{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:7633e241-d687-5469-b366-cb45092b7872",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.6.post7+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.4.post5+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.1.post11+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/tornado@6.1.0.post5+tuxcare",
      "type": "library",
      "name": "tornado",
      "version": "6.1.0.post5+tuxcare",
      "purl": "pkg:pypi/tornado@6.1.0.post5+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/django@4.0.post7+tuxcare",
      "type": "library",
      "name": "django",
      "version": "4.0.post7+tuxcare",
      "purl": "pkg:pypi/django@4.0.post7+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/dulwich@0.25.2.post6+tuxcare",
      "type": "library",
      "name": "dulwich",
      "version": "0.25.2.post6+tuxcare",
      "purl": "pkg:pypi/dulwich@0.25.2.post6+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/cryptography@43.0.3.post3+tuxcare",
      "type": "library",
      "name": "cryptography",
      "version": "43.0.3.post3+tuxcare",
      "purl": "pkg:pypi/cryptography@43.0.3.post3+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/gitpython@3.1.31.post3+tuxcare",
      "type": "library",
      "name": "gitpython",
      "version": "3.1.31.post3+tuxcare",
      "purl": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/gitpython@3.1.31.post2+tuxcare",
      "type": "library",
      "name": "gitpython",
      "version": "3.1.31.post2+tuxcare",
      "purl": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/starlette@0.27.0.post6+tuxcare",
      "type": "library",
      "name": "starlette",
      "version": "0.27.0.post6+tuxcare",
      "purl": "pkg:pypi/starlette@0.27.0.post6+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pypdf@5.9.0.post11+tuxcare",
      "type": "library",
      "name": "pypdf",
      "version": "5.9.0.post11+tuxcare",
      "purl": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/transformers@4.57.6.post3+tuxcare",
      "type": "library",
      "name": "transformers",
      "version": "4.57.6.post3+tuxcare",
      "purl": "pkg:pypi/transformers@4.57.6.post3+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/python-multipart@0.0.6.post6+tuxcare",
      "type": "library",
      "name": "python-multipart",
      "version": "0.0.6.post6+tuxcare",
      "purl": "pkg:pypi/python-multipart@0.0.6.post6+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/mlflow@2.22.4.post6+tuxcare",
      "type": "library",
      "name": "mlflow",
      "version": "2.22.4.post6+tuxcare",
      "purl": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/cryptography@44.0.3.post3+tuxcare",
      "type": "library",
      "name": "cryptography",
      "version": "44.0.3.post3+tuxcare",
      "purl": "pkg:pypi/cryptography@44.0.3.post3+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/langgraph-checkpoint@2.1.2.post3+tuxcare",
      "type": "library",
      "name": "langgraph-checkpoint",
      "version": "2.1.2.post3+tuxcare",
      "purl": "pkg:pypi/langgraph-checkpoint@2.1.2.post3+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pypdf@5.9.0.post10+tuxcare",
      "type": "library",
      "name": "pypdf",
      "version": "5.9.0.post10+tuxcare",
      "purl": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/transformers@4.57.6.post2+tuxcare",
      "type": "library",
      "name": "transformers",
      "version": "4.57.6.post2+tuxcare",
      "purl": "pkg:pypi/transformers@4.57.6.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare",
      "type": "library",
      "name": "mlflow",
      "version": "2.22.4.post5+tuxcare",
      "purl": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pypdf@5.9.0.post9+tuxcare",
      "type": "library",
      "name": "pypdf",
      "version": "5.9.0.post9+tuxcare",
      "purl": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/tornado@6.1.0.post4+tuxcare",
      "type": "library",
      "name": "tornado",
      "version": "6.1.0.post4+tuxcare",
      "purl": "pkg:pypi/tornado@6.1.0.post4+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/dulwich@0.25.2.post5+tuxcare",
      "type": "library",
      "name": "dulwich",
      "version": "0.25.2.post5+tuxcare",
      "purl": "pkg:pypi/dulwich@0.25.2.post5+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare",
      "type": "library",
      "name": "pyjwt",
      "version": "2.10.1.post2+tuxcare",
      "purl": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/python-multipart@0.0.6.post5+tuxcare",
      "type": "library",
      "name": "python-multipart",
      "version": "0.0.6.post5+tuxcare",
      "purl": "pkg:pypi/python-multipart@0.0.6.post5+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pypdf@5.9.0.post8+tuxcare",
      "type": "library",
      "name": "pypdf",
      "version": "5.9.0.post8+tuxcare",
      "purl": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/starlette@0.27.0.post5+tuxcare",
      "type": "library",
      "name": "starlette",
      "version": "0.27.0.post5+tuxcare",
      "purl": "pkg:pypi/starlette@0.27.0.post5+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/urllib3@1.25.11.post6+tuxcare",
      "type": "library",
      "name": "urllib3",
      "version": "1.25.11.post6+tuxcare",
      "purl": "pkg:pypi/urllib3@1.25.11.post6+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pypdf@5.9.0.post7+tuxcare",
      "type": "library",
      "name": "pypdf",
      "version": "5.9.0.post7+tuxcare",
      "purl": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/starlette@0.27.0.post4+tuxcare",
      "type": "library",
      "name": "starlette",
      "version": "0.27.0.post4+tuxcare",
      "purl": "pkg:pypi/starlette@0.27.0.post4+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/python-multipart@0.0.6.post4+tuxcare",
      "type": "library",
      "name": "python-multipart",
      "version": "0.0.6.post4+tuxcare",
      "purl": "pkg:pypi/python-multipart@0.0.6.post4+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/gunicorn@20.1.0.post3+tuxcare",
      "type": "library",
      "name": "gunicorn",
      "version": "20.1.0.post3+tuxcare",
      "purl": "pkg:pypi/gunicorn@20.1.0.post3+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/cryptography@44.0.3.post2+tuxcare",
      "type": "library",
      "name": "cryptography",
      "version": "44.0.3.post2+tuxcare",
      "purl": "pkg:pypi/cryptography@44.0.3.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/gunicorn@23.0.0.post1+tuxcare",
      "type": "library",
      "name": "gunicorn",
      "version": "23.0.0.post1+tuxcare",
      "purl": "pkg:pypi/gunicorn@23.0.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/cryptography@46.0.7.post1+tuxcare",
      "type": "library",
      "name": "cryptography",
      "version": "46.0.7.post1+tuxcare",
      "purl": "pkg:pypi/cryptography@46.0.7.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pillow@11.3.0.post3+tuxcare",
      "type": "library",
      "name": "pillow",
      "version": "11.3.0.post3+tuxcare",
      "purl": "pkg:pypi/pillow@11.3.0.post3+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/werkzeug@2.3.8.post2+tuxcare",
      "type": "library",
      "name": "werkzeug",
      "version": "2.3.8.post2+tuxcare",
      "purl": "pkg:pypi/werkzeug@2.3.8.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/urllib3@1.26.20.post4+tuxcare",
      "type": "library",
      "name": "urllib3",
      "version": "1.26.20.post4+tuxcare",
      "purl": "pkg:pypi/urllib3@1.26.20.post4+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/virtualenv@20.39.1.post1+tuxcare",
      "type": "library",
      "name": "virtualenv",
      "version": "20.39.1.post1+tuxcare",
      "purl": "pkg:pypi/virtualenv@20.39.1.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.6.post6+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/tornado@6.1.0.post3+tuxcare",
      "type": "library",
      "name": "tornado",
      "version": "6.1.0.post3+tuxcare",
      "purl": "pkg:pypi/tornado@6.1.0.post3+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pillow@11.2.1.post2+tuxcare",
      "type": "library",
      "name": "pillow",
      "version": "11.2.1.post2+tuxcare",
      "purl": "pkg:pypi/pillow@11.2.1.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pypdf@5.9.0.post6+tuxcare",
      "type": "library",
      "name": "pypdf",
      "version": "5.9.0.post6+tuxcare",
      "purl": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/paramiko@3.0.0.post2+tuxcare",
      "type": "library",
      "name": "paramiko",
      "version": "3.0.0.post2+tuxcare",
      "purl": "pkg:pypi/paramiko@3.0.0.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/langchain-core@0.3.83.post2+tuxcare",
      "type": "library",
      "name": "langchain-core",
      "version": "0.3.83.post2+tuxcare",
      "purl": "pkg:pypi/langchain-core@0.3.83.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/python-multipart@0.0.6.post3+tuxcare",
      "type": "library",
      "name": "python-multipart",
      "version": "0.0.6.post3+tuxcare",
      "purl": "pkg:pypi/python-multipart@0.0.6.post3+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/dulwich@0.25.2.post4+tuxcare",
      "type": "library",
      "name": "dulwich",
      "version": "0.25.2.post4+tuxcare",
      "purl": "pkg:pypi/dulwich@0.25.2.post4+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/requests@2.31.0.post2+tuxcare",
      "type": "library",
      "name": "requests",
      "version": "2.31.0.post2+tuxcare",
      "purl": "pkg:pypi/requests@2.31.0.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pypdf@5.9.0.post5+tuxcare",
      "type": "library",
      "name": "pypdf",
      "version": "5.9.0.post5+tuxcare",
      "purl": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/dulwich@0.25.2.post3+tuxcare",
      "type": "library",
      "name": "dulwich",
      "version": "0.25.2.post3+tuxcare",
      "purl": "pkg:pypi/dulwich@0.25.2.post3+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.5.post9+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/requests@2.30.0.post2+tuxcare",
      "type": "library",
      "name": "requests",
      "version": "2.30.0.post2+tuxcare",
      "purl": "pkg:pypi/requests@2.30.0.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/cryptography@45.0.7.post3+tuxcare",
      "type": "library",
      "name": "cryptography",
      "version": "45.0.7.post3+tuxcare",
      "purl": "pkg:pypi/cryptography@45.0.7.post3+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/numpy@1.21.0.post1+tuxcare",
      "type": "library",
      "name": "numpy",
      "version": "1.21.0.post1+tuxcare",
      "purl": "pkg:pypi/numpy@1.21.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/deepdiff@6.2.3.post2+tuxcare",
      "type": "library",
      "name": "deepdiff",
      "version": "6.2.3.post2+tuxcare",
      "purl": "pkg:pypi/deepdiff@6.2.3.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/flask-cors@4.0.2.post2+tuxcare",
      "type": "library",
      "name": "flask-cors",
      "version": "4.0.2.post2+tuxcare",
      "purl": "pkg:pypi/flask-cors@4.0.2.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/fastmcp@2.14.7.post2+tuxcare",
      "type": "library",
      "name": "fastmcp",
      "version": "2.14.7.post2+tuxcare",
      "purl": "pkg:pypi/fastmcp@2.14.7.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/starlette@0.13.6.post3+tuxcare",
      "type": "library",
      "name": "starlette",
      "version": "0.13.6.post3+tuxcare",
      "purl": "pkg:pypi/starlette@0.13.6.post3+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/starlette@0.27.0.post3+tuxcare",
      "type": "library",
      "name": "starlette",
      "version": "0.27.0.post3+tuxcare",
      "purl": "pkg:pypi/starlette@0.27.0.post3+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/dulwich@0.25.2.post2+tuxcare",
      "type": "library",
      "name": "dulwich",
      "version": "0.25.2.post2+tuxcare",
      "purl": "pkg:pypi/dulwich@0.25.2.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/langgraph-checkpoint@2.1.2.post2+tuxcare",
      "type": "library",
      "name": "langgraph-checkpoint",
      "version": "2.1.2.post2+tuxcare",
      "purl": "pkg:pypi/langgraph-checkpoint@2.1.2.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/mlflow@2.22.4.post4+tuxcare",
      "type": "library",
      "name": "mlflow",
      "version": "2.22.4.post4+tuxcare",
      "purl": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/requests@2.32.3.post2+tuxcare",
      "type": "library",
      "name": "requests",
      "version": "2.32.3.post2+tuxcare",
      "purl": "pkg:pypi/requests@2.32.3.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare",
      "type": "library",
      "name": "mlflow",
      "version": "2.9.1.post4+tuxcare",
      "purl": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/mlflow@2.22.4.post3+tuxcare",
      "type": "library",
      "name": "mlflow",
      "version": "2.22.4.post3+tuxcare",
      "purl": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.1.post10+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.6.post5+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare",
      "type": "library",
      "name": "mlflow",
      "version": "2.9.1.post3+tuxcare",
      "purl": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.5.post8+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.4.post4+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.1.post9+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.4.post3+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.5.post7+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/dulwich@0.25.2.post1+tuxcare",
      "type": "library",
      "name": "dulwich",
      "version": "0.25.2.post1+tuxcare",
      "purl": "pkg:pypi/dulwich@0.25.2.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/apache-airflow-providers-http@4.13.3.post1+tuxcare",
      "type": "library",
      "name": "apache-airflow-providers-http",
      "version": "4.13.3.post1+tuxcare",
      "purl": "pkg:pypi/apache-airflow-providers-http@4.13.3.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/langgraph-checkpoint@2.1.2.post1+tuxcare",
      "type": "library",
      "name": "langgraph-checkpoint",
      "version": "2.1.2.post1+tuxcare",
      "purl": "pkg:pypi/langgraph-checkpoint@2.1.2.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/langchain-text-splitters@0.3.11.post1+tuxcare",
      "type": "library",
      "name": "langchain-text-splitters",
      "version": "0.3.11.post1+tuxcare",
      "purl": "pkg:pypi/langchain-text-splitters@0.3.11.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/lxml@5.4.0.post1+tuxcare",
      "type": "library",
      "name": "lxml",
      "version": "5.4.0.post1+tuxcare",
      "purl": "pkg:pypi/lxml@5.4.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/lxml@4.9.4.post1+tuxcare",
      "type": "library",
      "name": "lxml",
      "version": "4.9.4.post1+tuxcare",
      "purl": "pkg:pypi/lxml@4.9.4.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/transformers@4.57.6.post1+tuxcare",
      "type": "library",
      "name": "transformers",
