{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a02fcdbb-e7f8-51c6-8e79-a9de152c7c3f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.1.post5+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:1f698476-eb6a-5256-9bb9-34e1131c8fab",
      "id": "CVE-2022-33124",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-33124 is a false positive for aiohttp 3.8.1.post5+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12eaf67b-74f4-50ca-b277-6ed1522c41fc",
      "id": "CVE-2023-37276",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-37276 is fixed in version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da985fd4-4ae0-5444-b5bb-658a38f695d2",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49081 is fixed in version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ece88f6-2707-5bd3-8456-b597240ff2ae",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-49082 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b4deb8a-7ed7-5f70-af97-6bdeba5d8bdb",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23334 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d00b5611-ff5c-57d2-bcc9-4e03b0734db3",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23829 is fixed in version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9984b3c3-03e0-548b-951e-97dfd4d683b9",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27306 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:565a822d-ed8d-5252-92e6-f7e786bba97d",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-30251 is fixed in version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4672bfb9-0d8f-5722-a05b-1b31186e8c83",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52304 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc1b03d7-9dc4-52c5-91dd-021877fb0ba3",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53643 is fixed in version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b1f2dd8-24b9-54e3-a87e-d2e32f38ba89",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1cb237a-c9de-529f-97bd-65b5eb7cd8ed",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb8fa4a5-3b3e-5081-a1df-4ba151c8b97a",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5da47dad-f5f6-5378-b393-e70ba3119b4f",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71750835-0eac-51dc-bb02-b14596a201c3",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2530eb8a-6634-508b-a85b-442b0d777367",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00a65e7a-79a5-568f-bfb9-0347524e90dd",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27018dcd-9128-557a-a78f-f407edc7d534",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f3e924a-57c5-53ce-aff1-5ccacdf130d2",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22815 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8379eb63-5a58-575e-828d-d8f11a5d4a57",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34513 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:544dd432-8f62-53cd-bca8-f04251ef9602",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34514 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9196eb2-8adb-5d66-9f27-78ebca0086bd",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b379ba2-4f7f-5423-bfda-9dae55b72977",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34516 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee6516d7-e91b-5909-914e-9e1455da5bc0",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34517 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f29098e1-af62-5a7e-aa81-62478e7ce6d9",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34518 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:282c94e9-4bbd-5c59-bbb9-1a8e492dbed5",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34519 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a434e67-c40d-5608-a03f-e1e51ee2728c",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34520 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75c2d644-f4e6-5264-9cab-85a09ec0dd4c",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34525 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:136da239-e060-5060-87c4-0b9b8be78943",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80e11318-9389-5e89-9ca6-463c42cf43d3",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a00a4afa-e271-5615-840f-a65929bc4388",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac499b89-7082-5697-925c-03b6102657b1",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ddb46bb-ffa1-54db-b632-5a568da1b94c",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0120527e-1f2c-5aae-b0d9-d10b99b13833",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.1.post5+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d753af1c-579d-52ec-a4d4-61fb75a9509c",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.1.post5+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c91ed0ea-8bb6-54a2-a531-d9b0f24f7138",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74015640-9100-551a-80df-f0de2afb46c1",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f34584f1-bb41-547f-97d1-37870e0a352a",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d32c1ce-015c-55aa-9c13-00fa16b187be",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.1.post5+tuxcare of aiohttp. CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe"
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2da9bbda-40ed-516c-b4d2-2b1b3fea89ad",
      "id": "GHSA-pjjw-qhg8-p2p9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
    }
  ]
}