{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:59c8fce2-73ba-5f59-a492-f044b2c15310",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.1.post8+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:cc808ca3-0e7e-5f36-98e3-6577c0adfc23",
      "id": "CVE-2022-33124",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-33124 is a false positive for aiohttp 3.8.1.post8+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82c37d67-ca33-5211-bd8e-254f7e8fdaf6",
      "id": "CVE-2023-37276",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-37276 is fixed in version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:921d6ec5-fcd3-5de1-841f-22ff98f126b8",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49081 is fixed in version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbe9fd23-2da0-5a67-8c43-e73cafc125be",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49082 is fixed in version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d181b42f-2793-55a1-987f-f6e4d2584d9e",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23334 is fixed in version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14cb1447-5f6f-5043-ac67-139d3908cf99",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23829 is fixed in version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2929e88-8813-5a5e-841f-fb469e68b5fa",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-27306 is fixed in version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d4ca5ac-5050-5835-8bbd-5e27e7045343",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-30251 is fixed in version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91e9ba74-abc6-5224-ab4b-416feeb9fb3a",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52304 is fixed in version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f2c72c7-3325-5be3-9b5a-ebac6cf70d9a",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53643 is fixed in version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3fcf7844-4e51-57ea-beed-72c0d09c63ec",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6073b5a2-89b0-59fa-89a0-3a7ae2862978",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53648aec-49c7-522a-928f-4ee6afcc4c38",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a185841-4ad4-5a55-a8f1-30aef965ede8",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4b0678b-239b-5dc8-b40b-fa11018c47a6",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52636317-43d5-50bf-9505-ba4348e3065d",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec12651e-6373-5a49-a668-45263d66c818",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0c7237a-80d5-5892-9a4e-02a1e3e9e998",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7728934b-1f04-5824-b1f5-ee63b6e3ca28",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22815 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57df598f-1702-5ce1-9b3a-3b7db3b539b1",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34513 is fixed in version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3564fabb-920d-59c6-9f68-685d30c368e9",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34514 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb6cf5cc-4206-5c50-a623-02072dee7305",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd08252e-5584-5eef-9ba8-20d2b5378cf3",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34516 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b965b7be-3c56-5626-bcaf-dc1dd0e5d304",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34517 is fixed in version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5cfd8cf8-7e50-5fd5-90e8-ae30cc027480",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34518 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32694423-fba6-57d8-bc9e-cd535aa0c57f",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34519 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26716d6f-2487-5208-b3cd-1b0cf8cb5cb7",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34520 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b85c733-f2bf-53f5-a6f2-0b0cfa1dbd48",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34525 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83e6f788-b589-53bc-862b-ddd8317485cf",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33bff859-502b-588d-a171-60521b1a9fb2",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a81c8324-277d-5ac7-be64-213f2fcdb1d9",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db182ab3-48c6-5e27-9b6e-c2046fa2b965",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff0f051e-4d90-5e93-a017-99c19034dbad",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ffe79d00-37a7-53dd-aec7-97d28ed1291a",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.1.post8+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40d38dae-3fc7-57f6-85c5-019ea070cf93",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.1.post8+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b663646-2231-5737-b03c-8a0358190373",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c62cfdf-c7b0-5cee-a911-a46df74361af",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63d1401b-d509-594f-89b5-2f61ee15847e",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc1e9983-1a75-52cf-9c9d-f5a9b30c02cf",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.1.post8+tuxcare of aiohttp. CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe"
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7d1b761-5a75-571d-881c-281173d0d2bd",
      "id": "GHSA-pjjw-qhg8-p2p9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-pjjw-qhg8-p2p9 is fixed in version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
    }
  ]
}