      "version": "4.57.6.post1+tuxcare",
      "purl": "pkg:pypi/transformers@4.57.6.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pyarrow@12.0.1.post1+tuxcare",
      "type": "library",
      "name": "pyarrow",
      "version": "12.0.1.post1+tuxcare",
      "purl": "pkg:pypi/pyarrow@12.0.1.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pytest@7.4.4.post1+tuxcare",
      "type": "library",
      "name": "pytest",
      "version": "7.4.4.post1+tuxcare",
      "purl": "pkg:pypi/pytest@7.4.4.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pytest@8.4.2.post1+tuxcare",
      "type": "library",
      "name": "pytest",
      "version": "8.4.2.post1+tuxcare",
      "purl": "pkg:pypi/pytest@8.4.2.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/keras@2.15.0.post1+tuxcare",
      "type": "library",
      "name": "keras",
      "version": "2.15.0.post1+tuxcare",
      "purl": "pkg:pypi/keras@2.15.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/fastmcp@2.14.7.post1+tuxcare",
      "type": "library",
      "name": "fastmcp",
      "version": "2.14.7.post1+tuxcare",
      "purl": "pkg:pypi/fastmcp@2.14.7.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare",
      "type": "library",
      "name": "pypdf",
      "version": "5.9.0.post4+tuxcare",
      "purl": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pillow@11.3.0.post2+tuxcare",
      "type": "library",
      "name": "pillow",
      "version": "11.3.0.post2+tuxcare",
      "purl": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/cryptography@45.0.7.post2+tuxcare",
      "type": "library",
      "name": "cryptography",
      "version": "45.0.7.post2+tuxcare",
      "purl": "pkg:pypi/cryptography@45.0.7.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.1.post8+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.5.post6+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.5.post5+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.4.post2+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/urllib3@1.25.11.post5+tuxcare",
      "type": "library",
      "name": "urllib3",
      "version": "1.25.11.post5+tuxcare",
      "purl": "pkg:pypi/urllib3@1.25.11.post5+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.6.post4+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pillow@10.4.0.post2+tuxcare",
      "type": "library",
      "name": "pillow",
      "version": "10.4.0.post2+tuxcare",
      "purl": "pkg:pypi/pillow@10.4.0.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/lightgbm@3.3.5.post1+tuxcare",
      "type": "library",
      "name": "lightgbm",
      "version": "3.3.5.post1+tuxcare",
      "purl": "pkg:pypi/lightgbm@3.3.5.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.6.post3+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/tornado@6.1.0.post2+tuxcare",
      "type": "library",
      "name": "tornado",
      "version": "6.1.0.post2+tuxcare",
      "purl": "pkg:pypi/tornado@6.1.0.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pyopenssl@24.3.0.post2+tuxcare",
      "type": "library",
      "name": "pyopenssl",
      "version": "24.3.0.post2+tuxcare",
      "purl": "pkg:pypi/pyopenssl@24.3.0.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/google-cloud-storage@2.19.0.post2+tuxcare",
      "type": "library",
      "name": "google-cloud-storage",
      "version": "2.19.0.post2+tuxcare",
      "purl": "pkg:pypi/google-cloud-storage@2.19.0.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/langchain-core@0.3.83.post1+tuxcare",
      "type": "library",
      "name": "langchain-core",
      "version": "0.3.83.post1+tuxcare",
      "purl": "pkg:pypi/langchain-core@0.3.83.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pyopenssl@25.3.0.post1+tuxcare",
      "type": "library",
      "name": "pyopenssl",
      "version": "25.3.0.post1+tuxcare",
      "purl": "pkg:pypi/pyopenssl@25.3.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pyopenssl@24.3.0.post1+tuxcare",
      "type": "library",
      "name": "pyopenssl",
      "version": "24.3.0.post1+tuxcare",
      "purl": "pkg:pypi/pyopenssl@24.3.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pyopenssl@23.3.0.post1+tuxcare",
      "type": "library",
      "name": "pyopenssl",
      "version": "23.3.0.post1+tuxcare",
      "purl": "pkg:pypi/pyopenssl@23.3.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare",
      "type": "library",
      "name": "mlflow",
      "version": "2.9.1.post2+tuxcare",
      "purl": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/mlflow@2.22.4.post2+tuxcare",
      "type": "library",
      "name": "mlflow",
      "version": "2.22.4.post2+tuxcare",
      "purl": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare",
      "type": "library",
      "name": "pyjwt",
      "version": "1.7.1.post2+tuxcare",
      "purl": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/setuptools@59.8.0.post1+tuxcare",
      "type": "library",
      "name": "setuptools",
      "version": "59.8.0.post1+tuxcare",
      "purl": "pkg:pypi/setuptools@59.8.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pillow@11.3.0.post1+tuxcare",
      "type": "library",
      "name": "pillow",
      "version": "11.3.0.post1+tuxcare",
      "purl": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pillow@10.4.0.post1+tuxcare",
      "type": "library",
      "name": "pillow",
      "version": "10.4.0.post1+tuxcare",
      "purl": "pkg:pypi/pillow@10.4.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/tornado@5.1.1.post1+tuxcare",
      "type": "library",
      "name": "tornado",
      "version": "5.1.1.post1+tuxcare",
      "purl": "pkg:pypi/tornado@5.1.1.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare",
      "type": "library",
      "name": "mlflow",
      "version": "2.9.1.post1+tuxcare",
      "purl": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/fastmcp@2.14.5.post1+tuxcare",
      "type": "library",
      "name": "fastmcp",
      "version": "2.14.5.post1+tuxcare",
      "purl": "pkg:pypi/fastmcp@2.14.5.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/cryptography@43.0.3.post2+tuxcare",
      "type": "library",
      "name": "cryptography",
      "version": "43.0.3.post2+tuxcare",
      "purl": "pkg:pypi/cryptography@43.0.3.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/cryptography@44.0.3.post1+tuxcare",
      "type": "library",
      "name": "cryptography",
      "version": "44.0.3.post1+tuxcare",
      "purl": "pkg:pypi/cryptography@44.0.3.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/cryptography@41.0.7.post2+tuxcare",
      "type": "library",
      "name": "cryptography",
      "version": "41.0.7.post2+tuxcare",
      "purl": "pkg:pypi/cryptography@41.0.7.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/cryptography@45.0.7.post1+tuxcare",
      "type": "library",
      "name": "cryptography",
      "version": "45.0.7.post1+tuxcare",
      "purl": "pkg:pypi/cryptography@45.0.7.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/cryptography@42.0.8.post2+tuxcare",
      "type": "library",
      "name": "cryptography",
      "version": "42.0.8.post2+tuxcare",
      "purl": "pkg:pypi/cryptography@42.0.8.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.1.post7+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/werkzeug@2.2.3.post4+tuxcare",
      "type": "library",
      "name": "werkzeug",
      "version": "2.2.3.post4+tuxcare",
      "purl": "pkg:pypi/werkzeug@2.2.3.post4+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/werkzeug@1.0.1.post4+tuxcare",
      "type": "library",
      "name": "werkzeug",
      "version": "1.0.1.post4+tuxcare",
      "purl": "pkg:pypi/werkzeug@1.0.1.post4+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.1.post6+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.1.post5+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pip@9.0.post1+tuxcare",
      "type": "library",
      "name": "pip",
      "version": "9.0.post1+tuxcare",
      "purl": "pkg:pypi/pip@9.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/werkzeug@2.3.8.post1+tuxcare",
      "type": "library",
      "name": "werkzeug",
      "version": "2.3.8.post1+tuxcare",
      "purl": "pkg:pypi/werkzeug@2.3.8.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/certifi@2022.12.7.post2+tuxcare",
      "type": "library",
      "name": "certifi",
      "version": "2022.12.7.post2+tuxcare",
      "purl": "pkg:pypi/certifi@2022.12.7.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pillow@9.4.0.post3+tuxcare",
      "type": "library",
      "name": "pillow",
      "version": "9.4.0.post3+tuxcare",
      "purl": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/certifi@2021.10.8.post2+tuxcare",
      "type": "library",
      "name": "certifi",
      "version": "2021.10.8.post2+tuxcare",
      "purl": "pkg:pypi/certifi@2021.10.8.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/werkzeug@2.2.3.post3+tuxcare",
      "type": "library",
      "name": "werkzeug",
      "version": "2.2.3.post3+tuxcare",
      "purl": "pkg:pypi/werkzeug@2.2.3.post3+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/gunicorn@20.1.0.post1+tuxcare",
      "type": "library",
      "name": "gunicorn",
      "version": "20.1.0.post1+tuxcare",
      "purl": "pkg:pypi/gunicorn@20.1.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/gunicorn@20.0.4.post2+tuxcare",
      "type": "library",
      "name": "gunicorn",
      "version": "20.0.4.post2+tuxcare",
      "purl": "pkg:pypi/gunicorn@20.0.4.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/requests@2.32.3.post1+tuxcare",
      "type": "library",
      "name": "requests",
      "version": "2.32.3.post1+tuxcare",
      "purl": "pkg:pypi/requests@2.32.3.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/gunicorn@21.2.0.post2+tuxcare",
      "type": "library",
      "name": "gunicorn",
      "version": "21.2.0.post2+tuxcare",
      "purl": "pkg:pypi/gunicorn@21.2.0.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/anyio@3.7.1.post1+tuxcare",
      "type": "library",
      "name": "anyio",
      "version": "3.7.1.post1+tuxcare",
      "purl": "pkg:pypi/anyio@3.7.1.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/gunicorn@21.2.0.post3+tuxcare",
      "type": "library",
      "name": "gunicorn",
      "version": "21.2.0.post3+tuxcare",
      "purl": "pkg:pypi/gunicorn@21.2.0.post3+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/requests@2.25.1.post1+tuxcare",
      "type": "library",
      "name": "requests",
      "version": "2.25.1.post1+tuxcare",
      "purl": "pkg:pypi/requests@2.25.1.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/requests@2.31.0.post1+tuxcare",
      "type": "library",
      "name": "requests",
      "version": "2.31.0.post1+tuxcare",
      "purl": "pkg:pypi/requests@2.31.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/requests@2.30.0.post1+tuxcare",
      "type": "library",
      "name": "requests",
      "version": "2.30.0.post1+tuxcare",
      "purl": "pkg:pypi/requests@2.30.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/gunicorn@20.1.0.post2+tuxcare",
      "type": "library",
      "name": "gunicorn",
      "version": "20.1.0.post2+tuxcare",
      "purl": "pkg:pypi/gunicorn@20.1.0.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/gunicorn@22.0.0.post1+tuxcare",
      "type": "library",
      "name": "gunicorn",
      "version": "22.0.0.post1+tuxcare",
      "purl": "pkg:pypi/gunicorn@22.0.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/tornado@6.1.0.post1+tuxcare",
      "type": "library",
      "name": "tornado",
      "version": "6.1.0.post1+tuxcare",
      "purl": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pymongo@3.13.0.post1+tuxcare",
      "type": "library",
      "name": "pymongo",
      "version": "3.13.0.post1+tuxcare",
      "purl": "pkg:pypi/pymongo@3.13.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pdfkit@0.6.1.post1+tuxcare",
      "type": "library",
      "name": "pdfkit",
      "version": "0.6.1.post1+tuxcare",
      "purl": "pkg:pypi/pdfkit@0.6.1.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/jaraco-context@5.3.0.post1+tuxcare",
      "type": "library",
      "name": "jaraco-context",
      "version": "5.3.0.post1+tuxcare",
      "purl": "pkg:pypi/jaraco-context@5.3.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pillow@9.5.0.post2+tuxcare",
      "type": "library",
      "name": "pillow",
      "version": "9.5.0.post2+tuxcare",
      "purl": "pkg:pypi/pillow@9.5.0.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/jinja2@2.11.3.post1+tuxcare",
      "type": "library",
      "name": "jinja2",
      "version": "2.11.3.post1+tuxcare",
      "purl": "pkg:pypi/jinja2@2.11.3.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/jinja2@3.0.3.post1+tuxcare",
      "type": "library",
      "name": "jinja2",
      "version": "3.0.3.post1+tuxcare",
      "purl": "pkg:pypi/jinja2@3.0.3.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare",
      "type": "library",
      "name": "pillow",
      "version": "8.4.0.post1+tuxcare",
      "purl": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/jinja2@2.11.3.post2+tuxcare",
      "type": "library",
      "name": "jinja2",
      "version": "2.11.3.post2+tuxcare",
      "purl": "pkg:pypi/jinja2@2.11.3.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/flask@1.1.4.post1+tuxcare",
      "type": "library",
      "name": "flask",
      "version": "1.1.4.post1+tuxcare",
      "purl": "pkg:pypi/flask@1.1.4.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/flask@2.2.1.post1+tuxcare",
      "type": "library",
      "name": "flask",
      "version": "2.2.1.post1+tuxcare",
      "purl": "pkg:pypi/flask@2.2.1.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pillow@9.4.0.post1+tuxcare",
      "type": "library",
      "name": "pillow",
      "version": "9.4.0.post1+tuxcare",
      "purl": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/werkzeug@1.0.1.post1+tuxcare",
      "type": "library",
      "name": "werkzeug",
      "version": "1.0.1.post1+tuxcare",
      "purl": "pkg:pypi/werkzeug@1.0.1.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pillow@9.5.0.post1+tuxcare",
      "type": "library",
      "name": "pillow",
      "version": "9.5.0.post1+tuxcare",
      "purl": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/werkzeug@1.0.1.post2+tuxcare",
      "type": "library",
      "name": "werkzeug",
      "version": "1.0.1.post2+tuxcare",
      "purl": "pkg:pypi/werkzeug@1.0.1.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/gunicorn@20.0.4.post1+tuxcare",
      "type": "library",
      "name": "gunicorn",
      "version": "20.0.4.post1+tuxcare",
      "purl": "pkg:pypi/gunicorn@20.0.4.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/werkzeug@1.0.1.post3+tuxcare",
      "type": "library",
      "name": "werkzeug",
      "version": "1.0.1.post3+tuxcare",
      "purl": "pkg:pypi/werkzeug@1.0.1.post3+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pillow@9.4.0.post2+tuxcare",
      "type": "library",
      "name": "pillow",
      "version": "9.4.0.post2+tuxcare",
      "purl": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/werkzeug@2.2.3.post1+tuxcare",
      "type": "library",
