)\n    + Fix: When encoding URLs with the CsrfPreventionFilter, don't add the nonce\n      to URLs that are known not to require it. (markt)\n    + Fix: Fix CombinedRealm isAvailable, it allows authentication if at least\n      one sub realm is available. (remm)\n    + Fix: 70048: Correctly handle asynchronous requests in PersistentValve.\n      (markt)\n    + Fix: Improve the detection of cross-context dispatches when using a\n      RequestDispatcher. (markt)\n    + Fix: Fix various instances of double decoding of URL patterns configured\n      either programmatically or in web.xml. (remm/markt)\n    + Fix: Align the rewrite conditions ornext flag processing with mod_rewrite,\n      which follows a purely sequential evaluation strategy. (remm)\n    + Fix: Change the default for the useRedirect attribute of the\n      ProxyErrorReportValve from true to false. (markt)\n    + Add: Add support for the showReport attribute in JsonErrorReportValve and\n      ProxyErrorReportValve. When set to false, detailed error information\n      (message, description, stack trace) is suppressed from error responses.\n      (dsoumis)\n    + Fix: Avoid a NoClassDefFoundError at startup when catalina-tribes.jar is\n      removed but catalina-ha.jar is present and the Cluster element is enabled\n      in server.xml. Cluster digester rules are now fully conditional on both\n      JARs being available. (dsoumis)\n    + Fix: Fix a potential deadlock when copying resources using WebDAV. (markt)\n    + Fix: Add jakarta., org.apache.catalina. and org.apache.tomcat.to the list\n      of reserved prefixes for SSI variables and request attributes. (markt)\n    + Fix: Missing URL decoding when processing addMapping on a Servlet\n      registration. (remm)\n    + Fix: The Timeout WebDAV header allows comma separated values (according to\n      the examples in the RFC). Use the first acceptable value. (remm)\n    + Fix: Fix various issues when logging the effective web.xml for a web\n      application. Empty sections are no longer logged. Special roles and empty\n      authorisation constraints are included. All session cookie attributes are\n      included. (markt)\n    + Fix: Expand the write lock for the save process in the MemoryUserDatabase\n      to avoid concurrency issues with the file save operations. (markt)\n    + Fix: Ensure atomic session persistence in FileStore. Based on pull request\n      #1016 by sahvx655-wq. (markt)\n    + Fix: Do not ignore methods configured on security constraints that map to\n      the default servlet. (markt)\n  * Cluster\n    + Fix: Expand wording and increase visibility of log message when cloud\n      membership is configured without a trust store as all certificates will be\n      trusted in this configuration. (markt)\n    + Fix: Ensure listeners are correctly added and removed when configuring the\n      channel coordinator. (markt)\n    + Fix: Fix some concurrency issues in FragmentationInterceptor. (markt)\n    + Fix: Fix some concurrency issues in OrderInterceptor. (markt)\n    + Fix: Fix some concurrency issues in TwoPhaseCommitInterceptor. (markt)\n    + Fix: Fix concurrency issues generating MD5 digests in the\n      CloudMembershipProvider implementations. (markt)\n    + Add: Add replay protection to the EncryptInterceptor. This is a breaking\n      change for the EncryptInterceptor. (markt)\n  * Coyote\n    + Add: Log a suitable warning if an encrypted PEM file is detected using an\n      insecure form for encryption. (markt)\n    + Fix: If TLS groups have been configured, use the configured groups rather\n      than using OpenSSL's default TLS groups when using Tomcat Native with\n      OpenSSL based connectors. (markt)\n    + Fix: For HTTP/2, ensure that any in progress request body reads are\n      cancelled if the container resets the associated stream. This prevents\n      delays waiting for reads to time out when it is known that no more data\n      will be received. (markt)\n    + Fix: Ensure that malformed HTTP/2 messages that should trigger a stream\n      reset do so, rather than triggered a connection close. (markt)\n    + Fix: Improve enforcement of header trailer allow list for HTTP/2. (remm)\n    + Fix: 70050: Avoid NPE when no header frame is processed in HTTP/2,\n      following refactor clean-up of header buffer. (remm)\n    + Fix: Properly use pollerThreadPriority for the NIO poller thread. (remm)\n    + Fix: Fix MessageByte.equals if called on a null MB. (remm)\n    + Fix: Call the delegate key manager in JSSE to retrieve the server key.\n      (remm)\n    + Fix: Avoid overflow scenarios in Asn1Parser. (remm)\n    + Fix: 70091: Add a new attribute, allowSchemeMismatch to Http2Protocol that\n      allows the consistency check for the scheme provided by the user agent to\n      be bypassed. (markt)\n    + Fix: isTrailerFieldsReady was always returning true. (remm)\n    + Fix: Align OpenSSL/Panama TLS implementation with other implementations\n      and throw an exception if there is an error loading the provided CRL(s).\n      (markt)\n    + Fix: Parsing of OpenSSL format cipher expressions incorrectly stopped if\n      @STRENGTH was encountered, ignoring any subsequent expressions. (markt)\n    + Fix: Handle the case where the HTTP/2 payload length is insufficient for\n      the mandatory data required by the flags set in the header. (markt)\n    + Fix: 70102: Correct expected size of ticket keys when calling\n      setSessionTicketKeys with an FFM connector. (markt)\n    + Fix: 69988: Fix post handshake authentication for TLS 1.3. It was broken\n      by a breaking change in OpenSSL between 1.1.1 and 3.0.0. (markt)\n    + Fix: When processing an OpenSSL cipher specification, fully align the\n      order of the resulting ciphers with the order produced by OpenSSL. (markt)\n    + Add: Add support for Brainpool TLS groups. Patch provided by YStankov.\n      (schultz)\n    + Update: Update both the minimum and recommended version for Tomcat Native\n      2.x to 2.0.15. (markt)\n    + Update: Update the minimum version for Tomcat Native 1.x to 1.3.8. (markt)\n  * Jasper\n    + Fix: Fix possible EL argument mismatch when it was set to null. (remm)\n    + Fix: Fix thread safety of TagPluginManager. (remm)\n    + Fix: Correctly use flush on JSP include. (remm)\n  * Web applications\n    + Add: Manager: Add checks to ensure that any uploaded files are uploaded to\n      the expected location. (markt)\n    + Add: Manager: Add checks to ensure that the requested context path for a\n      deployed WAR, directory or descriptor file is valid. (markt)\n    + Add: Documentation: Expand the description of some of the attributes of\n      the CrawlerSessionManagerValve. (markt)\n    + Fix: Documentation: Clearer description and correct documented default for\n      ocspSoftFail. (markt)\n    + Fix: Fix double escaping in the context names for the JSON mode of the\n      manager servlet. (remm)\n    + Fix: Manager: Ensure automatic deployment does not trigger an undeployment\n      during a Manager triggered web application reload. (markt)\n    + Fix: Documentation: Provide better documentation for the scheme and secure\n      attributes of a Connector. (markt)\n  * Websocket\n    + Fix: Incorrect Future.isDone() return by AsyncChannelWrapperSecure. (remm)\n    + Fix: Trigger standard WebSocket error handling if a call to\n      Endpoint.onOpen() fails for a programmatic endpoint. (markt)\n    + Fix: 70110: Fix memory leak if a call to Endpoint.onOpen() fails for a\n      programmatic endpoint. Test case provided by uabdur. (markt)\n    + Fix: If a client presents invalid parameters when negotiating a WebSocket\n      extension, decline the negotiation offer that includes the invalid\n      parameters rather than failing the connection. Pull request #1019 provided\n      by sahvx655-wq. (markt)\n  * Other\n    + Fix: Use per connection authenticator when executing an Ant task.