{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e737d7f5-184e-5b5e-bd99-fb1c0bcfe04e",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.1.post4+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:59b9e9cb-eec0-5f51-9aa1-943493d84066",
      "id": "CVE-2022-33124",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-33124 is a false positive for aiohttp 3.8.1.post4+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:057244f0-107f-5d80-997d-e914a51b128d",
      "id": "CVE-2023-37276",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-37276 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31857bf4-ce71-5e31-af9e-1f0b80dc4515",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49081 is fixed in version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7ab5a53-f09e-56ee-8a36-14c8dfc36f73",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-49082 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da88e611-dd5e-5d47-9675-b4f4f370d672",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23334 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27ab1439-1a14-598c-8969-eab48dba7d75",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23829 is fixed in version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:347f170b-2a6b-57a1-990d-9f932dfda2ce",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27306 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6bfaf253-3a4e-5e31-9d54-8fade7763da5",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-30251 is fixed in version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21475896-a29d-53f5-b306-1284f915a09e",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52304 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f24d557-2944-5006-8a5e-e25c1988099c",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-53643 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37ef5429-d867-57a4-bb6b-add261ef7cc0",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7160a1c-3887-50d7-b8d0-0c6aada34cb4",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b5689d9-94c7-5103-a870-1c6499d0d185",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5029fbf-e60f-5e9b-8ce6-a57444c3bd5a",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a9bbbb4-9bd0-58b2-b078-f0be68feb6c5",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:563b1f17-f9ea-5f8c-9707-0017051b20ff",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8343628c-94ea-577d-b7e9-61c83337592f",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2257f034-39cf-538f-86d6-ead8644c52e7",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8aa1bba3-a456-5fde-a89a-372fae38fb26",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22815 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c6692f7-b840-5a02-8496-ef151f90e2ae",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34513 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b951a269-8a38-5bf1-81f2-3c7115141d3e",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34514 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9a245aa-85d8-50a6-9db1-d8f22e9de46f",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78aabf7d-011c-5a96-a009-1cd3532c83f8",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34516 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de9ab509-5c2e-5b7d-8684-1730bbe29d69",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34517 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1151938-2797-5d9f-a3af-d3088a62abc1",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34518 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9c91e22-c224-594a-bf4b-81cdf389d89a",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34519 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a9a8d40-cfac-5688-8b47-40a9c5350f92",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34520 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d763b6d-7cc6-50b1-ba9e-cd3a0f512984",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34525 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2809847d-cdb2-5b9c-af0b-b30db2268827",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ad6e65b-c2ae-5c11-98f6-c2561715b5e9",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83589a36-eef8-5031-a46e-9342578f1419",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0649a3e7-ce02-5e80-b8a6-063ddc28a2c8",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c567e9a9-19a4-558d-85cb-35b9f3bc6455",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62a2caee-9d74-589b-91ac-8876885e99c0",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.1.post4+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1be3ab43-1577-5860-b3db-77a63de099d9",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.1.post4+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c936f9c-f26a-5490-8fdd-0f514805a1ef",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7cb931a6-55a4-53a2-a971-bea429a8aec3",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14fc76a0-35f9-54f6-8d26-815d0d00f93c",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04d56068-45fe-57d2-941a-ca9c95f9dd57",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.1.post4+tuxcare of aiohttp. CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe"
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aec19409-ad29-5d9b-aad8-9cbabca306ab",
      "id": "GHSA-pjjw-qhg8-p2p9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
    }
  ]
}