      "name": "werkzeug",
      "version": "2.2.3.post1+tuxcare",
      "purl": "pkg:pypi/werkzeug@2.2.3.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pillow@11.2.1.post1+tuxcare",
      "type": "library",
      "name": "pillow",
      "version": "11.2.1.post1+tuxcare",
      "purl": "pkg:pypi/pillow@11.2.1.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/flask@1.1.2.post1+tuxcare",
      "type": "library",
      "name": "flask",
      "version": "1.1.2.post1+tuxcare",
      "purl": "pkg:pypi/flask@1.1.2.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/flask@0.12.5.post1+tuxcare",
      "type": "library",
      "name": "flask",
      "version": "0.12.5.post1+tuxcare",
      "purl": "pkg:pypi/flask@0.12.5.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/certifi@2022.12.7.post1+tuxcare",
      "type": "library",
      "name": "certifi",
      "version": "2022.12.7.post1+tuxcare",
      "purl": "pkg:pypi/certifi@2022.12.7.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/cryptography@3.4.8.post5+tuxcare",
      "type": "library",
      "name": "cryptography",
      "version": "3.4.8.post5+tuxcare",
      "purl": "pkg:pypi/cryptography@3.4.8.post5+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/cryptography@3.4.8.post4+tuxcare",
      "type": "library",
      "name": "cryptography",
      "version": "3.4.8.post4+tuxcare",
      "purl": "pkg:pypi/cryptography@3.4.8.post4+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/cryptography@3.4.8.post1+tuxcare",
      "type": "library",
      "name": "cryptography",
      "version": "3.4.8.post1+tuxcare",
      "purl": "pkg:pypi/cryptography@3.4.8.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/cryptography@3.4.8.post3+tuxcare",
      "type": "library",
      "name": "cryptography",
      "version": "3.4.8.post3+tuxcare",
      "purl": "pkg:pypi/cryptography@3.4.8.post3+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/certifi@2021.10.8.post1+tuxcare",
      "type": "library",
      "name": "certifi",
      "version": "2021.10.8.post1+tuxcare",
      "purl": "pkg:pypi/certifi@2021.10.8.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/cryptography@3.4.8.post2+tuxcare",
      "type": "library",
      "name": "cryptography",
      "version": "3.4.8.post2+tuxcare",
      "purl": "pkg:pypi/cryptography@3.4.8.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/certifi@2023.7.22.post1+tuxcare",
      "type": "library",
      "name": "certifi",
      "version": "2023.7.22.post1+tuxcare",
      "purl": "pkg:pypi/certifi@2023.7.22.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/py@1.11.0.post1+tuxcare",
      "type": "library",
      "name": "py",
      "version": "1.11.0.post1+tuxcare",
      "purl": "pkg:pypi/py@1.11.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.6.post2+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/mlflow@2.22.4.post1+tuxcare",
      "type": "library",
      "name": "mlflow",
      "version": "2.22.4.post1+tuxcare",
      "purl": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/protobuf@4.25.8.post1+tuxcare",
      "type": "library",
      "name": "protobuf",
      "version": "4.25.8.post1+tuxcare",
      "purl": "pkg:pypi/protobuf@4.25.8.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/urllib3@1.26.20.post3+tuxcare",
      "type": "library",
      "name": "urllib3",
      "version": "1.26.20.post3+tuxcare",
      "purl": "pkg:pypi/urllib3@1.26.20.post3+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/celery@4.4.7.post1+tuxcare",
      "type": "library",
      "name": "celery",
      "version": "4.4.7.post1+tuxcare",
      "purl": "pkg:pypi/celery@4.4.7.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.1.post4+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.6.post1+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/protobuf@3.17.0.post1+tuxcare",
      "type": "library",
      "name": "protobuf",
      "version": "3.17.0.post1+tuxcare",
      "purl": "pkg:pypi/protobuf@3.17.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/python-jose@3.3.0.post2+tuxcare",
      "type": "library",
      "name": "python-jose",
      "version": "3.3.0.post2+tuxcare",
      "purl": "pkg:pypi/python-jose@3.3.0.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/urllib3@1.25.11.post4+tuxcare",
      "type": "library",
      "name": "urllib3",
      "version": "1.25.11.post4+tuxcare",
      "purl": "pkg:pypi/urllib3@1.25.11.post4+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/python-multipart@0.0.6.post2+tuxcare",
      "type": "library",
      "name": "python-multipart",
      "version": "0.0.6.post2+tuxcare",
      "purl": "pkg:pypi/python-multipart@0.0.6.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/urllib3@1.26.4.post4+tuxcare",
      "type": "library",
      "name": "urllib3",
      "version": "1.26.4.post4+tuxcare",
      "purl": "pkg:pypi/urllib3@1.26.4.post4+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.5.post4+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/starlette@0.13.6.post2+tuxcare",
      "type": "library",
      "name": "starlette",
      "version": "0.13.6.post2+tuxcare",
      "purl": "pkg:pypi/starlette@0.13.6.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pymysql@0.10.1.post1+tuxcare",
      "type": "library",
      "name": "pymysql",
      "version": "0.10.1.post1+tuxcare",
      "purl": "pkg:pypi/pymysql@0.10.1.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.1.post3+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/django@3.2.25.post2+tuxcare",
      "type": "library",
      "name": "django",
      "version": "3.2.25.post2+tuxcare",
      "purl": "pkg:pypi/django@3.2.25.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/urllib3@1.26.4.post3+tuxcare",
      "type": "library",
      "name": "urllib3",
      "version": "1.26.4.post3+tuxcare",
      "purl": "pkg:pypi/urllib3@1.26.4.post3+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/urllib3@1.25.11.post3+tuxcare",
      "type": "library",
      "name": "urllib3",
      "version": "1.25.11.post3+tuxcare",
      "purl": "pkg:pypi/urllib3@1.25.11.post3+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.1.post2+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/scikit-learn@1.0.2.post1+tuxcare",
      "type": "library",
      "name": "scikit-learn",
      "version": "1.0.2.post1+tuxcare",
      "purl": "pkg:pypi/scikit-learn@1.0.2.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/urllib3@1.26.20.post2+tuxcare",
      "type": "library",
      "name": "urllib3",
      "version": "1.26.20.post2+tuxcare",
      "purl": "pkg:pypi/urllib3@1.26.20.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.5.post3+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/h11@0.9.0.post1+tuxcare",
      "type": "library",
      "name": "h11",
      "version": "0.9.0.post1+tuxcare",
      "purl": "pkg:pypi/h11@0.9.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/urllib3@2.0.7.post1+tuxcare",
      "type": "library",
      "name": "urllib3",
      "version": "2.0.7.post1+tuxcare",
      "purl": "pkg:pypi/urllib3@2.0.7.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/numpy@1.16.0.post2+tuxcare",
      "type": "library",
      "name": "numpy",
      "version": "1.16.0.post2+tuxcare",
      "purl": "pkg:pypi/numpy@1.16.0.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare",
      "type": "library",
      "name": "pypdf",
      "version": "5.9.0.post3+tuxcare",
      "purl": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pyyaml@3.13.post1+tuxcare",
      "type": "library",
      "name": "pyyaml",
      "version": "3.13.post1+tuxcare",
      "purl": "pkg:pypi/pyyaml@3.13.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/sentence-transformers@2.7.0.post1+tuxcare",
      "type": "library",
      "name": "sentence-transformers",
      "version": "2.7.0.post1+tuxcare",
      "purl": "pkg:pypi/sentence-transformers@2.7.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/mysql-connector-python@8.4.0.post1+tuxcare",
      "type": "library",
      "name": "mysql-connector-python",
      "version": "8.4.0.post1+tuxcare",
      "purl": "pkg:pypi/mysql-connector-python@8.4.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pyjwt@1.7.1.post1+tuxcare",
      "type": "library",
      "name": "pyjwt",
      "version": "1.7.1.post1+tuxcare",
      "purl": "pkg:pypi/pyjwt@1.7.1.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare",
      "type": "library",
      "name": "pypdf",
      "version": "5.9.0.post2+tuxcare",
      "purl": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/starlette@0.13.6.post1+tuxcare",
      "type": "library",
      "name": "starlette",
      "version": "0.13.6.post1+tuxcare",
      "purl": "pkg:pypi/starlette@0.13.6.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/websockets@8.1.post1+tuxcare",
      "type": "library",
      "name": "websockets",
      "version": "8.1.post1+tuxcare",
      "purl": "pkg:pypi/websockets@8.1.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/starlette@0.27.0.post2+tuxcare",
      "type": "library",
      "name": "starlette",
      "version": "0.27.0.post2+tuxcare",
      "purl": "pkg:pypi/starlette@0.27.0.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/urllib3@1.26.4.post2+tuxcare",
      "type": "library",
      "name": "urllib3",
      "version": "1.26.4.post2+tuxcare",
      "purl": "pkg:pypi/urllib3@1.26.4.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/idna@2.10.post1+tuxcare",
      "type": "library",
      "name": "idna",
      "version": "2.10.post1+tuxcare",
      "purl": "pkg:pypi/idna@2.10.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/statsmodels@0.14.5.post1+tuxcare",
      "type": "library",
      "name": "statsmodels",
      "version": "0.14.5.post1+tuxcare",
      "purl": "pkg:pypi/statsmodels@0.14.5.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/torch@1.13.1.post2+tuxcare",
      "type": "library",
      "name": "torch",
      "version": "1.13.1.post2+tuxcare",
      "purl": "pkg:pypi/torch@1.13.1.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pyyaml@5.3.1.post1+tuxcare",
      "type": "library",
      "name": "pyyaml",
      "version": "5.3.1.post1+tuxcare",
      "purl": "pkg:pypi/pyyaml@5.3.1.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/twisted@20.3.0.post4+tuxcare",
      "type": "library",
      "name": "twisted",
      "version": "20.3.0.post4+tuxcare",
      "purl": "pkg:pypi/twisted@20.3.0.post4+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/django@5.1.post3+tuxcare",
      "type": "library",
      "name": "django",
      "version": "5.1.post3+tuxcare",
      "purl": "pkg:pypi/django@5.1.post3+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/protobuf@4.24.3.post1+tuxcare",
      "type": "library",
      "name": "protobuf",
      "version": "4.24.3.post1+tuxcare",
      "purl": "pkg:pypi/protobuf@4.24.3.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/django@4.2.post1+tuxcare",
      "type": "library",
      "name": "django",
      "version": "4.2.post1+tuxcare",
      "purl": "pkg:pypi/django@4.2.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/django@4.0.post6+tuxcare",
      "type": "library",
      "name": "django",
      "version": "4.0.post6+tuxcare",
      "purl": "pkg:pypi/django@4.0.post6+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/django@5.1.post2+tuxcare",
      "type": "library",
      "name": "django",
      "version": "5.1.post2+tuxcare",
      "purl": "pkg:pypi/django@5.1.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/django@4.0.post5+tuxcare",
      "type": "library",
      "name": "django",
      "version": "4.0.post5+tuxcare",
      "purl": "pkg:pypi/django@4.0.post5+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/urllib3@1.26.4.post1+tuxcare",
      "type": "library",
      "name": "urllib3",
      "version": "1.26.4.post1+tuxcare",
      "purl": "pkg:pypi/urllib3@1.26.4.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/torch@1.13.1.post1+tuxcare",
      "type": "library",
      "name": "torch",
      "version": "1.13.1.post1+tuxcare",
      "purl": "pkg:pypi/torch@1.13.1.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/urllib3@1.25.11.post2+tuxcare",
      "type": "library",
      "name": "urllib3",
      "version": "1.25.11.post2+tuxcare",
      "purl": "pkg:pypi/urllib3@1.25.11.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/numpy@1.15.4.post2+tuxcare",
      "type": "library",
      "name": "numpy",
      "version": "1.15.4.post2+tuxcare",
      "purl": "pkg:pypi/numpy@1.15.4.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/setuptools@68.0.0.post1+tuxcare",
      "type": "library",
      "name": "setuptools",
      "version": "68.0.0.post1+tuxcare",
      "purl": "pkg:pypi/setuptools@68.0.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/setuptools@75.0.0.post1+tuxcare",
      "type": "library",
      "name": "setuptools",
      "version": "75.0.0.post1+tuxcare",
      "purl": "pkg:pypi/setuptools@75.0.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/setuptools@70.3.0.post1+tuxcare",
      "type": "library",
      "name": "setuptools",
      "version": "70.3.0.post1+tuxcare",
      "purl": "pkg:pypi/setuptools@70.3.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/cryptography@41.0.7.post1+tuxcare",
      "type": "library",
      "name": "cryptography",
      "version": "41.0.7.post1+tuxcare",
      "purl": "pkg:pypi/cryptography@41.0.7.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pypdf@5.9.0.post1+tuxcare",
      "type": "library",
      "name": "pypdf",
      "version": "5.9.0.post1+tuxcare",
      "purl": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/django@3.2.25.post1+tuxcare",
      "type": "library",
      "name": "django",
      "version": "3.2.25.post1+tuxcare",
      "purl": "pkg:pypi/django@3.2.25.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/flask-cors@4.0.2.post1+tuxcare",
      "type": "library",
      "name": "flask-cors",
      "version": "4.0.2.post1+tuxcare",
      "purl": "pkg:pypi/flask-cors@4.0.2.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/urllib3@1.26.20.post1+tuxcare",
      "type": "library",
      "name": "urllib3",
      "version": "1.26.20.post1+tuxcare",
      "purl": "pkg:pypi/urllib3@1.26.20.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/django@5.0.post5+tuxcare",
      "type": "library",
      "name": "django",
      "version": "5.0.post5+tuxcare",
      "purl": "pkg:pypi/django@5.0.post5+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/cryptography@42.0.0.post1+tuxcare",
      "type": "library",
      "name": "cryptography",
      "version": "42.0.0.post1+tuxcare",
      "purl": "pkg:pypi/cryptography@42.0.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/gitpython@3.1.31.post1+tuxcare",
      "type": "library",
      "name": "gitpython",
      "version": "3.1.31.post1+tuxcare",
      "purl": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/python-jose@3.3.0.post1+tuxcare",
      "type": "library",
      "name": "python-jose",
      "version": "3.3.0.post1+tuxcare",
      "purl": "pkg:pypi/python-jose@3.3.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/orjson@3.8.5.post1+tuxcare",