\n      (remm/markt)\n    + Update: Update Commons Daemon to 1.6.1. (markt)\n    + Update: Improvements to French translations. (remm)\n    + Update: Improvements to Japanese translations provided by tak7iji. (markt)\n    + Update: Update the packaged version of the Tomcat Migration Tool for\n      Jakarta EE to 1.0.12. (markt)\n    + Update: Update Tomcat Native to 2.0.15. (markt)\n",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/SUSE%2FSUSE-SU-2026:3112-1.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "This update for tomcat fixes the following issues\n\nUpdate to Tomcat 9.0.119.\n\nSecurity issues fixed:\n\n- CVE-2026-50229: improper neutralization of script-related HTML tags in the number guess example (bsc#1269791).\n- CVE-2026-53404: always-incorrect control flow implementation in the rewrite valve caused non-OR conditions to be\n  skipped if the first condition in an OR chain matched (bsc#1269910).\n- CVE-2026-53434: error condition not handled when configuring CRLs for a FFM based connector (bsc#1269824).\n- CVE-2026-55276: always-incorrect control flow implementation caused special roles and empty authorization constraints\n  to not be included when the effective web.xml was logged (bsc#1269909).\n- CVE-2026-55955: improper authentication allows a replay attack against the EncryptionInterceptor in the cluster\n  component (bsc#1269908).\n- CVE-2026-55956: improper authorization leads to security constraints specified for the default servlet ignoring any\n  method or method omission configured as part of the constraint (bsc#1269907).\n\nOther updates and bugfixes:\n  \n- Tomcat 9.0.119\n  * Catalina\n    + Add: Add support for literal '%' characters in access log output. Based on\n      pull request #1002 by Fabian Hahn. (markt)\n    + Fix: Prevent duplicate log messages when clustering JARs are not present\n      on startup. (csutherl)\n    + Code: Remove unnecessary code from the SSI processing engine that was\n      duplicating some of the normalisation checks. (markt)\n    + Fix: Cleaner handling of invalid SPNEGO tokens. (remm)\n    + Fix: Avoid some NPEs in the Connector class on an uninitialize protocol.\n      (remm)\n    + Fix: Incorrect session average life calculation. (remm)\n    + Fix: Improve robustness on using Pipeline.setBasic on a running pipeline.\n      (remm)\n    + Fix: Avoid any init parameter updates when conflicts are found for\n      filters, similar to what is done for servlets, as required by the servlet\n      specification. (remm)\n    + Fix: Fix container event cleanups in some edge cases. (remm)\n    + Fix: Check for last-modified header in ExpiresFilter when a servlet uses\n      addDateHeader to avoid wrongly considering it has been set. (remm)\n    + Fix: Fix hour unit used by ExpiresFilter. (remm)\n    + Fix: Remove exception swallowing in DataSourceStore to align it with\n      FileStore and avoid session loss on errors. (remm)\n    + Fix: Add support for single-quote escaped literal as well as quoted\n      literals in DateFormatCache. (schultz)\n    + Fix: On JAAS logout, clear out role principals on the subject that were\n      added on commit, as recommended by the JAAS specification. (remm)\n    + Fix: MemoryRealm should not add a dummy role when none is specified in the\n      configuration. (remm)\n    + Fix: DataSourceUserDatabase should return a null principal on a non\n      existing user. (remm)\n    + Fix: Fix shared lock expiration in WebDAV. (remm)\n    + Fix: Inaccurate session exipration statistics when using the persistent\n      manager. (remm)\n    + Fix: Skip BOM when serving files with UTF-32 encoding. (remm)\n    + Fix: Mixup of WrapperListener and WrapperLifecycle elements in\n      storeconfig. (remm)\n    + Fix: Incorrect processing of modified users in DataSourceUserDatabase.\n      (remm)\n    + Update: Clarify behavior in the UserDatabase for user, role and group\n      creation that it does not immediately override existing elements. Removal\n      (or update) needs to be used instead. (remm)\n    + Fix: 70049: Align the web application class loader with parent class\n      loaders and swallow any errors caused by invalid paths when looking up\n      resources and behave as if the resources were not found in that case.\n      (markt)\n    + Fix: Improve validation of Range and Content-Range parsers so invalid\n      ranges trigger a 4xx response rather than a 500 response. Pull request\n      #1012 provided by Sahana Surendra Bogar. (markt)\n    + Fix: Fix connection leak in ProxyErrorReportValve. (remm)\n    + Fix: When using the RewriteValve, %{SSL:HTTPS} now returns on or off\n      rather than true or false to align with httpd. (markt)\n    + Fix: Reset the encoding used for query string parameters between requests\n      in case an application changed the encoding in a previous request. (markt)\n    + Fix: When encoding URLs with the CsrfPreventionFilter, don't add the nonce\n      to URLs that are known not to require it. (markt)\n    + Fix: Fix CombinedRealm isAvailable, it allows authentication if at least\n      one sub realm is available. (remm)\n    + Fix: 70048: Correctly handle asynchronous requests in PersistentValve.\n      (markt)\n    + Fix: Improve the detection of cross-context dispatches when using a\n      RequestDispatcher. (markt)\n    + Fix: Fix various instances of double decoding of URL patterns configured\n      either programmatically or in web.xml. (remm/markt)\n    + Fix: Align the rewrite conditions ornext flag processing with mod_rewrite,\n      which follows a purely sequential evaluation strategy. (remm)\n    + Fix: Change the default for the useRedirect attribute of the\n      ProxyErrorReportValve from true to false. (markt)\n    + Add: Add support for the showReport attribute in JsonErrorReportValve and\n      ProxyErrorReportValve. When set to false, detailed error information\n      (message, description, stack trace) is suppressed from error responses.