{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f4931f7d-1735-5f7b-aa56-096a79145c23",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.1.post6+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:ec220fc3-2011-5034-b7e9-f7b6632d2eea",
      "id": "CVE-2022-33124",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-33124 is a false positive for aiohttp 3.8.1.post6+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e2b212c-d910-5208-99ca-4551d5ca48de",
      "id": "CVE-2023-37276",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-37276 is fixed in version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1718bab2-14c1-55d1-a241-665ddfc3c192",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49081 is fixed in version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbd8c8dc-4c41-54ca-bec7-2a586536c0e8",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49082 is fixed in version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb6177f9-5170-549c-9368-5941ea99517d",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23334 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60818faa-61a1-5a1f-9d86-f5313c72bd67",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23829 is fixed in version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef2fc72d-3136-5745-818a-d0f01caee328",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-27306 is fixed in version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:989e9734-004a-59d4-a3a6-250c692f5928",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-30251 is fixed in version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:041ae525-0355-57ac-b71a-d4a4e313bf3b",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52304 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7de3a6db-cad4-5ed7-9dad-c9bee09013ca",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53643 is fixed in version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2b895d1-afcd-50c0-9aa0-ad5c1a22c193",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50dab4f4-6a77-5346-b529-d5129f2ebec2",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1ccde4c-3524-53a0-a257-2d224e7e3182",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a78c338-6939-5b98-9433-92c477cfc7a5",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c48731d1-64f0-561c-942a-79d6d3455127",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8178fdb8-b504-542c-80a0-9773f81ba401",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cca8b0d5-d9e0-5d60-83ca-d9c9a7279b35",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:409ee904-b7fa-5780-8ad3-7e4b70b751d9",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d98008b7-32bd-5d4a-b0fa-3279426bdd61",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22815 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:789a1f86-d9c4-558f-9b47-6809593f0a44",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34513 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0c7379a-fafd-5ed3-83aa-d5276a8c0c33",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34514 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ded7465-c6cc-5880-9d2a-dc8221addbb3",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e85940f3-aaf0-53b8-8d95-5647ae40eebd",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34516 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbc66457-953e-5d11-8495-726aacb966e9",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34517 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c303fe70-b0df-594b-be70-24339a9812bb",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34518 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8849470f-c753-5b02-9ecc-bdea0bb8fb77",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34519 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4991d4b-017e-599a-81af-9e04e9b8835a",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34520 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24ae41e0-469e-5de1-bb02-4242b1ad0711",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34525 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42f7426b-1c1a-51b5-b1fe-19fad9b484f0",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99baf69f-e981-5657-bb9c-d442c98dfbcf",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ccf2a614-a329-5b53-a584-36e6ed35e866",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:baae7c48-7654-5629-82a4-5650fd2be391",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6a274bb-c1fb-5fae-bf71-724aaa2c9408",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc9858c3-09af-5060-bd05-9f1270a29749",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.1.post6+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05bf5d42-802a-5591-9b94-82971736b70d",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.1.post6+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c9fc676-becc-58f6-9aec-06b3355d5bdb",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56949f9e-8b6c-5a84-a24b-d9eb92cc14f5",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45553d25-2a3c-54f8-80ff-5c74830045b4",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79135d11-1a3f-519d-8e8e-4c077faace4a",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.1.post6+tuxcare of aiohttp. CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe"
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57039b05-a6a2-5280-bedb-031ba9e2257d",
      "id": "GHSA-pjjw-qhg8-p2p9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
    }
  ]
}