      "type": "library",
      "name": "orjson",
      "version": "3.8.5.post1+tuxcare",
      "purl": "pkg:pypi/orjson@3.8.5.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/redis@4.5.1.post1+tuxcare",
      "type": "library",
      "name": "redis",
      "version": "4.5.1.post1+tuxcare",
      "purl": "pkg:pypi/redis@4.5.1.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/idna@3.6.post1+tuxcare",
      "type": "library",
      "name": "idna",
      "version": "3.6.post1+tuxcare",
      "purl": "pkg:pypi/idna@3.6.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/tqdm@4.66.1.post1+tuxcare",
      "type": "library",
      "name": "tqdm",
      "version": "4.66.1.post1+tuxcare",
      "purl": "pkg:pypi/tqdm@4.66.1.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/python-multipart@0.0.6.post1+tuxcare",
      "type": "library",
      "name": "python-multipart",
      "version": "0.0.6.post1+tuxcare",
      "purl": "pkg:pypi/python-multipart@0.0.6.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/paramiko@3.0.0.post1+tuxcare",
      "type": "library",
      "name": "paramiko",
      "version": "3.0.0.post1+tuxcare",
      "purl": "pkg:pypi/paramiko@3.0.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/piexif@1.1.3.post1+tuxcare",
      "type": "library",
      "name": "piexif",
      "version": "1.1.3.post1+tuxcare",
      "purl": "pkg:pypi/piexif@1.1.3.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/deepdiff@6.2.3.post1+tuxcare",
      "type": "library",
      "name": "deepdiff",
      "version": "6.2.3.post1+tuxcare",
      "purl": "pkg:pypi/deepdiff@6.2.3.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pydantic@v1.10.5.post1+tuxcare",
      "type": "library",
      "name": "pydantic",
      "version": "v1.10.5.post1+tuxcare",
      "purl": "pkg:pypi/pydantic@v1.10.5.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/django@4.0.post4+tuxcare",
      "type": "library",
      "name": "django",
      "version": "4.0.post4+tuxcare",
      "purl": "pkg:pypi/django@4.0.post4+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/dnspython@2.3.0.post1+tuxcare",
      "type": "library",
      "name": "dnspython",
      "version": "2.3.0.post1+tuxcare",
      "purl": "pkg:pypi/dnspython@2.3.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/django@5.0.post4+tuxcare",
      "type": "library",
      "name": "django",
      "version": "5.0.post4+tuxcare",
      "purl": "pkg:pypi/django@5.0.post4+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/django@5.0.post3+tuxcare",
      "type": "library",
      "name": "django",
      "version": "5.0.post3+tuxcare",
      "purl": "pkg:pypi/django@5.0.post3+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pandas@2.2.0.post1+tuxcare",
      "type": "library",
      "name": "pandas",
      "version": "2.2.0.post1+tuxcare",
      "purl": "pkg:pypi/pandas@2.2.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/django@5.0.post2+tuxcare",
      "type": "library",
      "name": "django",
      "version": "5.0.post2+tuxcare",
      "purl": "pkg:pypi/django@5.0.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pyjwt@2.10.1.post1+tuxcare",
      "type": "library",
      "name": "pyjwt",
      "version": "2.10.1.post1+tuxcare",
      "purl": "pkg:pypi/pyjwt@2.10.1.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/django@5.0.post1+tuxcare",
      "type": "library",
      "name": "django",
      "version": "5.0.post1+tuxcare",
      "purl": "pkg:pypi/django@5.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/starlette@0.27.0.post1+tuxcare",
      "type": "library",
      "name": "starlette",
      "version": "0.27.0.post1+tuxcare",
      "purl": "pkg:pypi/starlette@0.27.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/django@4.0.post3+tuxcare",
      "type": "library",
      "name": "django",
      "version": "4.0.post3+tuxcare",
      "purl": "pkg:pypi/django@4.0.post3+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/django@5.0.1.post3+tuxcare",
      "type": "library",
      "name": "django",
      "version": "5.0.1.post3+tuxcare",
      "purl": "pkg:pypi/django@5.0.1.post3+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare",
      "type": "library",
      "name": "pyjwt",
      "version": "2.3.0.post1+tuxcare",
      "purl": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pyjwt@2.8.0.post1+tuxcare",
      "type": "library",
      "name": "pyjwt",
      "version": "2.8.0.post1+tuxcare",
      "purl": "pkg:pypi/pyjwt@2.8.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/django@5.0.1.post2+tuxcare",
      "type": "library",
      "name": "django",
      "version": "5.0.1.post2+tuxcare",
      "purl": "pkg:pypi/django@5.0.1.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/celery@v5.1.2.post1+tuxcare",
      "type": "library",
      "name": "celery",
      "version": "v5.1.2.post1+tuxcare",
      "purl": "pkg:pypi/celery@v5.1.2.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/django@5.1.post1+tuxcare",
      "type": "library",
      "name": "django",
      "version": "5.1.post1+tuxcare",
      "purl": "pkg:pypi/django@5.1.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/django@4.0.post2+tuxcare",
      "type": "library",
      "name": "django",
      "version": "4.0.post2+tuxcare",
      "purl": "pkg:pypi/django@4.0.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.1.post1+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/pandas@2.2.2.post1+tuxcare",
      "type": "library",
      "name": "pandas",
      "version": "2.2.2.post1+tuxcare",
      "purl": "pkg:pypi/pandas@2.2.2.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/django@4.0.post1+tuxcare",
      "type": "library",
      "name": "django",
      "version": "4.0.post1+tuxcare",
      "purl": "pkg:pypi/django@4.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/fastapi@0.104.1.post1+tuxcare",
      "type": "library",
      "name": "fastapi",
      "version": "0.104.1.post1+tuxcare",
      "purl": "pkg:pypi/fastapi@0.104.1.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/future@1.0.0.post1+tuxcare",
      "type": "library",
      "name": "future",
      "version": "1.0.0.post1+tuxcare",
      "purl": "pkg:pypi/future@1.0.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/uvicorn@0.11.6.post1+tuxcare",
      "type": "library",
      "name": "uvicorn",
      "version": "0.11.6.post1+tuxcare",
      "purl": "pkg:pypi/uvicorn@0.11.6.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/numpy@1.15.4.post1+tuxcare",
      "type": "library",
      "name": "numpy",
      "version": "1.15.4.post1+tuxcare",
      "purl": "pkg:pypi/numpy@1.15.4.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/fastapi@0.63.0.post2+tuxcare",
      "type": "library",
      "name": "fastapi",
      "version": "0.63.0.post2+tuxcare",
      "purl": "pkg:pypi/fastapi@0.63.0.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/fastapi@0.63.0.post1+tuxcare",
      "type": "library",
      "name": "fastapi",
      "version": "0.63.0.post1+tuxcare",
      "purl": "pkg:pypi/fastapi@0.63.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/django@5.1.4.post1+tuxcare",
      "type": "library",
      "name": "django",
      "version": "5.1.4.post1+tuxcare",
      "purl": "pkg:pypi/django@5.1.4.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/django@5.1.9.post1+tuxcare",
      "type": "library",
      "name": "django",
      "version": "5.1.9.post1+tuxcare",
      "purl": "pkg:pypi/django@5.1.9.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/django@5.0.2.post1+tuxcare",
      "type": "library",
      "name": "django",
      "version": "5.0.2.post1+tuxcare",
      "purl": "pkg:pypi/django@5.0.2.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/numpy@1.16.0.post1+tuxcare",
      "type": "library",
      "name": "numpy",
      "version": "1.16.0.post1+tuxcare",
      "purl": "pkg:pypi/numpy@1.16.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.5.post2+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.4.post1+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/django@5.0.1.post1+tuxcare",
      "type": "library",
      "name": "django",
      "version": "5.0.1.post1+tuxcare",
      "purl": "pkg:pypi/django@5.0.1.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/statsmodels@0.14.4.post1+tuxcare",
      "type": "library",
      "name": "statsmodels",
      "version": "0.14.4.post1+tuxcare",
      "purl": "pkg:pypi/statsmodels@0.14.4.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.5.post1+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/httpx@0.22.0.post1+tuxcare",
      "type": "library",
      "name": "httpx",
      "version": "0.22.0.post1+tuxcare",
      "purl": "pkg:pypi/httpx@0.22.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/setuptools@75.8.0.post1+tuxcare",
      "type": "library",
      "name": "setuptools",
      "version": "75.8.0.post1+tuxcare",
      "purl": "pkg:pypi/setuptools@75.8.0.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/cryptography@43.0.1.post1+tuxcare",
      "type": "library",
      "name": "cryptography",
      "version": "43.0.1.post1+tuxcare",
      "purl": "pkg:pypi/cryptography@43.0.1.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/idna@2.8.post1+tuxcare",
      "type": "library",
      "name": "idna",
      "version": "2.8.post1+tuxcare",
      "purl": "pkg:pypi/idna@2.8.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/idna@2.1.post1+tuxcare",
      "type": "library",
      "name": "idna",
      "version": "2.1.post1+tuxcare",
      "purl": "pkg:pypi/idna@2.1.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/setuptools@65.5.1.post1+tuxcare",
      "type": "library",
      "name": "setuptools",
      "version": "65.5.1.post1+tuxcare",
      "purl": "pkg:pypi/setuptools@65.5.1.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/waitress@2.1.2.post2+tuxcare",
      "type": "library",
      "name": "waitress",
      "version": "2.1.2.post2+tuxcare",
      "purl": "pkg:pypi/waitress@2.1.2.post2+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/waitress@2.1.2.post1+tuxcare",
      "type": "library",
      "name": "waitress",
      "version": "2.1.2.post1+tuxcare",
      "purl": "pkg:pypi/waitress@2.1.2.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/cryptography@43.0.3.post1+tuxcare",
      "type": "library",
      "name": "cryptography",
      "version": "43.0.3.post1+tuxcare",
      "purl": "pkg:pypi/cryptography@43.0.3.post1+tuxcare"
    },
    {
      "bom-ref": "pkg:pypi/cryptography@42.0.8.post1+tuxcare",
      "type": "library",
      "name": "cryptography",
      "version": "42.0.8.post1+tuxcare",
      "purl": "pkg:pypi/cryptography@42.0.8.post1+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:475f72ec-38d6-5dd0-9159-e82039b280d7",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-49081 affects version 3.8.6.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9d3074f-7be8-556f-8e86-2db35eaa7b1e",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49082 is fixed in version 3.8.6.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8e95039-bcd9-5e5e-acfb-6f0af5308aa8",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23334 affects version 3.8.6.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:144af424-c9a3-594f-8bae-76cf1244bfc5",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23829 affects version 3.8.6.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ecd924da-8ae5-54ab-902e-92fd6dd5d9ab",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27306 affects version 3.8.6.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b015e001-f2ab-5ca8-a54f-0ef8f580e18c",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-30251 is fixed in version 3.8.6.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7cb0513c-08d4-556a-a84c-abdb3d9ff816",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52304 affects version 3.8.6.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fddc2254-7705-5e07-9bc7-e4f9bb79b081",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-53643 affects version 3.8.6.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b777980-487f-52cc-8f5e-9420b793f804",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.6.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1093b9ca-58f2-547a-b4ef-908875ef1b52",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.6.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87f73ace-5977-5242-bb88-b3f82ce273f6",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.6.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3523c9f1-47b0-52f4-b09f-838e81bd3c89",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.6.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e057fd1f-02c5-5804-b3b0-2af12af8571b",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.6.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39a5ad25-12d7-5c3e-ab44-93365f8f2a8e",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.6.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7662d144-f638-503f-99a2-97a3f7974fe2",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.6.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:475854c5-f4d4-5991-9357-d8eba475f457",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.6.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71fd7f23-8d7a-5b75-995b-e5836d0d987b",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22815 is fixed in version 3.8.6.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0488abf1-b838-59fc-9881-5e1bdcc480cd",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34513 is fixed in version 3.8.6.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86e501f5-0e74-58eb-bac0-f6db666232af",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34514 is fixed in version 3.8.6.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d5c1062-6327-5f62-8489-6197c742dba3",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.6.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b940e491-f417-5e50-abbe-8eee1cc6e628",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34516 is fixed in version 3.8.6.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6009b5db-e3b5-5c99-8bcf-27e6581dd0da",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34517 is fixed in version 3.8.6.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51d7920b-0355-5144-9236-2be9206ab061",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34518 is fixed in version 3.8.6.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fc2d593-1d97-572c-a60a-39c9152ca9ff",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34519 is fixed in version 3.8.6.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3efa2f1-c355-5e9c-9948-98bd5413f6ee",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34520 is fixed in version 3.8.6.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ee746b9-a428-5575-8121-c47dc39121bc",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34525 is fixed in version 3.8.6.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ed34eb4-6356-59ea-a130-6d2170b691e2",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.6.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f24e5d75-dcba-5701-8d6e-b0820e19cb48",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47265 is fixed in version 3.8.6.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67785b80-cae7-5e59-baa8-11e1ecfe5033",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50269 is fixed in version 3.8.6.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a74268c5-b8c1-5f65-a743-c6444e06d4df",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54273 is fixed in version 3.8.6.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c331335-e413-5fe5-8fac-011d64af7dc7",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54274 is fixed in version 3.8.6.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0d1abd9-181c-56c6-9ec2-d5fa1de251f7",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.6.post7+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0215b1a-bcb5-547f-a8c4-a5ae0656e0df",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.6.post7+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9860db0e-4935-54db-9ec6-71be876f4502",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54277 is fixed in version 3.8.6.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2815077-c6e7-5720-91c9-d2de48dfa9ae",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54278 is fixed in version 3.8.6.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89722a04-00b5-5934-9549-fa5457fd3ca3",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54279 is fixed in version 3.8.6.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73185fd9-ab04-52cd-8b99-8944ab2a2bd8",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.6.post7+tuxcare of aiohttp. Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf2cc901-ad7e-517a-96c6-55c5bf9d5619",