\n      (dsoumis)\n    + Fix: Avoid a NoClassDefFoundError at startup when catalina-tribes.jar is\n      removed but catalina-ha.jar is present and the Cluster element is enabled\n      in server.xml. Cluster digester rules are now fully conditional on both\n      JARs being available. (dsoumis)\n    + Fix: Fix a potential deadlock when copying resources using WebDAV. (markt)\n    + Fix: Add jakarta., org.apache.catalina. and org.apache.tomcat.to the list\n      of reserved prefixes for SSI variables and request attributes. (markt)\n    + Fix: Missing URL decoding when processing addMapping on a Servlet\n      registration. (remm)\n    + Fix: The Timeout WebDAV header allows comma separated values (according to\n      the examples in the RFC). Use the first acceptable value. (remm)\n    + Fix: Fix various issues when logging the effective web.xml for a web\n      application. Empty sections are no longer logged. Special roles and empty\n      authorisation constraints are included. (markt)\n    + Fix: Expand the write lock for the save process in the MemoryUserDatabase\n      to avoid concurrency issues with the file save operations. (markt)\n    + Fix: Ensure atomic session persistence in FileStore. Based on pull request\n      #1016 by sahvx655-wq. (markt)\n    + Fix: Do not ignore methods configured on security constraints that map to\n      the default servlet. (markt)\n  * Cluster\n    + Fix: Expand wording and increase visibility of log message when cloud\n      membership is configured without a trust store as all certificates will be\n      trusted in this configuration. (markt)\n    + Fix: Ensure listeners are correctly added and removed when configuring the\n      channel coordinator. (markt)\n    + Fix: Fix some concurrency issues in FragmentationInterceptor. (markt)\n    + Fix: Fix some concurrency issues in OrderInterceptor. (markt)\n    + Fix: Fix some concurrency issues in TwoPhaseCommitInterceptor. (markt)\n    + Fix: Fix concurrency issues generating MD5 digests in the\n      CloudMembershipProvider implementations. (markt)\n    + Add: Add replay protection to the EncryptInterceptor. This is a breaking\n      change for the EncryptInterceptor. (markt)\n  * Coyote\n    + Add: Log a suitable warning if an encrypted PEM file is detected using an\n      insecure form for encryption. (markt)\n    + Fix: If TLS groups have been configured, use the configured groups rather\n      than using OpenSSL's default TLS groups when using Tomcat Native with\n      OpenSSL based connectors. (markt)\n    + Fix: For HTTP/2, ensure that any in progress request body reads are\n      cancelled if the container resets the associated stream. This prevents\n      delays waiting for reads to time out when it is known that no more data\n      will be received. (markt)\n    + Fix: Ensure that malformed HTTP/2 messages that should trigger a stream\n      reset do so, rather than triggered a connection close. (markt)\n    + Fix: Improve enforcement of header trailer allow list for HTTP/2. (remm)\n    + Fix: 70050: Avoid NPE when no header frame is processed in HTTP/2,\n      following refactor clean-up of header buffer. (remm)\n    + Fix: Properly use pollerThreadPriority for the NIO poller thread. (remm)\n    + Fix: Fix MessageByte.equals if called on a null MB. (remm)\n    + Fix: Call the delegate key manager in JSSE to retrieve the server key.\n      (remm)\n    + Fix: Avoid overflow scenarios in Asn1Parser. (remm)\n    + Fix: 70091: Add a new attribute, allowSchemeMismatch to Http2Protocol that\n      allows the consistency check for the scheme provided by the user agent to\n      be bypassed. (markt)\n    + Fix: isTrailerFieldsReady was always returning true. (remm)\n    + Fix: Align OpenSSL/Panama TLS implementation with other implementations\n      and throw an exception if there is an error loading the provided CRL(s).\n      (markt)\n    + Fix: Parsing of OpenSSL format cipher expressions incorrectly stopped if\n      @STRENGTH was encountered, ignoring any subsequent expressions. (markt)\n    + Fix: Handle the case where the HTTP/2 payload length is insufficient for\n      the mandatory data required by the flags set in the header. (markt)\n    + Fix: 70102: Correct expected size of ticket keys when calling\n      setSessionTicketKeys with an FFM connector. (markt)\n    + Fix: 69988: Fix post handshake authentication for TLS 1.3. It was broken\n      by a breaking change in OpenSSL between 1.1.1 and 3.0.0. (markt)\n    + Fix: When processing an OpenSSL cipher specification, fully align the\n      order of the resulting ciphers with the order produced by OpenSSL. (markt)\n    + Add: Add support for Brainpool TLS groups. Patch provided by YStankov.\n      (schultz)\n    + Update: Update both the minimum and recommended version for Tomcat Native\n      1.x to 1.3.8. (markt)\n  * Jasper\n    + Fix: Fix possible EL argument mismatch when it was set to null. (remm)\n    + Fix: Fix thread safety of TagPluginManager. (remm)\n    + Fix: Correctly use flush on JSP include. (remm)\n  * Web applications\n    + Add: Manager: Add checks to ensure that any uploaded files are uploaded to\n      the expected location. (markt)\n    + Add: Manager: Add checks to ensure that the requested context path for a\n      deployed WAR, directory or descriptor file is valid. (markt)\n    + Add: Documentation: Expand the description of some of the attributes of\n      the CrawlerSessionManagerValve. (markt)\n    + Fix: Documentation: Clearer description and correct documented default for\n      ocspSoftFail. (markt)\n    + Fix: Fix double escaping in the context names for the JSON mode of the\n      manager servlet. (remm)\n    + Fix: Manager: Ensure automatic deployment does not trigger an undeployment\n      during a Manager triggered web application reload. (markt)\n    + Fix: Documentation: Provide better documentation for the scheme and secure\n      attributes of a Connector. (markt)\n  * Websocket\n    + Fix: Incorrect Future.isDone() return by AsyncChannelWrapperSecure. (remm)\n    + Fix: Trigger standard WebSocket error handling if a call to\n      Endpoint.onOpen() fails for a programmatic endpoint. (markt)\n    + Fix: 70110: Fix memory leak if a call to Endpoint.onOpen() fails for a\n      programmatic endpoint. Test case provided by uabdur. (markt)\n    + Fix: If a client presents invalid parameters when negotiating a WebSocket\n      extension, decline the negotiation offer that includes the invalid\n      parameters rather than failing the connection. Pull request #1019 provided\n      by sahvx655-wq. (markt)\n  * Other\n    + Fix: Wrong references to jakarta instead of javax. (remm)\n    + Fix: Restore default authenticator to nullafter executing an Ant task.\n      (remm)\n    + Update: Update Commons Daemon to 1.6.1. (markt)\n    + Update: Improvements to French translations. (remm)\n    + Update: Improvements to Japanese translations provided by tak7iji. (markt)\n    + Update: Update Tomcat Native to 1.3.8. (markt)\n",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/SUSE%2FSUSE-SU-2026:3167-1.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "A flaw was found in Apache Tomcat where access control rules for the default servlet are improperly handled. An attacker can exploit this issue to bypass specific HTTP method restrictions, potentially gaining unauthorized access to protected application resources.",
