{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b55d257b-09ea-5ff7-b0d8-4b8e3d839ac3",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.6.post2+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:efaf9d04-2cd0-57ff-ae05-b264c933f8ab",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-49081 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5464dd7-19ef-5cd7-9194-f40df12f72ca",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49082 is fixed in version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:998c9055-f854-5ec9-9940-c1a0ef8f11f2",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23334 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c373221-049a-51dc-a357-db90bf17627c",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23829 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:124e8c57-e1f2-53a4-80f5-b28765723ef5",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27306 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2515c524-455d-54e0-9e17-82dffe70e6c9",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-30251 is fixed in version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:893a8794-8c81-577c-ad4f-fcf667a95df0",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52304 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a026e511-4918-5255-b464-c685501f38d5",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-53643 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50883f7e-4ea8-5b07-8a77-ae3e6c7b044a",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41d4625c-a0e2-5365-a64d-ef12b91b4621",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f10b9db4-d9e9-55bc-a587-27c84c1050ff",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bda846b-223e-5ad1-82de-ebbac3a2810c",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49270a6e-4bc5-5285-83a6-94501a21b552",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f4eeedd-7f30-5a1c-98dc-062e07a83293",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0039f55d-f42b-524e-859b-8552ea72c1f9",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8cbe4fbd-5483-5804-b86e-0144c0182e57",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0db9a52-6153-5e5e-8e7d-a3dfc7c5ddb0",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22815 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f9e6f8a-c38c-5245-8b56-53418f1ea23e",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34513 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b84f9c5b-5281-5738-aa46-834a6f2754d1",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34514 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ffcd3e9-0416-5efa-aed2-543e557cb515",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f60abfac-251f-5abf-8ad3-c608195b3b3a",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34516 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f81b3cb7-bf0a-55d7-89f1-6f868128c5e5",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34517 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:573d0b7a-2595-5e1c-8aed-f9291ef6855a",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34518 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df773947-5365-5ae7-ab7e-d0af15300e39",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34519 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bee851e-fccd-52dc-bcee-1f4c43157df1",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34520 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8ac9bd2-1b91-54b0-b7c8-0e255f0c7b19",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34525 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:070c0945-eab1-56ed-98fc-544261e91ec0",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8dca71f-1747-50be-bee6-fbb074d52df8",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:acfc7ded-f1a2-5f63-82f3-0cbfaac25518",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:233ec697-f7e3-53ef-9ed7-14c65fa6c6e1",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3822cba-fcb9-5d33-84e3-c16a344bb6aa",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ea6d090-6537-5be6-b2af-671f83fb393a",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.6.post2+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a34bb32-93f3-573a-a4b9-e9dccdb9ef0a",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.6.post2+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f926a6d-c440-561a-b727-b7441a56c0eb",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8ef79d0-205f-55a0-81b9-6ad74c6047b5",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2abd8b1d-2053-5c45-b2dd-751696ccbee5",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95b0bbd7-8055-515a-8f91-226b87aeefe6",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.6.post2+tuxcare of aiohttp. Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
    }
  ]
}