{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:071173f5-748d-5a75-8096-d7cc2005230f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.6.post3+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:56b570e2-082c-5712-98e3-22a7ddfe3523",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-49081 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12cb4bf4-0ccf-58ec-8c38-ae1d4ba766e2",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49082 is fixed in version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6c11800-6536-5c4a-b849-ac5fac3878b8",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23334 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16af813d-bc67-5605-b7b2-76f8f7850e7b",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23829 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2741d217-bc6f-5d8d-ab0a-9ba4cb54079b",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27306 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ccd095b6-bf2f-51b3-a0c3-f7ac68e3e3b6",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-30251 is fixed in version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4d5b549-524e-5077-9ed5-3dec7f48fab9",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52304 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:839ee2bb-f1d2-5f8c-b711-a3618f7502e5",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-53643 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec59f775-e5b3-56e3-b809-d9ecf1242c92",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be262416-0742-5e7b-83fa-be29cc08b94d",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c6b5eec-e142-50d2-9329-40dd355aaf7f",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6674be27-b66f-5334-a858-b88d0e39f804",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60d369e5-6c98-5bd7-a335-72d63ceb238b",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f58fdc1c-1f53-5ccb-8f08-91fa4b8b26d3",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c5a295c-6abc-5082-a826-188a2a0b1f06",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2497f4c-ef10-5aff-8a20-8bd067718563",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:093880df-b5d8-5684-aeec-0a4a5408e318",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22815 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a8f8911-a519-5f12-8ce2-933590a093e0",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34513 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ea649f2-97f7-54f8-ba13-cc9ef151f78c",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34514 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c8a458d-be1a-5e4a-b6d6-783ef8cd08c1",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:deac2fb0-06d7-55c2-9056-856385577b02",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34516 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9d0c7c6-3a5f-5297-9e96-ba548a043e31",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34517 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9084c4f5-4414-5dc7-b980-6e1ec911d9ba",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34518 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36a08db5-d61e-5c38-ae35-8aeeef8b2f1f",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34519 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40e27d29-6e23-5d69-aa9d-8dcd708342c5",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34520 is fixed in version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4915f281-2245-5f7d-ba2b-838095aac910",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34525 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ca0d99e-2108-54a4-a6a1-2cdb81caa899",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2477986-95e8-5fe3-ad0b-9700ade50b5a",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3265b9cb-b1e2-59cd-87ab-dc73de3393b6",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06dcfc4a-0adf-5f48-a15b-0803c2f8ec54",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:002aebb5-ed81-5dee-9b1f-b5867681f01b",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:961a7e1a-6462-55f1-9a2f-7b5809322240",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.6.post3+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bea350cc-b477-53da-a279-0a2f0874696b",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.6.post3+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f8f4362-d5b6-59ee-82ad-552c45a9ece6",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7352166-0cf8-59d2-8217-a00032d18b2f",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c43adb7-2c8b-5a72-88d2-b2a4877034aa",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8581331-38a2-58ee-b9bb-cacb110e8ed6",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.6.post3+tuxcare of aiohttp. Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
    }
  ]
}