                    "title": "redhat - https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:43401.json"
                },
                {
                    "category": "description",
                    "text": "A flaw was found in Apache Tomcat where access control rules for the default servlet are improperly handled. An attacker can exploit this issue to bypass specific HTTP method restrictions, potentially gaining unauthorized access to protected application resources.",
                    "title": "redhat - https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:43402.json"
                },
                {
                    "category": "other",
                    "text": "0.01531",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "4.5",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "There is product data available from source Certbundde, The value of the most recent EPSS score, VENDOR FIX as product remediation category",
                    "title": "NCSC Score top increasing factors"
                },
                {
                    "category": "other",
                    "text": "There is product data available from source Debian, Is related to a product by vendor Apache, There is cwe data available from source Nvd",
                    "title": "NCSC Score top decreasing factors"
                },
                {
                    "category": "details",
                    "text": "Severity: 2\n",
                    "title": "Vendor assessment"
                }
            ],
            "product_status": {
                "first_fixed": [
                    "CSAFPID-2454484",
                    "CSAFPID-3052056"
                ],
                "fixed": [
                    "CSAFPID-8882551",
                    "CSAFPID-8882552",
                    "CSAFPID-8882553",
                    "CSAFPID-8882554",
                    "CSAFPID-8882555",
                    "CSAFPID-8882556",
                    "CSAFPID-8882557",
                    "CSAFPID-8882558",
                    "CSAFPID-8882559",
                    "CSAFPID-8882560",
                    "CSAFPID-8882561",
                    "CSAFPID-8882562",
                    "CSAFPID-8882563",
                    "CSAFPID-8882564",
                    "CSAFPID-8882565",
                    "CSAFPID-8882566",
                    "CSAFPID-8882567",
                    "CSAFPID-8882568",
                    "CSAFPID-8882569",
                    "CSAFPID-8882570",
                    "CSAFPID-8882571",
                    "CSAFPID-8882572",
                    "CSAFPID-8882573",
                    "CSAFPID-8882574",
                    "CSAFPID-8882575",
                    "CSAFPID-8882576",
                    "CSAFPID-8882577",
                    "CSAFPID-8882578",
                    "CSAFPID-8882579",
                    "CSAFPID-8882580",
                    "CSAFPID-8882584"
                ],
                "known_affected": [
                    "CSAFPID-3039726",
                    "CSAFPID-6016911",
                    "CSAFPID-8513127",
                    "CSAFPID-8513128",
                    "CSAFPID-8513129",
                    "CSAFPID-8514460",
                    "CSAFPID-8514461",
                    "CSAFPID-8514462",
                    "CSAFPID-8514463",
                    "CSAFPID-8514464",
                    "CSAFPID-8514465",
                    "CSAFPID-2454482",
                    "CSAFPID-8528498",
                    "CSAFPID-8528499",
                    "CSAFPID-8528500",
                    "CSAFPID-8532143",
                    "CSAFPID-8532144",
                    "CSAFPID-8532146",
                    "CSAFPID-8532147",
                    "CSAFPID-8532148",
                    "CSAFPID-8537259",
                    "CSAFPID-8537260",
                    "CSAFPID-8537261",
                    "CSAFPID-1317176",
                    "CSAFPID-3764266",
                    "CSAFPID-3764267",
                    "CSAFPID-3764268",
                    "CSAFPID-3764269",
                    "CSAFPID-3764270",
                    "CSAFPID-3764271",
                    "CSAFPID-3764272",
                    "CSAFPID-3764273",
                    "CSAFPID-3764274",
                    "CSAFPID-3764275",
                    "CSAFPID-3764276",
                    "CSAFPID-3764277",
                    "CSAFPID-3764278",
                    "CSAFPID-3764279",
                    "CSAFPID-3764280",
                    "CSAFPID-3764281",
                    "CSAFPID-3764282",
                    "CSAFPID-3764283",
                    "CSAFPID-3764284",
                    "CSAFPID-3764285",
                    "CSAFPID-3764286",
                    "CSAFPID-3764287",
                    "CSAFPID-3764288",
                    "CSAFPID-3764289",
                    "CSAFPID-3764290",
                    "CSAFPID-3764291",
                    "CSAFPID-3764292",
                    "CSAFPID-3764293",
                    "CSAFPID-3764294",
                    "CSAFPID-3764295",
                    "CSAFPID-3764296",
                    "CSAFPID-3764297",
                    "CSAFPID-3764298",
                    "CSAFPID-3764299",
                    "CSAFPID-3764300",
                    "CSAFPID-3764301",
                    "CSAFPID-3764302",
                    "CSAFPID-3764303",
                    "CSAFPID-3764304",
                    "CSAFPID-3764305",
                    "CSAFPID-3764306",
                    "CSAFPID-3764307",
                    "CSAFPID-3764308",
                    "CSAFPID-3764314",
                    "CSAFPID-3764315",
                    "CSAFPID-3764316",
                    "CSAFPID-3764317",
                    "CSAFPID-3764318",
                    "CSAFPID-3764319",
                    "CSAFPID-3764320",
                    "CSAFPID-3764321",
                    "CSAFPID-3764322",
                    "CSAFPID-3764326",
                    "CSAFPID-3764327",
                    "CSAFPID-3764328",
                    "CSAFPID-3764329",
                    "CSAFPID-3764330",
                    "CSAFPID-3764331",
                    "CSAFPID-3764332",
                    "CSAFPID-3764333",
                    "CSAFPID-3764334",
                    "CSAFPID-3764335",
                    "CSAFPID-3764336",
                    "CSAFPID-3764337",
                    "CSAFPID-3764338",
                    "CSAFPID-3764339",
                    "CSAFPID-3764340",
                    "CSAFPID-3764341",
                    "CSAFPID-3764342",
                    "CSAFPID-3764343",
                    "CSAFPID-3764344",
                    "CSAFPID-3764345",
                    "CSAFPID-3764346",
