{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:2d630967-4ac0-5213-9b32-b5d37f936274",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.1.post1+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:ac5fa9c6-9858-5259-86d3-72850c1d8452",
      "id": "CVE-2022-33124",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-33124 is a false positive for aiohttp 3.8.1.post1+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a8f04ef-a9e2-580c-b5e3-fbd040c99f5c",
      "id": "CVE-2023-37276",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-37276 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e03962f-97eb-5ba7-ab96-0e78cc1a2fa1",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-49081 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a384c8db-c82a-57cd-b716-0b623c7de149",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-49082 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43df72e3-36fa-5e41-9650-ef9a9c5374fc",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23334 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6757cbd1-42a1-554d-b0ba-479c9ea9ecd3",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23829 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2ae0902-8f11-5c97-9e32-9dd3e5ef6524",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27306 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1ed5888-c28d-5314-92f9-036348ac10d1",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-30251 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32d3257d-5c49-5d4a-8bf3-2afac5e10a0d",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52304 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8db62e05-1c39-54f6-b25c-f5609663459a",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-53643 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22600a1c-8378-5fd1-9458-087304371172",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b87ecfd-0e87-5cd1-9c68-54cbd4055b06",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09ca2978-497e-542a-87ef-d00a2603d3e9",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fd6df35-32c4-5d93-8e72-5a9946f384a0",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e520fa43-f5aa-5f5a-ad14-99c285cc5eb1",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afb20e44-25b6-5eec-857e-68acc6431a40",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6bf86a1-42b1-52da-9766-c4978d5514e0",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c58fae00-1fbc-5f67-b27d-6e715412c7c0",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f53b1104-9321-5129-92d5-f16665d8cdd3",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22815 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a746f5b-b5ae-5d3c-82eb-abcbd7215e06",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34513 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:796fe057-450f-598a-9643-fe7b37a4d2c8",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34514 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:188c30bc-17d4-59dc-a92f-1c8f9c0e3feb",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66a77b03-65d1-50e4-a3f8-4eb517746cfc",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34516 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9563427-ceb8-57d0-aa86-85bfd3381256",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34517 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0393d81c-04c3-554b-8683-ca5d7b9f1e4e",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34518 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f164672-a029-57b0-a451-5355e616964d",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34519 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10c6a6ad-ffe8-50ee-978c-349fc0eee1bf",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34520 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e792919-a08e-53df-ad10-11a7c556c2d5",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34525 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0292573d-1019-50dc-b51a-d072f440ba5d",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d54e9c8-81ae-5251-9da5-cbcb059db192",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9c5e56e-b003-5c05-b4e7-87859401f692",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50f2c1bd-f164-5204-bbc7-ebeb13214a09",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13e29fee-75ce-5593-948b-b5993a413876",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42fae804-7cc6-5e58-8763-e4bc1018eadc",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.1.post1+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2515679a-cf90-530e-b627-104964fd4c25",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.1.post1+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:021336f3-add6-553a-a539-62b0cb4117ab",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ccac468-48e6-5c91-87da-73f45b5548dd",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fdb9f16a-52a1-595d-a492-3886df56ab6b",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5f246a5-6589-5622-84e2-1a229c298625",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.1.post1+tuxcare of aiohttp. CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe"
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91ea5cee-da26-51ea-90e7-336517c263c2",
      "id": "GHSA-pjjw-qhg8-p2p9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
    }
  ]
}