{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:29a469e5-c2fb-5647-94ef-3d17b2c57614",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.1.post11+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:f6984609-6725-5e9f-81a0-10d9648e83e2",
      "id": "CVE-2022-33124",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-33124 is a false positive for aiohttp 3.8.1.post11+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05aab2de-82c1-5998-a3bb-e6d60d65a99c",
      "id": "CVE-2023-37276",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-37276 is fixed in version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40b1368e-fedc-5248-af54-8c119a73edcc",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49081 is fixed in version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3053030-7e54-5143-bae2-ac0b9df1ffc8",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49082 is fixed in version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c8880c2-0abd-5b05-8bac-b334f24be125",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23334 is fixed in version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55c21fdf-0778-58b4-815e-91d9e26d3c1f",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23829 is fixed in version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98cb501d-da1a-5b6b-8bb6-e23e2661b20d",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-27306 is fixed in version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23a869d1-5214-5a5f-ae5d-cd0b83dd388b",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-30251 is fixed in version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c4175d0-ee0b-5ef1-8e7e-df3bc84e8901",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52304 is fixed in version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:879d63c7-6255-5573-879d-1cd5547d549e",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53643 is fixed in version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9e2e8e9-98d0-53fa-b323-f7d7584877c6",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55faca34-11fa-5f39-a88a-4ae4da347d71",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5166930-1eec-5e00-9c8a-e6ba7090280e",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82f90e01-ff3a-55e7-b208-0a49344333e4",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24b12dd4-13ff-5df5-af50-0cdb95ab4a36",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f6188ac-d32d-5b4d-9fc3-e593ee8d247e",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b82cb01-29d2-5a41-ba2a-99e3d7a8d33c",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58d34624-9aed-5a84-84cb-fd6948f3b2c1",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c73f428e-f1bf-51a1-b99d-a2344171ad0b",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22815 is fixed in version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ae30683-00d1-5281-a817-784fa6b12d20",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34513 is fixed in version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2385b82-4f10-548b-a2ad-77ce503c3bce",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34514 is fixed in version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:887b2751-3142-55c9-89e4-10d1c91068c9",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1fcb1a62-0e5f-532c-8145-848431ef9f5f",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34516 is fixed in version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2599dfa2-874b-5d60-a0c4-ac07fa3197e9",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34517 is fixed in version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4a0e803-668a-5860-9014-075646b27b33",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34518 is fixed in version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4bcfd870-cd5c-5e97-b719-22f35c7b556e",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34519 is fixed in version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f3c70f8-db5a-50fe-bf44-bd1c6db6ac4b",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34520 is fixed in version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57631646-ebd4-54a8-9a6b-e282e14f4dfe",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34525 is fixed in version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77a73ec8-6546-5596-ae84-898ee20a9de4",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97502266-f289-5435-b2f1-ac5ce6e3a07c",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd2d93d9-f572-54a8-bf7a-5e4e146bb41b",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa65fdfb-a5eb-5de2-8e1f-12b0734632c7",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0467e054-1ef3-53e4-a6e3-54bfc3729a9d",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:faf18582-cc45-5e98-87ae-c5013bcc1d81",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.1.post11+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a01b97c-97b8-5979-8b9f-6dc0c3a62795",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.1.post11+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7932ceef-4d7c-5a58-901c-f83e2caa0fd1",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e2bfcb5-5cae-5e88-8b7b-3ab9a28e26b8",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbd06466-7356-5a2d-8fe4-8a1458331339",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f38711aa-b3b4-5903-be1b-251bbe42fb22",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.1.post11+tuxcare of aiohttp. CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe"
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4fc954c-7b04-58dd-91e8-8cedd4211cac",
      "id": "GHSA-pjjw-qhg8-p2p9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-pjjw-qhg8-p2p9 is fixed in version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
    }
  ]
}