                    "CSAFPID-3764347",
                    "CSAFPID-3764348",
                    "CSAFPID-3764349",
                    "CSAFPID-3764350",
                    "CSAFPID-3764351",
                    "CSAFPID-3764352",
                    "CSAFPID-3764353",
                    "CSAFPID-3764354",
                    "CSAFPID-3764355",
                    "CSAFPID-3764356",
                    "CSAFPID-3764357",
                    "CSAFPID-3764358",
                    "CSAFPID-3764359",
                    "CSAFPID-3764360",
                    "CSAFPID-3764361",
                    "CSAFPID-3764362",
                    "CSAFPID-3764363",
                    "CSAFPID-3764364",
                    "CSAFPID-3764365",
                    "CSAFPID-3764366",
                    "CSAFPID-3764367",
                    "CSAFPID-6241470",
                    "CSAFPID-6241471",
                    "CSAFPID-6241472",
                    "CSAFPID-6241473",
                    "CSAFPID-6241474",
                    "CSAFPID-6241475",
                    "CSAFPID-6243297",
                    "CSAFPID-6243298",
                    "CSAFPID-6243299",
                    "CSAFPID-6243300",
                    "CSAFPID-6243301",
                    "CSAFPID-6243302",
                    "CSAFPID-6243545",
                    "CSAFPID-6243546",
                    "CSAFPID-6243547",
                    "CSAFPID-6243548",
                    "CSAFPID-6243549",
                    "CSAFPID-6243550",
                    "CSAFPID-6243553",
                    "CSAFPID-6243554",
                    "CSAFPID-6243555",
                    "CSAFPID-6243556",
                    "CSAFPID-7053077",
                    "CSAFPID-7053078",
                    "CSAFPID-7053079",
                    "CSAFPID-7053080",
                    "CSAFPID-7053081",
                    "CSAFPID-7053082",
                    "CSAFPID-7053083",
                    "CSAFPID-7053084",
                    "CSAFPID-7053085",
                    "CSAFPID-7053086",
                    "CSAFPID-7053087",
                    "CSAFPID-7053088",
                    "CSAFPID-7053089",
                    "CSAFPID-7053090",
                    "CSAFPID-7053091",
                    "CSAFPID-7053092",
                    "CSAFPID-7053093",
                    "CSAFPID-7762533",
                    "CSAFPID-7762534",
                    "CSAFPID-7762535",
                    "CSAFPID-7762536",
                    "CSAFPID-7762537",
                    "CSAFPID-7762538",
                    "CSAFPID-7762539",
                    "CSAFPID-7762540",
                    "CSAFPID-7762541",
                    "CSAFPID-7762542",
                    "CSAFPID-7762543",
                    "CSAFPID-8263920",
                    "CSAFPID-8263921",
                    "CSAFPID-8263922",
                    "CSAFPID-8263923",
                    "CSAFPID-8263924",
                    "CSAFPID-8263925",
                    "CSAFPID-8263926",
                    "CSAFPID-8263927",
                    "CSAFPID-8263928",
                    "CSAFPID-8263929",
                    "CSAFPID-8263930",
                    "CSAFPID-8263932",
                    "CSAFPID-8598247",
                    "CSAFPID-8598248",
                    "CSAFPID-8598249",
                    "CSAFPID-8598988",
                    "CSAFPID-1317175",
                    "CSAFPID-1317174",
                    "CSAFPID-1330299",
                    "CSAFPID-8848631",
                    "CSAFPID-8849606",
                    "CSAFPID-8854300",
                    "CSAFPID-8854301",
                    "CSAFPID-8854302",
                    "CSAFPID-8854303",
                    "CSAFPID-8854314",
                    "CSAFPID-8854315",
                    "CSAFPID-8857448",
                    "CSAFPID-1330296",
                    "CSAFPID-8879897",
                    "CSAFPID-1351079",
                    "CSAFPID-5452529",
                    "CSAFPID-9010915",
                    "CSAFPID-9010916",
                    "CSAFPID-9010917",
                    "CSAFPID-9010918",
                    "CSAFPID-9010919"
                ],
                "under_investigation": [
                    "CSAFPID-6016912"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-55956"
                },
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/55xxx/CVE-2026-55956.json"
                },
                {
                    "category": "external",
                    "summary": "Source - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2123.json"
                },
                {
                    "category": "external",
                    "summary": "Source - debian",
                    "url": "https://security-tracker.debian.org/tracker/CVE-2026-55956"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - hkcert",
                    "url": "https://www.hkcert.org/security-bulletin/apache-tomcat-multiple-vulnerabilities_20260702"
                },
                {
                    "category": "external",
                    "summary": "Source - netapp",
                    "url": "https://security.netapp.com/advisory/ntap-20260703-0016"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Bitnami%2FBIT-tomcat-2026-55956.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Ubuntu%2FUBUNTU-CVE-2026-55956.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-55956.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/SUSE%2FSUSE-SU-2026:3087-1.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/SUSE%2FSUSE-SU-2026:3088-1.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/SUSE%2FSUSE-SU-2026:22647-1.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/SUSE%2FSUSE-SU-2026:3112-1.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/SUSE%2FSUSE-SU-2026:22646-1.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/SUSE%2FSUSE-SU-2026:22648-1.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/SUSE%2FSUSE-SU-2026:3167-1.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - redhat",
                    "url": "https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:43401.json"
                },
                {
                    "category": "external",
                    "summary": "Source - redhat",
                    "url": "https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:43402.json"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=10000"
                },
                {
                    "category": "external",
                    "summary": "Source - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2887.json"
                },
                {
                    "category": "external",
                    "summary": "Source - ncscclear",
                    "url": "https://advisories.ncsc.nl/advisory?id=NCSC-2026-0309"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; netapp; nvd; osv; redhat",
