{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:939feb20-553c-50f6-9428-c820812bb092",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.1.post2+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:308e7e9f-f05e-5e4b-b075-68b081426253",
      "id": "CVE-2022-33124",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-33124 is a false positive for aiohttp 3.8.1.post2+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff15f441-6c0e-5749-a6f0-17723f858a71",
      "id": "CVE-2023-37276",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-37276 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90fc8532-e193-51e9-87f5-5554964ac743",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49081 is fixed in version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5123f454-7426-59c6-b6c7-ab3dc8849c3a",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-49082 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be66cc7f-b157-592e-8d09-6f0e1a7f92ba",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23334 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f45d647-50c6-5990-8385-11e793229281",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23829 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56d008e0-4778-57ad-afc2-87bbb00bb806",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27306 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcdbe26f-8be5-5468-888a-a17894be8afe",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-30251 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f03a4fb6-768d-5034-b0d4-9f4eb1ba36b7",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52304 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50ceef91-c2be-59c3-a4bd-c1c35669580b",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-53643 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a35ed9f3-3753-592d-b0b3-a0fe2b775f34",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9863194b-fe97-5bde-94e9-2cbe2a5e6196",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b5ed928-c014-5a9d-be0a-54445e819589",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3e5d6dd-9fab-5b63-822d-40a111da7b91",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd66abee-42fc-59d1-8353-8d22d484e741",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70424e44-785b-5e38-88a9-7749c28b5ca2",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f02f7fa-4cd0-5e84-9f8b-99257cbedbd2",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcf7c713-dd9d-5fc4-93ad-9900b3a95f8c",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87021d5f-2714-5726-8547-5a462fd7c331",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22815 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98c994ef-6558-5938-a129-a7f7a99ce4fe",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34513 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:542a41f3-6cfb-5372-acd5-dc4622b96dc3",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34514 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4834e793-cdbc-52ab-b7c5-19ce3e072fce",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6e31bf4-76fb-5f62-a398-3d0eee15f2d9",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34516 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff088aab-99e4-591e-98ba-8b5823af0ec4",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34517 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:740b0491-30a6-5c06-b1a9-827a059645dd",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34518 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8e04697-935e-590f-88ec-1e0621ec5ed2",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34519 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2d14588-46ad-5536-8762-d3a53eabcaa1",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34520 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:acf644b8-effb-54ac-a0ec-d80dfb36a5a5",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34525 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:baef910d-6a09-5265-b399-a9b6da351351",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:113d1182-cd8f-5da2-ba8b-db6181308d03",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6dbbc972-247c-50de-b969-9c0096f26f91",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5ad0c5a-473a-5093-8030-c209cf94165f",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0495ca15-7731-5a97-9827-8009a91fa9d6",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa842b9f-3745-5635-93f5-870295b664f9",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.1.post2+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20952625-f5b5-5f73-acfa-ee5e3271ffd5",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.1.post2+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:411e5b7c-cc0d-5d44-9dfd-310dbb97e813",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d97bfb72-676f-50c3-92a7-31dde056b192",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58c6a208-563b-56a9-8110-996865469e47",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15e4ec42-5410-53bc-a04a-59fa3c64d644",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.1.post2+tuxcare of aiohttp. CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe"
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd84c1bf-13ef-596d-a33b-cc417dfe155f",
      "id": "GHSA-pjjw-qhg8-p2p9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
    }
  ]
}