{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:1d6c83fb-8307-5079-843b-4ec9feb5ba7c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.1.post7+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:efe1c1ef-d7a5-5eee-b4d7-2fc696e8d414",
      "id": "CVE-2022-33124",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-33124 is a false positive for aiohttp 3.8.1.post7+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5fa5600-b371-521d-95bb-215421a4af62",
      "id": "CVE-2023-37276",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-37276 is fixed in version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d6d54d9-429b-5298-a308-bb30100fb3e9",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49081 is fixed in version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1120dea-3025-5eeb-8b76-ebc3a8e9cfee",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49082 is fixed in version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d9ff890-5780-5b4d-8920-242062fc3532",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23334 is fixed in version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:447be8c5-dfa5-50ec-8a6c-518bcd082290",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23829 is fixed in version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29f84cac-7980-57b0-812b-6c5604870fb8",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-27306 is fixed in version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6d34b5f-183a-5fdb-abe5-76aa121ce7c3",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-30251 is fixed in version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac8f0870-2e8a-515c-88e5-baf69ccb46f9",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52304 is fixed in version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9c4b35d-eef1-5d99-b8dc-94af3feca52b",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53643 is fixed in version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:067940de-f835-5029-bcb2-e8c71a9971da",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bcd3f6e6-827a-5250-ae4a-293292eafa13",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a21c0f35-9973-5ab3-b01e-593f9e5721da",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:420890f9-377a-5f2b-9890-d0506f883404",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d28568b-9b78-5593-84fc-09435702f6fd",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb95dda7-0a74-5aaf-b9f6-d6ebec9d92c3",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6acb94e-fa45-5e97-b38e-144cb2ae7316",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b67b708-0921-5e0c-916a-960ecf2f6115",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b12a02ce-280b-564a-b038-19dfcfa6e436",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22815 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e574bf43-9499-5d4b-9506-c40256b0da93",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34513 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df168562-233e-54df-860c-c2dfffcdeb20",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34514 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef1ce006-f63f-5be9-98c8-2b97cf29b4ed",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd6da254-c879-519a-bb98-0efcf7130fcb",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34516 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e03cae1d-c402-54bb-9e39-9f4853883490",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34517 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d74c2028-baee-56dc-8136-0826373b2e5b",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34518 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13fabdb0-39de-528c-adac-4bc253204cc0",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34519 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca580f76-5a39-5659-855f-e137634732d0",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34520 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6353b66e-2985-54ac-a8ad-84173c3ce5f9",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34525 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:305de710-f182-5671-9fd1-72ea94c15f6f",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4442ea4-7225-511a-a106-f1181d706130",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8aadce3f-1698-52cb-8de0-af34dd99b57f",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37778db4-c922-56df-9f1c-c4c372fecc59",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eab5e0fa-93c2-548b-9e8a-37cd3ad29cf6",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd3ab937-5b75-5051-aeb4-47175553e8b9",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.1.post7+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac5d40a7-787d-51ca-8c44-d26f7d9d52de",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.1.post7+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cab7e913-4d54-5d16-8a70-113b6f4a10d9",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32d9aa49-a8c4-54c9-87fb-73a57d9d74d7",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0e438c1-fb51-596e-9174-ee37634bb60b",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d578f3b8-59f4-52d2-a9ce-f2425eb17e96",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.1.post7+tuxcare of aiohttp. CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe"
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85374b67-b2cd-5bbd-9237-0ccc37d41774",
      "id": "GHSA-pjjw-qhg8-p2p9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-pjjw-qhg8-p2p9 is fixed in version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
    }
  ]
}