                    "url": "https://lists.apache.org/thread/dcjdcnnnww9hhdm016hr0l7hpw1bzjfp"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; nvd; osv",
                    "url": "http://www.openwall.com/lists/oss-security/2026/06/29/25"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2123.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2123"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://github.com/advisories/GHSA-4x29-79gh-6v8q"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://github.com/advisories/GHSA-5v3h-fjv2-54fg"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://github.com/advisories/GHSA-7895-gffq-w6jq"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://github.com/advisories/GHSA-c5ph-rghf-fjfj"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://github.com/advisories/GHSA-mqg3-r7h5-24x4"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://github.com/advisories/GHSA-PG42-RG8C-J886"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://github.com/advisories/GHSA-H792-V28V-PPGR"
                },
                {
                    "category": "external",
                    "summary": "Reference - netapp",
                    "url": "https://lists.apache.org/thread/wlt2no8bw45zl1w8byop4zfqphldf5j0"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv; redhat",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-55956"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/TCOZWVOSSPCRORP3OMSICQT5MPT5Z7FL/"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://ubuntu.com/security/CVE-2026-55956"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv; redhat",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-55956"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://github.com/apache/tomcat/commit/3f6bd2ba5e53d1f340bbe5ad2d42a28b29440b7a"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://github.com/apache/tomcat/commit/9c3b1efb74fd04f77639720af1d48a8f664ad9bb"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://github.com/apache/tomcat/commit/a0374c450970760efafbd8806a1db278830ba7bd"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55956.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://access.redhat.com/errata/RHSA-2026:39189"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GUM3J7NCFJJDCVZU3MRFJSJ4P75CA4DU/"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/654TBDHUNFIPHX45WIOCKLK57NAQ3FS6/"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://ubuntu.com/security/notices/USN-8551-1"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://lists.suse.com/pipermail/sle-security-updates/2026-July/027561.html"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://lists.suse.com/pipermail/sle-security-updates/2026-July/027563.html"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://lists.suse.com/pipermail/sle-security-updates/2026-July/027562.html"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://www.suse.com/support/update/announcement/2026/suse-su-20263087-1/"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://bugzilla.suse.com/1232390"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://bugzilla.suse.com/1269791"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://bugzilla.suse.com/1269824"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://bugzilla.suse.com/1269907"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://bugzilla.suse.com/1269908"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://bugzilla.suse.com/1269909"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://bugzilla.suse.com/1269910"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://www.suse.com/security/cve/CVE-2026-50229"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://www.suse.com/security/cve/CVE-2026-53404"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://www.suse.com/security/cve/CVE-2026-53434"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://www.suse.com/security/cve/CVE-2026-55276"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://www.suse.com/security/cve/CVE-2026-55955"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://www.suse.com/security/cve/CVE-2026-55956"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://www.suse.com/support/update/announcement/2026/suse-su-20263088-1/"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202622646-1/"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202622647-1/"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://www.suse.com/support/update/announcement/2026/suse-su-202622648-1/"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://www.suse.com/support/update/announcement/2026/suse-su-20263112-1/"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://lists.suse.com/pipermail/sle-security-updates/2026-July/027593.html"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://lists.suse.com/pipermail/sle-security-updates/2026-July/027594.html"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://lists.suse.com/pipermail/sle-security-updates/2026-July/027615.html"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://alas.aws.amazon.com/AL2/ALAS2TOMCAT9-2026-027.html"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://lists.suse.com/pipermail/sle-security-updates/2026-July/027694.html"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://www.suse.com/support/update/announcement/2026/suse-su-20263167-1/"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-55956"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2494676"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde; redhat",
                    "url": "https://access.redhat.com/errata/RHSA-2026:43401"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/updates/classification/#important"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://docs.redhat.com/en/documentation/red_hat_jboss_web_server/6.2/html/red_hat_jboss_web_server_6.2_service_pack_4_release_notes/index"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2476511"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2476512"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2476513"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2476516"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2476518"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2476519"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2476520"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2494681"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_43401.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde; redhat",
                    "url": "https://access.redhat.com/errata/RHSA-2026:43402"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2447327"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_43402.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://access.redhat.com/errata/RHSA-2026:49951"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://access.redhat.com/errata/RHSA-2026:49952"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://alas.aws.amazon.com/AL2/ALAS2-2026-3864.html"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2887.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2887"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://www.oracle.com/security-alerts/cspuaug2026.html#AppendixCGBU"