      "id": "CVE-2023-37276",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-37276 is fixed in version 3.8.4.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:906780f2-0ae2-5ad9-8d2f-f656285587c6",
      "id": "CVE-2023-47627",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-47627 affects version 3.8.4.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5fa28ed-5e4a-53b8-8a43-53d04ecb8678",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-49081 affects version 3.8.4.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72ae1821-5b03-5fae-8662-c27859f591c7",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-49082 affects version 3.8.4.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54bba7ba-7559-5c20-a6fc-dd8cc13f049b",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23334 affects version 3.8.4.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2ac3ad3-85ac-58c1-835d-aca9fab1663d",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23829 affects version 3.8.4.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:929abfb3-fb82-5fdd-8928-ffe4325323c3",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27306 affects version 3.8.4.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a512864f-daea-5e0f-a7c9-34518f6b2660",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-30251 affects version 3.8.4.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17e2aa5f-8f37-5d5d-9754-91a07ca3358a",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52304 affects version 3.8.4.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4944723a-8b37-55c8-a9de-8b5046ff72b9",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-53643 affects version 3.8.4.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e67e9788-55b5-5741-bdba-d500afd29e6f",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.4.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b25e67c0-846f-5d0c-8ad7-0dbb2dec2d9c",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.4.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ccabf2a5-733d-540f-a6db-336afb40a072",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.4.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c8b85a8-716b-52b4-94db-cbd18622bd59",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.4.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4ecc0c7-ba40-5856-bb63-81e0cc214077",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.4.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d81c4eb7-61c3-5234-bb1d-7298098d9672",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.4.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46dc506b-b923-53ed-8001-4edff235f9dc",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.4.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f48b7a00-195e-5f06-b901-c40d65fc90fa",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.4.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bcf9470-5f9c-520e-bd9e-c77ceb410318",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22815 is fixed in version 3.8.4.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:daf001df-c275-53bb-a31e-0dd6cba8cc35",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34513 is fixed in version 3.8.4.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5bf7008d-1933-5620-a4ab-d29856d92fbc",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34514 is fixed in version 3.8.4.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1b48885-a31f-56fc-a723-2d3124c23ffc",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34515 is fixed in version 3.8.4.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68bc40f0-5d39-5aa4-a656-be5bfb33c438",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34516 is fixed in version 3.8.4.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:483d0626-eac1-57ba-88ca-3176459279a2",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34517 is fixed in version 3.8.4.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3012b766-45b9-5ea7-bacc-4c84e63b2c5f",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34518 is fixed in version 3.8.4.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0390a4a1-20aa-5d4c-a971-a0a554dd8d9c",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34519 is fixed in version 3.8.4.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e33cad2-bf0f-5d64-aa34-d6c8ee348c11",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34520 is fixed in version 3.8.4.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d193fb20-0799-5447-98e3-437b099ee7bb",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34525 affects version 3.8.4.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63b6bf39-3c37-5efb-b9b4-16879526ef5b",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.4.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb86b943-a023-5abc-952c-0475587a3514",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47265 is fixed in version 3.8.4.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a882eb0f-e74d-5f43-bdf6-12a0f3a7cd3c",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.4.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:796ba48e-d9a5-5bc9-a881-da9a766466c1",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.4.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93546fa2-6eed-5e51-b2bd-568f6c8e0587",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.4.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4aba194b-d900-5d20-b831-a1d0033ecf85",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.4.post5+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.4.post4+tuxcare. The vulnerability requires the server_hostname parameter feature, which was not added until version 3.9.0+ (August 2023), six months after version 3.8.4 was released (February 2023). The target version cannot receive the malicious input described in the CVE."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0814f72e-a8e6-5a26-88cc-a9f7ad720a96",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.4.post5+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.4.post4+tuxcare) does not contain the DigestAuthMiddleware component. This feature was introduced in aiohttp version 3.12, which postdates the target version. The vulnerability cannot manifest because the affected code does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f9010a4-24eb-5112-9fd4-aa21dcf4a62f",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.4.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a539ee7-898a-5b04-af64-735b1dbe7d1c",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.4.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c385b1b8-d155-5079-b3c0-ed91451ff9e6",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.4.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d24363d8-f13f-567c-ae55-1097960edbfd",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54280 is fixed in version 3.8.4.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbb3fae8-1261-5ef8-a315-8da76f36cefc",
      "id": "GHSA-pjjw-qhg8-p2p9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.4.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6984609-6725-5e9f-81a0-10d9648e83e2",
      "id": "CVE-2022-33124",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-33124 is a false positive for aiohttp 3.8.1.post11+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05aab2de-82c1-5998-a3bb-e6d60d65a99c",
      "id": "CVE-2023-37276",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-37276 is fixed in version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40b1368e-fedc-5248-af54-8c119a73edcc",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49081 is fixed in version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3053030-7e54-5143-bae2-ac0b9df1ffc8",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49082 is fixed in version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c8880c2-0abd-5b05-8bac-b334f24be125",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23334 is fixed in version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55c21fdf-0778-58b4-815e-91d9e26d3c1f",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23829 is fixed in version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98cb501d-da1a-5b6b-8bb6-e23e2661b20d",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-27306 is fixed in version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23a869d1-5214-5a5f-ae5d-cd0b83dd388b",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-30251 is fixed in version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c4175d0-ee0b-5ef1-8e7e-df3bc84e8901",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52304 is fixed in version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:879d63c7-6255-5573-879d-1cd5547d549e",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53643 is fixed in version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9e2e8e9-98d0-53fa-b323-f7d7584877c6",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55faca34-11fa-5f39-a88a-4ae4da347d71",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5166930-1eec-5e00-9c8a-e6ba7090280e",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82f90e01-ff3a-55e7-b208-0a49344333e4",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24b12dd4-13ff-5df5-af50-0cdb95ab4a36",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f6188ac-d32d-5b4d-9fc3-e593ee8d247e",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b82cb01-29d2-5a41-ba2a-99e3d7a8d33c",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58d34624-9aed-5a84-84cb-fd6948f3b2c1",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c73f428e-f1bf-51a1-b99d-a2344171ad0b",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22815 is fixed in version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ae30683-00d1-5281-a817-784fa6b12d20",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34513 is fixed in version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2385b82-4f10-548b-a2ad-77ce503c3bce",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34514 is fixed in version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:887b2751-3142-55c9-89e4-10d1c91068c9",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1fcb1a62-0e5f-532c-8145-848431ef9f5f",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34516 is fixed in version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2599dfa2-874b-5d60-a0c4-ac07fa3197e9",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34517 is fixed in version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4a0e803-668a-5860-9014-075646b27b33",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34518 is fixed in version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4bcfd870-cd5c-5e97-b719-22f35c7b556e",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34519 is fixed in version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f3c70f8-db5a-50fe-bf44-bd1c6db6ac4b",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34520 is fixed in version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57631646-ebd4-54a8-9a6b-e282e14f4dfe",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34525 is fixed in version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77a73ec8-6546-5596-ae84-898ee20a9de4",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97502266-f289-5435-b2f1-ac5ce6e3a07c",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd2d93d9-f572-54a8-bf7a-5e4e146bb41b",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa65fdfb-a5eb-5de2-8e1f-12b0734632c7",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0467e054-1ef3-53e4-a6e3-54bfc3729a9d",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:faf18582-cc45-5e98-87ae-c5013bcc1d81",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.1.post11+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a01b97c-97b8-5979-8b9f-6dc0c3a62795",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.1.post11+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7932ceef-4d7c-5a58-901c-f83e2caa0fd1",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e2bfcb5-5cae-5e88-8b7b-3ab9a28e26b8",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbd06466-7356-5a2d-8fe4-8a1458331339",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f38711aa-b3b4-5903-be1b-251bbe42fb22",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.1.post11+tuxcare of aiohttp. CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe"
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4fc954c-7b04-58dd-91e8-8cedd4211cac",
      "id": "GHSA-pjjw-qhg8-p2p9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-pjjw-qhg8-p2p9 is fixed in version 3.8.1.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:442d4717-5541-5ac3-ac10-c59508ce4f2c",
      "id": "CVE-2023-28370",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28370 is fixed in version 6.1.0.post5+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f94bff3b-8143-5065-8b6b-1942155f4142",
      "id": "CVE-2024-52804",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52804 is fixed in version 6.1.0.post5+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a586169a-27b9-51b5-a9f3-3c067e84ff1d",
      "id": "CVE-2025-47287",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-47287 is fixed in version 6.1.0.post5+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbdda741-cdb0-567e-9d29-84a1ad7f8b40",
