{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d84cefa0-1aec-5380-a190-e1cd59944a20",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.6.post1+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:78a7cbf9-109b-5048-b5f2-3b55fd4eccd3",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-49081 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab93bbf2-1d45-5ce6-ab89-384424989615",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-49082 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86b21d71-c518-563e-b01d-2238958664d8",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23334 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3215a656-af25-576a-afd8-9639cc76f810",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23829 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d53ac28-aaf1-52de-9ee1-73e36d453b54",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27306 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c804fd2-653e-5a69-83ba-61eb40e3014c",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-30251 is fixed in version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b325dff3-4785-550d-a07e-417c1a401bfc",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52304 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8122a549-1d67-5522-9061-877ced349b38",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-53643 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e90d3e53-4990-556e-9f02-919d214fd164",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:262f1ff1-c191-5ba1-a82a-596227a6a76c",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90f5f698-c47c-5dfd-a96a-4eb8498568aa",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aeed7e82-9def-592d-b535-175559328952",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45b14c58-b46d-52ce-b237-be0fdb39d950",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f16ba94-17f5-5eb3-bd45-b85216d054e4",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e928b027-3e7a-5a9b-b711-321bcfbec957",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff606ea8-c3b3-5da7-93db-ad202845e936",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30c32613-4514-5917-a0b8-0bacfadad88c",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22815 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c943e838-a869-53e6-9be8-04ca363ad0d1",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34513 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c22970b2-5e94-5f6d-bcf4-23dcc52c31c6",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34514 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:427e8b25-40b2-52cf-851c-6fc214db1ab3",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f3e43f6-dbb0-541c-a369-7e5a6ce22b6d",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34516 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a519b20a-0922-58d7-8b0d-db474f4ff0eb",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34517 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27e7fa4f-32ec-5338-8098-3b68877a2614",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34518 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b2e2075-bc32-5d09-9cf3-1b263f5e16f9",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34519 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:feb78044-2c07-5316-ac9b-bf7d83118bb3",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34520 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ef06b6f-f5bb-531d-987c-3e066c21e801",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34525 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c604611-70f4-5e6b-a7b3-affe0f3a36f3",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03e40610-fb89-5fa0-95db-2687f8571d66",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f570dcd6-e2bf-5f4d-b644-260c961706f1",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ebca4a4-b801-56fb-bc87-df21e61de033",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fac5eddf-da48-5e2c-bdc2-f17b118e3c29",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64c4f4c7-0493-5c73-9eeb-53e0c1f1b48f",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.6.post1+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d68a4390-ebec-599b-86bc-c429c971daae",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.6.post1+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e7bb516-e0ce-5081-be61-1310a009f11e",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f42cd5b2-7bc3-5901-8d46-01e844bc5db9",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99e1e6ed-ad65-564c-831f-bd95a8c9406b",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3571b3f0-f4c0-5e75-92c2-672fe4a214fd",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.6.post1+tuxcare of aiohttp. Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
    }
  ]
}