                }
            ],
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Before applying this update, make sure all previously released errata relevant to your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://access.redhat.com/articles/11258",
                    "product_ids": [
                        "CSAFPID-5912598",
                        "CSAFPID-5912611",
                        "CSAFPID-5912624",
                        "CSAFPID-8882551",
                        "CSAFPID-8882552",
                        "CSAFPID-8882553",
                        "CSAFPID-8882554",
                        "CSAFPID-8882555",
                        "CSAFPID-8882556",
                        "CSAFPID-8882557",
                        "CSAFPID-8882558",
                        "CSAFPID-8882559",
                        "CSAFPID-8882560",
                        "CSAFPID-8882561",
                        "CSAFPID-8882562",
                        "CSAFPID-8882563",
                        "CSAFPID-8882564",
                        "CSAFPID-8882565",
                        "CSAFPID-8882566",
                        "CSAFPID-8882567",
                        "CSAFPID-8882568",
                        "CSAFPID-8882569",
                        "CSAFPID-8882570",
                        "CSAFPID-8882571",
                        "CSAFPID-8882572",
                        "CSAFPID-8882573",
                        "CSAFPID-8882574",
                        "CSAFPID-8882575",
                        "CSAFPID-8882576",
                        "CSAFPID-8882577",
                        "CSAFPID-8882578",
                        "CSAFPID-8882579",
                        "CSAFPID-8882580"
                    ],
                    "restart_required": {
                        "category": "none"
                    },
                    "url": "https://access.redhat.com/errata/RHSA-2026:43401"
                },
                {
                    "category": "workaround",
                    "details": "Review your application's web.xml file. Ensure security constraints explicitly deny unauthorized users by path, rather than relying strictly on filtering specific HTTP methods (like GET or POST).",
                    "product_ids": [
                        "CSAFPID-5912598",
                        "CSAFPID-5912611",
                        "CSAFPID-5912624",
                        "CSAFPID-8882551",
                        "CSAFPID-8882552",
                        "CSAFPID-8882553",
                        "CSAFPID-8882554",
                        "CSAFPID-8882555",
                        "CSAFPID-8882556",
                        "CSAFPID-8882557",
                        "CSAFPID-8882558",
                        "CSAFPID-8882559",
                        "CSAFPID-8882560",
                        "CSAFPID-8882561",
                        "CSAFPID-8882562",
                        "CSAFPID-8882563",
                        "CSAFPID-8882564",
                        "CSAFPID-8882565",
                        "CSAFPID-8882566",
                        "CSAFPID-8882567",
                        "CSAFPID-8882568",
                        "CSAFPID-8882569",
                        "CSAFPID-8882570",
                        "CSAFPID-8882571",
                        "CSAFPID-8882572",
                        "CSAFPID-8882573",
                        "CSAFPID-8882574",
                        "CSAFPID-8882575",
                        "CSAFPID-8882576",
                        "CSAFPID-8882577",
                        "CSAFPID-8882578",
                        "CSAFPID-8882579",
                        "CSAFPID-8882580",
                        "CSAFPID-8882584"
                    ]
                },
                {
                    "category": "vendor_fix",
                    "details": "Before applying the update, back up your existing Red Hat JBoss Web Server installation, including all applications and configuration files.\n\nThe References section of this erratum contains a download link for the update. You must be logged in to download the update.",
                    "product_ids": [
                        "CSAFPID-8882584"
                    ],
                    "restart_required": {
                        "category": "none"
                    },
                    "url": "https://access.redhat.com/errata/RHSA-2026:43402"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM"
                    },
                    "products": [
                        "CSAFPID-1317174",
                        "CSAFPID-1317175",
                        "CSAFPID-1317176",
                        "CSAFPID-1330296",
                        "CSAFPID-1330299",
                        "CSAFPID-1351079",
                        "CSAFPID-2454482",
                        "CSAFPID-3039726",
                        "CSAFPID-3764266",
                        "CSAFPID-3764267",
                        "CSAFPID-3764268",
                        "CSAFPID-3764269",
                        "CSAFPID-3764270",
                        "CSAFPID-3764271",
                        "CSAFPID-3764272",
                        "CSAFPID-3764273",
                        "CSAFPID-3764274",
                        "CSAFPID-3764275",
                        "CSAFPID-3764276",
                        "CSAFPID-3764277",
                        "CSAFPID-3764278",
                        "CSAFPID-3764279",
                        "CSAFPID-3764280",
                        "CSAFPID-3764281",
                        "CSAFPID-3764282",
                        "CSAFPID-3764283",
                        "CSAFPID-3764284",
                        "CSAFPID-3764285",
                        "CSAFPID-3764286",
                        "CSAFPID-3764287",
                        "CSAFPID-3764288",
                        "CSAFPID-3764289",
                        "CSAFPID-3764290",
                        "CSAFPID-3764291",
                        "CSAFPID-3764292",
                        "CSAFPID-3764293",
                        "CSAFPID-3764294",
                        "CSAFPID-3764295",
                        "CSAFPID-3764296",
                        "CSAFPID-3764297",
                        "CSAFPID-3764298",
                        "CSAFPID-3764299",
                        "CSAFPID-3764300",
                        "CSAFPID-3764301",
                        "CSAFPID-3764302",
                        "CSAFPID-3764303",
                        "CSAFPID-3764304",
                        "CSAFPID-3764305",
                        "CSAFPID-3764306",
                        "CSAFPID-3764307",
                        "CSAFPID-3764308",
                        "CSAFPID-3764314",
                        "CSAFPID-3764315",
                        "CSAFPID-3764316",