      "id": "CVE-2025-67724",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-67724 is fixed in version 6.1.0.post5+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56b55af7-497b-52d0-963c-4a4fb5652167",
      "id": "CVE-2025-67725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-67725 is fixed in version 6.1.0.post5+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7272cff6-284c-5e2b-a952-fe01150aa1a7",
      "id": "CVE-2026-31958",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-31958 is fixed in version 6.1.0.post5+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9aa9ed63-6585-5c56-ae8e-ff50771d1fc0",
      "id": "CVE-2026-35536",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-35536 is fixed in version 6.1.0.post5+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93201e0e-fc4e-57b2-abde-394118f6df5b",
      "id": "CVE-2026-49853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49853 is fixed in version 6.1.0.post5+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0eef37d9-d4d4-55de-b224-00c0746e109e",
      "id": "CVE-2026-49854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49854 is fixed in version 6.1.0.post5+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4062f5d3-561f-5179-8cb2-03d18c04a15b",
      "id": "CVE-2026-49855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49855 is fixed in version 6.1.0.post5+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6572658-1026-519b-be11-3301e8f1795f",
      "id": "GHSA-753j-mpmx-qq6g",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-753j-mpmx-qq6g is fixed in version 6.1.0.post5+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e019e305-4221-5dca-b02b-317339bf1127",
      "id": "GHSA-78cv-mqj4-43f7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-78cv-mqj4-43f7 is fixed in version 6.1.0.post5+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:682a4cba-4a54-567f-a964-aa9f0f8e40b4",
      "id": "GHSA-pw6j-qg29-8w7f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-pw6j-qg29-8w7f is fixed in version 6.1.0.post5+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09b7690c-6174-531b-96f5-37970d583984",
      "id": "GHSA-qppv-j76h-2rpx",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-qppv-j76h-2rpx is fixed in version 6.1.0.post5+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4118a3af-ea8a-5b1e-8120-de908fb4b2d8",
      "id": "GHSA-w235-7p84-xx57",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-w235-7p84-xx57 is fixed in version 6.1.0.post5+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99e6ca18-10dc-536c-808d-ccb3df96690a",
      "id": "CVE-2021-45115",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-45115 is fixed in version 4.0.post7+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f6d1a60-4133-5014-8080-e3a6602654ae",
      "id": "CVE-2021-45116",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-45116 is fixed in version 4.0.post7+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fdac9c21-aa2e-56e5-be69-e26ca36799a5",
      "id": "CVE-2021-45452",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-45452 is fixed in version 4.0.post7+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd4d70c7-40a9-5aba-98f7-8265c288fe3b",
      "id": "CVE-2022-22818",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22818 is fixed in version 4.0.post7+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b4e3768-a181-5d54-a81a-48cc7905f83f",
      "id": "CVE-2022-23833",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23833 is fixed in version 4.0.post7+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af616f1c-3dab-5926-96ea-74f41b8547a9",
      "id": "CVE-2022-28346",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-28346 is fixed in version 4.0.post7+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de8f5d88-e5d2-581a-836b-7973780839fd",
      "id": "CVE-2022-28347",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-28347 is fixed in version 4.0.post7+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d929f4a0-1ef4-521a-9bdd-080e1687d52d",
      "id": "CVE-2022-34265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-34265 is fixed in version 4.0.post7+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53124069-40ae-516e-afd8-816864b50fa3",
      "id": "CVE-2022-36359",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-36359 is fixed in version 4.0.post7+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b30ffbe-05a5-5fe5-a010-1374dc8c7644",
      "id": "CVE-2022-41323",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41323 is fixed in version 4.0.post7+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4dbb9c26-6e6c-5509-b395-7489ba6aff95",
      "id": "CVE-2023-23969",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-23969 is fixed in version 4.0.post7+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ce1becd-ad4b-525b-89e4-46e49d70e9db",
      "id": "CVE-2023-24580",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-24580 is fixed in version 4.0.post7+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fdc7adb7-650c-598b-a52d-ee345366611e",
      "id": "CVE-2023-31047",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-31047 affects version 4.0.post7+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26596018-5c11-5d38-b27d-d0f684a25647",
      "id": "CVE-2023-36053",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36053 affects version 4.0.post7+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ba521a0-5a1e-5eb7-9598-4354b215c333",
      "id": "CVE-2023-43665",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-43665 is fixed in version 4.0.post7+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40f04ae8-bd4f-513c-8021-8df2e86c6581",
      "id": "CVE-2023-46695",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46695 affects version 4.0.post7+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f53824a3-970d-50ef-8dda-1aaecaaf3a84",
      "id": "CVE-2024-45231",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-45231 affects version 4.0.post7+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67044590-48f4-59ad-aabe-0df89add202c",
      "id": "CVE-2025-13372",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13372 affects version 4.0.post7+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d94fb8ca-94e2-5255-8fe1-6d93ab521e4d",
      "id": "CVE-2025-13473",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13473 affects version 4.0.post7+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22a8676e-2031-5592-90d4-abf5ebf7747e",
      "id": "CVE-2025-14550",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-14550 affects version 4.0.post7+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe924d02-0c00-5840-8f89-ff0e2b892267",
      "id": "CVE-2025-48432",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48432 affects version 4.0.post7+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7974ef1-5d60-58da-80f7-93fa281ede04",
      "id": "CVE-2025-57833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57833 affects version 4.0.post7+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0dbb4beb-fd65-517f-a913-991ce0573560",
      "id": "CVE-2025-64458",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64458 affects version 4.0.post7+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ffcfe6bc-7301-5977-9f12-690fc7ee4471",
      "id": "CVE-2025-64459",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64459 affects version 4.0.post7+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb923819-e2bb-5fe0-9566-938ab1bb2ffd",
      "id": "CVE-2025-64460",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64460 affects version 4.0.post7+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbcccce4-0c71-511b-a00c-45a331a1c142",
      "id": "CVE-2026-1207",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1207 affects version 4.0.post7+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bf7a55e-6ec2-50ec-a6d4-0fb58bec06bc",
      "id": "CVE-2026-1285",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1285 affects version 4.0.post7+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98ec29cb-44df-5040-b611-2e207604a73f",
      "id": "CVE-2026-1287",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1287 affects version 4.0.post7+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1cead4b9-d148-56c9-9e3b-00ee742f5da6",
      "id": "CVE-2026-1312",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1312 affects version 4.0.post7+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64617732-3221-59ba-90a6-b0a22501582e",
      "id": "AIKIDO-2026-10554",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2026-10554 is fixed in version 0.25.2.post6+tuxcare of dulwich."
      },
      "affects": [
        {
          "ref": "pkg:pypi/dulwich@0.25.2.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd66a02d-44b1-52f2-ac77-7086d5d937ea",
      "id": "CVE-2026-42305",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42305 is fixed in version 0.25.2.post6+tuxcare of dulwich."
      },
      "affects": [
        {
          "ref": "pkg:pypi/dulwich@0.25.2.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9d960a2-de4b-52c2-9d4a-50da093f0cde",
      "id": "CVE-2026-42563",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42563 is fixed in version 0.25.2.post6+tuxcare of dulwich."
      },
      "affects": [
        {
          "ref": "pkg:pypi/dulwich@0.25.2.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c536e09-cd6c-58a0-9198-2547e69c15aa",
      "id": "CVE-2026-47712",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47712 is fixed in version 0.25.2.post6+tuxcare of dulwich."
      },
      "affects": [
        {
          "ref": "pkg:pypi/dulwich@0.25.2.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1666477a-17a4-50cf-b0f8-a4b7065b24f9",
      "id": "CVE-2026-47734",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47734 is fixed in version 0.25.2.post6+tuxcare of dulwich."
      },
      "affects": [
        {
          "ref": "pkg:pypi/dulwich@0.25.2.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:413128c4-06a2-5e98-8770-9526f5c95f7d",
      "id": "CVE-2026-52726",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52726 is fixed in version 0.25.2.post6+tuxcare of dulwich."
      },
      "affects": [
        {
          "ref": "pkg:pypi/dulwich@0.25.2.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02443cdb-3b75-5bb2-9372-f9bdbde6e39b",
      "id": "CVE-2024-12797",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-12797 is fixed in version 43.0.3.post3+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@43.0.3.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af3c921f-17b1-54b8-afc2-894a662c9629",
      "id": "CVE-2026-26007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-26007 is fixed in version 43.0.3.post3+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@43.0.3.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dceea4a4-05c2-5d92-8d49-1bcdb34f4d53",
      "id": "CVE-2026-34073",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34073 is fixed in version 43.0.3.post3+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@43.0.3.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5f30d04-6242-5c54-bc3e-c2ae4b248caa",
      "id": "GHSA-537c-gmf6-5ccf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-537c-gmf6-5ccf affects version 43.0.3.post3+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@43.0.3.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b705bd1-d61d-53dd-a3fe-f083efb1b3ec",
      "id": "CVE-2023-40267",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40267 affects version 3.1.31.post3+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a7139b6-8ce9-5f4f-be0a-8b2133c0e451",
      "id": "CVE-2023-40590",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-40590 is fixed in version 3.1.31.post3+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a69be668-f15d-55b6-8a2c-59d4155c3bc3",
      "id": "CVE-2023-41040",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41040 is fixed in version 3.1.31.post3+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc459845-9048-54ce-9e81-e02b5b1594d4",
      "id": "CVE-2024-22190",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22190 is fixed in version 3.1.31.post3+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:631361e9-4d42-5111-b680-075a805d4d96",
      "id": "CVE-2026-42215",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42215 is fixed in version 3.1.31.post3+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f3924b3-5e0a-5e00-9775-e9141c9d51ca",
      "id": "CVE-2026-42284",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42284 affects version 3.1.31.post3+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a87162fc-ee95-5b1c-8593-1f4b403b64ee",
      "id": "CVE-2026-44243",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44243 affects version 3.1.31.post3+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20e6f6c0-4193-5fb4-a320-2d46a1a495e3",
      "id": "CVE-2026-44244",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44244 is fixed in version 3.1.31.post3+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb9d30df-6c25-5f96-b26a-1345fe9ea928",
      "id": "GHSA-2f96-g7mh-g2hx",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-2f96-g7mh-g2hx affects version 3.1.31.post3+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:602bbfa6-6b8a-56fb-9263-83d4958ace58",
      "id": "GHSA-3rp5-jjmw-4wv2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-3rp5-jjmw-4wv2 affects version 3.1.31.post3+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09f14709-efd1-51f5-b973-df029c13cdc3",
      "id": "GHSA-6p8h-3wgx-97gf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-6p8h-3wgx-97gf affects version 3.1.31.post3+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03031d34-c99b-590e-a86b-c35cac8b572a",
      "id": "GHSA-94p4-4cq8-9g67",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-94p4-4cq8-9g67 affects version 3.1.31.post3+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bde6676-f17c-5c16-91d4-68e68030c854",
      "id": "GHSA-956x-8gvw-wg5v",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-956x-8gvw-wg5v affects version 3.1.31.post3+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4196a974-ba18-5513-be58-e468cb87f209",
      "id": "GHSA-fjr4-x663-mwxc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-fjr4-x663-mwxc affects version 3.1.31.post3+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8743b031-2010-5e67-adaf-1143c2501851",
      "id": "GHSA-mv93-w799-cj2w",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-mv93-w799-cj2w is fixed in version 3.1.31.post3+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d44626c8-8de8-5515-92c8-40c9779af398",
      "id": "GHSA-r9mr-m37c-5fr3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-r9mr-m37c-5fr3 affects version 3.1.31.post3+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d49d9bb-bfd5-59a6-bb27-cd8f3a9ab9ab",
      "id": "GHSA-rwj8-pgh3-r573",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-rwj8-pgh3-r573 affects version 3.1.31.post3+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19f82a98-dbd3-58f7-9cb3-51457cb5e162",