                        "CSAFPID-3764317",
                        "CSAFPID-3764318",
                        "CSAFPID-3764319",
                        "CSAFPID-3764320",
                        "CSAFPID-3764321",
                        "CSAFPID-3764322",
                        "CSAFPID-3764326",
                        "CSAFPID-3764327",
                        "CSAFPID-3764328",
                        "CSAFPID-3764329",
                        "CSAFPID-3764330",
                        "CSAFPID-3764331",
                        "CSAFPID-3764332",
                        "CSAFPID-3764333",
                        "CSAFPID-3764334",
                        "CSAFPID-3764335",
                        "CSAFPID-3764336",
                        "CSAFPID-3764337",
                        "CSAFPID-3764338",
                        "CSAFPID-3764339",
                        "CSAFPID-3764340",
                        "CSAFPID-3764341",
                        "CSAFPID-3764342",
                        "CSAFPID-3764343",
                        "CSAFPID-3764344",
                        "CSAFPID-3764345",
                        "CSAFPID-3764346",
                        "CSAFPID-3764347",
                        "CSAFPID-3764348",
                        "CSAFPID-3764349",
                        "CSAFPID-3764350",
                        "CSAFPID-3764351",
                        "CSAFPID-3764352",
                        "CSAFPID-3764353",
                        "CSAFPID-3764354",
                        "CSAFPID-3764355",
                        "CSAFPID-3764356",
                        "CSAFPID-3764357",
                        "CSAFPID-3764358",
                        "CSAFPID-3764359",
                        "CSAFPID-3764360",
                        "CSAFPID-3764361",
                        "CSAFPID-3764362",
                        "CSAFPID-3764363",
                        "CSAFPID-3764364",
                        "CSAFPID-3764365",
                        "CSAFPID-3764366",
                        "CSAFPID-3764367",
                        "CSAFPID-5452529",
                        "CSAFPID-6016911",
                        "CSAFPID-6241470",
                        "CSAFPID-6241471",
                        "CSAFPID-6241472",
                        "CSAFPID-6241473",
                        "CSAFPID-6241474",
                        "CSAFPID-6241475",
                        "CSAFPID-6243297",
                        "CSAFPID-6243298",
                        "CSAFPID-6243299",
                        "CSAFPID-6243300",
                        "CSAFPID-6243301",
                        "CSAFPID-6243302",
                        "CSAFPID-6243545",
                        "CSAFPID-6243546",
                        "CSAFPID-6243547",
                        "CSAFPID-6243548",
                        "CSAFPID-6243549",
                        "CSAFPID-6243550",
                        "CSAFPID-6243553",
                        "CSAFPID-6243554",
                        "CSAFPID-6243555",
                        "CSAFPID-6243556",
                        "CSAFPID-7053077",
                        "CSAFPID-7053078",
                        "CSAFPID-7053079",
                        "CSAFPID-7053080",
                        "CSAFPID-7053081",
                        "CSAFPID-7053082",
                        "CSAFPID-7053083",
                        "CSAFPID-7053084",
                        "CSAFPID-7053085",
                        "CSAFPID-7053086",
                        "CSAFPID-7053087",
                        "CSAFPID-7053088",
                        "CSAFPID-7053089",
                        "CSAFPID-7053090",
                        "CSAFPID-7053091",
                        "CSAFPID-7053092",
                        "CSAFPID-7053093",
                        "CSAFPID-7762533",
                        "CSAFPID-7762534",
                        "CSAFPID-7762535",
                        "CSAFPID-7762536",
                        "CSAFPID-7762537",
                        "CSAFPID-7762538",
                        "CSAFPID-7762539",
                        "CSAFPID-7762540",
                        "CSAFPID-7762541",
                        "CSAFPID-7762542",
                        "CSAFPID-7762543",
                        "CSAFPID-8263920",
                        "CSAFPID-8263921",
                        "CSAFPID-8263922",
                        "CSAFPID-8263923",
                        "CSAFPID-8263924",
                        "CSAFPID-8263925",
                        "CSAFPID-8263926",
                        "CSAFPID-8263927",
                        "CSAFPID-8263928",
                        "CSAFPID-8263929",
                        "CSAFPID-8263930",
                        "CSAFPID-8263932",
                        "CSAFPID-8513127",
                        "CSAFPID-8513128",
                        "CSAFPID-8513129",
                        "CSAFPID-8514460",
                        "CSAFPID-8514461",
                        "CSAFPID-8514462",
                        "CSAFPID-8514463",
                        "CSAFPID-8514464",
                        "CSAFPID-8514465",
                        "CSAFPID-8528498",
                        "CSAFPID-8528499",
                        "CSAFPID-8528500",
                        "CSAFPID-8532143",
                        "CSAFPID-8532144",
                        "CSAFPID-8532146",
                        "CSAFPID-8532147",
                        "CSAFPID-8532148",
                        "CSAFPID-8537259",
                        "CSAFPID-8537260",
                        "CSAFPID-8537261",
                        "CSAFPID-8598247",
                        "CSAFPID-8598248",
                        "CSAFPID-8598249",
                        "CSAFPID-8598988",
                        "CSAFPID-8848631",
                        "CSAFPID-8849606",
                        "CSAFPID-8854300",
                        "CSAFPID-8854301",
                        "CSAFPID-8854302",
                        "CSAFPID-8854303",
                        "CSAFPID-8854314",
                        "CSAFPID-8854315",
                        "CSAFPID-8857448",
                        "CSAFPID-8879897",
                        "CSAFPID-9010915",
                        "CSAFPID-9010916",
                        "CSAFPID-9010917",
                        "CSAFPID-9010918",
                        "CSAFPID-9010919"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "details": "Successful exploitation of these vulnerabilities could lead to disclosure of sensitive information or addition or modification of data.",
                    "product_ids": [
                        "CSAFPID-8532143",
                        "CSAFPID-8532144",
                        "CSAFPID-8532146",
                        "CSAFPID-8532147",
                        "CSAFPID-8532148"
                    ]
                }
            ],
            "title": "CVE-2026-55956"
        }
    ]
}