      "id": "CVE-2023-40267",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40267 affects version 3.1.31.post2+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e504d958-fc86-540e-aa76-6f66eaff4917",
      "id": "CVE-2023-40590",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-40590 is fixed in version 3.1.31.post2+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad2ef30f-a4b5-5205-8355-034d907c164d",
      "id": "CVE-2023-41040",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41040 is fixed in version 3.1.31.post2+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01da89ef-f807-5547-a499-fb3af55ed3d5",
      "id": "CVE-2024-22190",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22190 is fixed in version 3.1.31.post2+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0227928f-9c94-5a92-9994-f27a29259464",
      "id": "CVE-2026-42215",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42215 affects version 3.1.31.post2+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c49c095-afc5-5abf-b3c8-0d41ce5f8ad4",
      "id": "CVE-2026-42284",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42284 affects version 3.1.31.post2+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:406bf01e-801a-5ebc-a31c-1b1d24b6a6ab",
      "id": "CVE-2026-44243",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44243 affects version 3.1.31.post2+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7924597-3d89-53e7-afd8-27628071aca4",
      "id": "CVE-2026-44244",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44244 is fixed in version 3.1.31.post2+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28c1fe42-9f57-5db2-bf57-4a25eb95c4ae",
      "id": "GHSA-2f96-g7mh-g2hx",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-2f96-g7mh-g2hx affects version 3.1.31.post2+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de24b0dd-ec50-5bcb-804e-7b7a8ac43464",
      "id": "GHSA-3rp5-jjmw-4wv2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-3rp5-jjmw-4wv2 affects version 3.1.31.post2+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5de3469-3605-5b61-9802-5a44d9333d9d",
      "id": "GHSA-6p8h-3wgx-97gf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-6p8h-3wgx-97gf affects version 3.1.31.post2+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e934ee8b-8a8b-5b0d-983f-92279cd2385b",
      "id": "GHSA-94p4-4cq8-9g67",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-94p4-4cq8-9g67 affects version 3.1.31.post2+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d51d7c87-f670-5439-a19e-5f01b83bb209",
      "id": "GHSA-956x-8gvw-wg5v",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-956x-8gvw-wg5v affects version 3.1.31.post2+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06ce1321-fcdb-5af4-bb7c-80534610b68b",
      "id": "GHSA-fjr4-x663-mwxc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-fjr4-x663-mwxc affects version 3.1.31.post2+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1b00462-2f61-58eb-8c3d-6835bc231474",
      "id": "GHSA-mv93-w799-cj2w",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mv93-w799-cj2w affects version 3.1.31.post2+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6025f472-68f8-5943-86fe-6ca8c0f752ec",
      "id": "GHSA-r9mr-m37c-5fr3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-r9mr-m37c-5fr3 affects version 3.1.31.post2+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22e40aef-789e-58ae-9432-5f3b500344c9",
      "id": "GHSA-rwj8-pgh3-r573",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-rwj8-pgh3-r573 affects version 3.1.31.post2+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26a7ce38-a23d-574e-8a40-8851496fbaa1",
      "id": "CVE-2024-47874",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47874 is fixed in version 0.27.0.post6+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbc90edd-d0a7-53e8-9b86-670edc07d37e",
      "id": "CVE-2025-54121",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-54121 is fixed in version 0.27.0.post6+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba95fa5b-1ed9-56c0-bf89-7271cf2cf09b",
      "id": "CVE-2025-62727",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-62727 does not affect version 0.27.0.post6+tuxcare of starlette. Version 0.27.0 is not vulnerable. Summary: The target repository (Starlette version 0.27.0) is NOT vulnerable to CVE-2025-62727. The vulnerable Range header parsing logic was introduced in version 0.39.0, and the target version 0.27.0 predates this introduction. The FileResponse class in version 0.27.0 does not implement any Range header parsing or processing functionality. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43c0084e-1326-589f-81fb-73fe6fef032c",
      "id": "CVE-2026-48710",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48710 is fixed in version 0.27.0.post6+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79520264-9f2b-54e9-8fc2-a86849776c6e",
      "id": "CVE-2026-48817",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48817 is fixed in version 0.27.0.post6+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17ec4141-4a22-58a2-b60a-911154d0bf0b",
      "id": "CVE-2026-48818",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48818 is fixed in version 0.27.0.post6+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa117158-9f06-5d8c-911b-6d69796e892e",
      "id": "CVE-2026-54282",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54282 is fixed in version 0.27.0.post6+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:156b0dd8-0932-5cb1-a0cc-d78cc6e3dcb5",
      "id": "CVE-2026-54283",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54283 is fixed in version 0.27.0.post6+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6761653-bf06-5ee9-a6ac-874c15fb8230",
      "id": "GHSA-93gm-qmq6-w238",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-93gm-qmq6-w238 is a false positive for starlette 0.27.0.post6+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82e33165-47e5-5242-bcfc-0bfc23cc6af1",
      "id": "CVE-2025-55197",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55197 is fixed in version 5.9.0.post11+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ad9995c-ef4f-58c1-9308-2b3323ab0c13",
      "id": "CVE-2025-62707",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-62707 is fixed in version 5.9.0.post11+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4c2d5a2-d2af-5034-a8db-23080e968826",
      "id": "CVE-2025-62708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-62708 is fixed in version 5.9.0.post11+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9c76f49-633a-59d8-af4d-edb74400f03d",
      "id": "CVE-2025-66019",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66019 affects version 5.9.0.post11+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0223e34c-903d-58ec-a5ba-b9d7c23f93c2",
      "id": "CVE-2026-22690",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22690 affects version 5.9.0.post11+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:558569fa-ed07-5730-abbe-eebb57055ddc",
      "id": "CVE-2026-22691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22691 affects version 5.9.0.post11+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2793c8f5-45fc-5aed-a6f5-d9a23dc5148f",
      "id": "CVE-2026-24688",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24688 affects version 5.9.0.post11+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05769c47-ed44-5208-8bfa-da06e3abc6a7",
      "id": "CVE-2026-27024",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27024 affects version 5.9.0.post11+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c625d083-8834-50c8-b33d-b0e51049d3ff",
      "id": "CVE-2026-27025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27025 affects version 5.9.0.post11+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fdf3d233-897e-59bf-86b4-aa7cb7a7abcc",
      "id": "CVE-2026-27026",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27026 affects version 5.9.0.post11+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f4e4e9a-3c73-5add-9aaa-ea87057b6572",
      "id": "CVE-2026-27628",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27628 is fixed in version 5.9.0.post11+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2dfd6fd-c2fb-5aeb-88d2-6f153f487fa9",
      "id": "CVE-2026-27888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27888 affects version 5.9.0.post11+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14e9bc65-177e-5d2c-8822-e86a964b092f",
      "id": "CVE-2026-28351",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-28351 affects version 5.9.0.post11+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37ea8a44-9c49-597c-81fc-19211ea77ad2",
      "id": "CVE-2026-28804",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-28804 affects version 5.9.0.post11+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a528a9d9-8d3b-5c11-bbd8-760c49bd05bf",
      "id": "CVE-2026-31826",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-31826 affects version 5.9.0.post11+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:646b0ff2-a29c-511b-9fd4-7c4274f59eb1",
      "id": "CVE-2026-33123",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33123 affects version 5.9.0.post11+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f851f2cc-aba3-5f9c-9f00-796751dc1272",
      "id": "CVE-2026-33699",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33699 affects version 5.9.0.post11+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:250f61d9-e25f-54c4-9df0-97b76b73b64c",
      "id": "CVE-2026-40260",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40260 affects version 5.9.0.post11+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc7a44f8-d201-5cc2-aec7-586a04a49f76",
      "id": "CVE-2026-41168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41168 is fixed in version 5.9.0.post11+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8b682a9-99c1-5ee2-ab3a-f4153e3c0449",
      "id": "CVE-2026-41312",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41312 is fixed in version 5.9.0.post11+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c09afda6-855e-5073-be7c-f8896b1e57fa",
      "id": "CVE-2026-41313",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41313 is fixed in version 5.9.0.post11+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:055433b9-82cc-5eca-917a-f3e09cc7511e",
      "id": "CVE-2026-41314",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41314 is fixed in version 5.9.0.post11+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2632e79-cc50-5ffb-a6bd-be6c23d78f56",
      "id": "CVE-2026-48155",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48155 is fixed in version 5.9.0.post11+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b2dce22-970b-53c7-9975-227d61f7d2a6",
      "id": "CVE-2026-48156",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48156 is fixed in version 5.9.0.post11+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a7b16ca-9a33-57bd-90f4-ff9667ae5d6b",
      "id": "CVE-2026-48735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48735 affects version 5.9.0.post11+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93e3c6ac-d32a-5f01-983f-b4bb62f1f585",
      "id": "CVE-2026-49460",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49460 is fixed in version 5.9.0.post11+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92fd2b1d-1f1d-5e12-be3a-9b732f39f1ec",
      "id": "CVE-2026-49461",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49461 is fixed in version 5.9.0.post11+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4cdb4fa6-0761-5a24-af87-c92cf6bc9a9b",
      "id": "CVE-2026-54530",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54530 is fixed in version 5.9.0.post11+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50e2bde7-b459-531a-9930-e576245cf675",
      "id": "CVE-2026-54531",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54531 is fixed in version 5.9.0.post11+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37eb2e8e-26bf-55e5-b111-13969b288270",
      "id": "CVE-2026-54651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54651 is fixed in version 5.9.0.post11+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a866024-3fbb-5303-9562-e4bdf8bf5e5d",
      "id": "CVE-2026-59935",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59935 affects version 5.9.0.post11+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f80f4c1e-7d08-5543-9f93-bc01b61e54d4",
      "id": "CVE-2026-59936",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59936 affects version 5.9.0.post11+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46ee7ed4-f745-5119-be74-6c4cfc44f7b9",
      "id": "CVE-2026-59937",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59937 affects version 5.9.0.post11+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49ae7a08-2d19-505e-9a1d-85753744efa8",
      "id": "CVE-2026-59938",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59938 affects version 5.9.0.post11+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5953947-9f21-5b12-81c8-df298cd55ee2",
      "id": "GHSA-4pxv-j86v-mhcw",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post11+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58443214-3daf-5933-938a-1a794685b989",
      "id": "GHSA-7gw9-cf7v-778f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post11+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc05e7d8-1f7f-5e19-bbe8-51b2d7459870",
      "id": "GHSA-9m86-7pmv-2852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post11+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:441932b1-ba72-57b2-975b-1ed342a20935",
      "id": "GHSA-jj6c-8h6c-hppx",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post11+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7754b2f9-22e9-5a7e-ac0a-35b35c83e311",
      "id": "GHSA-jm82-fx9c-mx94",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-jm82-fx9c-mx94 is fixed in version 5.9.0.post11+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7d08d18-b0b2-5a5a-9d25-ae0b36c8a18d",
      "id": "GHSA-x284-j5p8-9c5p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-x284-j5p8-9c5p affects version 5.9.0.post11+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c34e1a40-216a-5951-a7cd-06ec9fc48375",
      "id": "CVE-2026-1839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1839 is fixed in version 4.57.6.post3+tuxcare of transformers."
      },
      "affects": [
        {
          "ref": "pkg:pypi/transformers@4.57.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35c4e9ed-d927-5e98-949c-e8381a2ec50d",
      "id": "CVE-2026-4372",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-4372 is fixed in version 4.57.6.post3+tuxcare of transformers."
      },
      "affects": [
        {
          "ref": "pkg:pypi/transformers@4.57.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab98ba10-243f-5e2f-b36d-82f6d505cfac",
      "id": "CVE-2026-5241",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-5241 is fixed in version 4.57.6.post3+tuxcare of transformers."
      },
      "affects": [
        {
          "ref": "pkg:pypi/transformers@4.57.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f511fcac-9287-5f4d-b924-221e16db8c68",
      "id": "CVE-2024-24762",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-24762 is fixed in version 0.0.6.post6+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce4eb199-2887-56ea-b315-2617061cd279",
      "id": "CVE-2024-53981",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-53981 is fixed in version 0.0.6.post6+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00eafb8d-565a-506c-99c0-33f867f4d028",
      "id": "CVE-2026-24486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24486 affects version 0.0.6.post6+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13f628c6-a1be-5d17-88d6-050a36aaf9db",
      "id": "CVE-2026-40347",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40347 is fixed in version 0.0.6.post6+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf68d81d-db59-5f8b-a089-38d9e6f2b4df",
      "id": "CVE-2026-42561",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42561 is fixed in version 0.0.6.post6+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ae464f6-6761-5b3c-af80-ab0db9dd0af8",
      "id": "CVE-2026-53537",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-53537 is fixed in version 0.0.6.post6+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0ca7024-a86f-584e-89d3-f7f55742d2fa",
      "id": "CVE-2026-53538",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-53538 is fixed in version 0.0.6.post6+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ffa0e89f-4db8-5918-afda-7de7c89194a7",
      "id": "CVE-2026-53539",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53539 affects version 0.0.6.post6+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b7671af-2454-5c3a-aec6-39b5b324e48d",
      "id": "CVE-2026-53540",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-53540 is fixed in version 0.0.6.post6+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25b9484f-7559-5020-ad0a-55ee08f91cc4",
      "id": "CVE-2024-37059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37059 affects version 2.22.4.post6+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8cd43e84-bbea-5dd1-a34f-95e8b7fc1a1f",
      "id": "CVE-2025-10279",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-10279 is fixed in version 2.22.4.post6+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e00ed1c-4cb2-5b43-9ac9-3295e5811279",
      "id": "CVE-2025-14279",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-14279 is fixed in version 2.22.4.post6+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:078b8af5-87c7-5ab3-9437-94d426658eac",
      "id": "CVE-2025-14287",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-14287 is fixed in version 2.22.4.post6+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf874fa3-ceb2-523c-9c42-a4c6f9ca0a72",
      "id": "CVE-2025-15031",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-15031 is fixed in version 2.22.4.post6+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c819ca9-ddd6-58e7-afc6-2f9b73744c0d",
      "id": "CVE-2025-15036",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-15036 does not affect version 2.22.4.post6+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db7631e9-28a2-575f-aaee-4e9785f3c104",
      "id": "CVE-2025-15379",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-15379 affects version 2.22.4.post6+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef568ea3-7e53-5016-8e5f-9d47314e46f7",
      "id": "CVE-2025-15381",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-15381 affects version 2.22.4.post6+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:677adc71-ab0f-5587-915e-394dd74d88b2",
      "id": "CVE-2026-0545",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-0545 does not affect version 2.22.4.post6+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b14df4ca-7c75-5503-94bb-084b137604b7",
      "id": "CVE-2026-0596",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-0596 is fixed in version 2.22.4.post6+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4e03883-e3b4-5969-a6f1-44ad426cf2a4",
      "id": "CVE-2026-10803",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10803 affects version 2.22.4.post6+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e668f805-d8c8-5711-871c-00ffaad1cdd3",
      "id": "CVE-2026-2033",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-2033 is fixed in version 2.22.4.post6+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb9b6a40-7b62-5d12-9ace-ff1893d59a3f",
      "id": "CVE-2026-2393",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-2393 does not affect version 2.22.4.post6+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3246bbf-9b71-5ba0-86ae-33478db0a07c",
      "id": "CVE-2026-2614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-2614 is fixed in version 2.22.4.post6+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfc775c1-0ec3-545a-b375-358c59eaa8b9",
      "id": "CVE-2026-2635",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-2635 is fixed in version 2.22.4.post6+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e908fd56-7456-5edb-8560-0eb7a1996111",
      "id": "CVE-2026-2651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-2651 is fixed in version 2.22.4.post6+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d42745b-e047-5cc3-a3f2-6c359e71d15d",
      "id": "CVE-2026-2652",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-2652 does not affect version 2.22.4.post6+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7fa0fb70-0a3f-548b-92c2-42a0b8bda760",
      "id": "CVE-2026-2734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2734 affects version 2.22.4.post6+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a5feab2-985e-5744-af94-e048a899cac6",
      "id": "CVE-2026-3198",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-3198 does not affect version 2.22.4.post6+tuxcare of mlflow. not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05d4c642-f6c6-58f7-aa1f-2e0ccc088d3a",
      "id": "CVE-2026-33865",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33865 affects version 2.22.4.post6+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8bbb447-249d-50a3-9d63-6bab2f19eb5e",
      "id": "CVE-2026-33866",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33866 does not affect version 2.22.4.post6+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efdfc1f6-1669-5a87-bb76-c9152a7a7437",
      "id": "CVE-2026-4035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-4035 is fixed in version 2.22.4.post6+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3e9f41c-bfc1-5129-9158-7c8522e62b46",
      "id": "CVE-2026-4137",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-4137 is fixed in version 2.22.4.post6+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:862e4933-1234-5be6-89ec-86d89557e173",
      "id": "CVE-2026-26007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-26007 is fixed in version 44.0.3.post3+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@44.0.3.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30296981-4e9e-56b8-ada8-04ffb60d525f",
      "id": "CVE-2026-34073",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34073 is fixed in version 44.0.3.post3+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@44.0.3.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99f42a8d-6e50-5433-b626-dda56d47c75a",
      "id": "GHSA-537c-gmf6-5ccf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-537c-gmf6-5ccf is fixed in version 44.0.3.post3+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@44.0.3.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ddba6a9f-5742-578e-bb34-eaf8a95c6d2e",
      "id": "CVE-2024-49768",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-49768 is fixed in version 2.1.2.post3+tuxcare of langgraph-checkpoint."
      },
      "affects": [
        {
          "ref": "pkg:pypi/langgraph-checkpoint@2.1.2.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cab1f557-be86-5e27-be33-e59e519a2eb6",
      "id": "CVE-2024-49769",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-49769 is fixed in version 2.1.2.post3+tuxcare of langgraph-checkpoint."
      },
      "affects": [
        {
          "ref": "pkg:pypi/langgraph-checkpoint@2.1.2.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa9ddda0-4b9d-5724-a2dc-0306f0622c40",
      "id": "CVE-2025-64439",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64439 is fixed in version 2.1.2.post3+tuxcare of langgraph-checkpoint."
      },
      "affects": [
        {
          "ref": "pkg:pypi/langgraph-checkpoint@2.1.2.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa6ae3cc-3643-5979-adb8-23ab82c77d15",
      "id": "CVE-2026-27794",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27794 is fixed in version 2.1.2.post3+tuxcare of langgraph-checkpoint."
      },
      "affects": [
        {
          "ref": "pkg:pypi/langgraph-checkpoint@2.1.2.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59733f5e-081e-5b1f-8252-525e237fbab9",
      "id": "CVE-2026-48775",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48775 is fixed in version 2.1.2.post3+tuxcare of langgraph-checkpoint."
      },
      "affects": [
        {
          "ref": "pkg:pypi/langgraph-checkpoint@2.1.2.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40eb60b3-82f1-587d-a33f-132e37287332",
      "id": "CVE-2025-55197",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55197 is fixed in version 5.9.0.post10+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b576ad26-de38-5fd6-adc6-d6e286fb4e6a",
      "id": "CVE-2025-62707",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-62707 is fixed in version 5.9.0.post10+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81ecd34d-ebef-59f6-8e8d-bd1cfa76c345",
      "id": "CVE-2025-62708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-62708 is fixed in version 5.9.0.post10+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22368e9f-b53e-5e10-93c6-b83f6d907604",
      "id": "CVE-2025-66019",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66019 affects version 5.9.0.post10+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6db47af8-e88e-53a1-adf8-3e09e5dff631",
      "id": "CVE-2026-22690",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22690 affects version 5.9.0.post10+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d68fb331-6db6-565c-8ad0-3d4f23f6ef8d",
      "id": "CVE-2026-22691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22691 affects version 5.9.0.post10+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94b6880a-5aaf-5f1c-9d8d-321d80461a6b",
      "id": "CVE-2026-24688",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24688 affects version 5.9.0.post10+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc068cbf-b4e0-5603-9b09-5659f7590b3d",
      "id": "CVE-2026-27024",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27024 affects version 5.9.0.post10+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b06f374-eeb4-5f02-bc6d-c21f21931101",
      "id": "CVE-2026-27025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27025 affects version 5.9.0.post10+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11ef6357-debb-5df5-b0b5-81d398391255",
      "id": "CVE-2026-27026",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27026 affects version 5.9.0.post10+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21d14870-f80c-50a3-a797-355fa2f88bed",
      "id": "CVE-2026-27628",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27628 is fixed in version 5.9.0.post10+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab1ba8b4-d631-5fa7-b0de-8c7e8ed03f7a",
      "id": "CVE-2026-27888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27888 affects version 5.9.0.post10+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6751b115-f93c-5d4b-af23-11384100d35d",
      "id": "CVE-2026-28351",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-28351 affects version 5.9.0.post10+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bfb4f83-1de4-589c-aeb8-31ce8c9383a4",
      "id": "CVE-2026-28804",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-28804 affects version 5.9.0.post10+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efca9281-ea2b-5f0d-a220-db29a34e5018",
      "id": "CVE-2026-31826",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-31826 affects version 5.9.0.post10+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b034280-0a7b-5459-a4c2-874a7712864d",
      "id": "CVE-2026-33123",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33123 affects version 5.9.0.post10+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3240b9c6-6051-56a1-be42-c344ec7a0d96",
      "id": "CVE-2026-33699",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33699 affects version 5.9.0.post10+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b88a3e18-e96e-558f-be33-c427c3d131c2",
      "id": "CVE-2026-40260",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40260 affects version 5.9.0.post10+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54ea8e44-8bce-598d-b853-070758376fac",
      "id": "CVE-2026-41168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41168 is fixed in version 5.9.0.post10+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f82358e-d4a4-53b4-8fd5-a4d77237390a",
      "id": "CVE-2026-41312",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41312 is fixed in version 5.9.0.post10+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d40b6f97-c425-50c8-8980-ffa93d46850e",
      "id": "CVE-2026-41313",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41313 is fixed in version 5.9.0.post10+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9dae5ec-921a-5c42-be32-259882a6fa73",
      "id": "CVE-2026-41314",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41314 is fixed in version 5.9.0.post10+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96821218-2109-530f-99da-c54f1bff493f",
      "id": "CVE-2026-48155",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48155 is fixed in version 5.9.0.post10+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34de3304-e031-5368-9790-ab81fe7248d9",
      "id": "CVE-2026-48156",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48156 is fixed in version 5.9.0.post10+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97e71750-0139-5b22-9692-6f55ec8d8669",
      "id": "CVE-2026-48735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48735 affects version 5.9.0.post10+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e4f8808-b5dd-5382-a394-7d9e1c2e681f",
      "id": "CVE-2026-49460",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49460 is fixed in version 5.9.0.post10+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a8bbced-5a67-5bda-b3e8-7688698daf68",
      "id": "CVE-2026-49461",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49461 is fixed in version 5.9.0.post10+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b35917bd-158d-5564-b0f5-d09b9d8103f2",
      "id": "CVE-2026-54530",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54530 is fixed in version 5.9.0.post10+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a6f7134-9a73-5284-a05a-b1396cc61559",
      "id": "CVE-2026-54531",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54531 is fixed in version 5.9.0.post10+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d4b308a-2d73-50fb-a1af-e3bdec0988e1",
      "id": "CVE-2026-54651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54651 affects version 5.9.0.post10+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f2b6801-f2b2-5f69-9ae5-c42b7557d77c",
      "id": "CVE-2026-59935",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59935 affects version 5.9.0.post10+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2616cc49-2ee4-56d8-b166-6ec3e2e05327",
      "id": "CVE-2026-59936",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59936 affects version 5.9.0.post10+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e5586f4-4b99-50ae-b66e-95bc0245f1ce",
      "id": "CVE-2026-59937",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59937 affects version 5.9.0.post10+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ff5d8d3-e4ea-519b-8b18-9172b1c7c875",
      "id": "CVE-2026-59938",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59938 affects version 5.9.0.post10+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20e6d000-1f54-5f2a-b742-33162d46b00f",
      "id": "GHSA-4pxv-j86v-mhcw",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post10+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ec2fdd8-836c-5bd8-9fd4-1045a5cbd5e7",
      "id": "GHSA-7gw9-cf7v-778f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post10+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2d68ec4-d617-524c-9014-1f37e1f7b8b8",
      "id": "GHSA-9m86-7pmv-2852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post10+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:213b7cb7-5f2e-583e-9f58-1edf7122a091",
      "id": "GHSA-jj6c-8h6c-hppx",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post10+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ce588a8-a3ba-5c97-8cbf-3075c0568fd6",
      "id": "GHSA-jm82-fx9c-mx94",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-jm82-fx9c-mx94 is fixed in version 5.9.0.post10+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87551862-eaee-5491-bbc2-f42583587935",
      "id": "GHSA-x284-j5p8-9c5p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-x284-j5p8-9c5p affects version 5.9.0.post10+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cac2dfb0-597b-588f-8ef6-e463b8c33eef",
      "id": "CVE-2026-1839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1839 is fixed in version 4.57.6.post2+tuxcare of transformers."
      },
      "affects": [
        {
          "ref": "pkg:pypi/transformers@4.57.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:702550ce-bc17-532b-8a9d-efcada3856ac",
      "id": "CVE-2026-4372",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-4372 is fixed in version 4.57.6.post2+tuxcare of transformers."
      },
      "affects": [
        {
          "ref": "pkg:pypi/transformers@4.57.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:adfe18cb-8bbc-5c58-9fa0-3fe7e8ad9fcb",
      "id": "CVE-2026-5241",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-5241 affects version 4.57.6.post2+tuxcare of transformers."
      },
      "affects": [
        {
          "ref": "pkg:pypi/transformers@4.57.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc079298-1277-5a0a-8872-3b71527ac14a",
      "id": "CVE-2024-37059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37059 affects version 2.22.4.post5+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c74fd28d-461c-5d0d-be90-0df140ac677d",
      "id": "CVE-2025-10279",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-10279 is fixed in version 2.22.4.post5+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5ed9277-1ce6-5bbd-8e29-7db5ebb01ec7",
      "id": "CVE-2025-14279",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-14279 is fixed in version 2.22.4.post5+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:302cf14e-e717-54dc-9611-50be45b4fa2f",
      "id": "CVE-2025-14287",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-14287 is fixed in version 2.22.4.post5+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f771905c-a478-5c4f-8760-a51bbd2224ae",
      "id": "CVE-2025-15031",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-15031 is fixed in version 2.22.4.post5+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b9b0981-e054-5eda-81ee-666df432fc6e",
      "id": "CVE-2025-15036",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-15036 does not affect version 2.22.4.post5+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c24d81b7-3c25-5c47-8085-c3fdf388eabd",
      "id": "CVE-2025-15379",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-15379 affects version 2.22.4.post5+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7ef5578-43df-5c69-ba7a-be3b4319bf5c",
      "id": "CVE-2025-15381",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-15381 affects version 2.22.4.post5+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07c9bc1a-8448-54e0-b420-a75160db060b",
      "id": "CVE-2026-0545",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-0545 does not affect version 2.22.4.post5+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68a193fe-9dae-5edd-bb27-0f21ae511c6a",
      "id": "CVE-2026-0596",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-0596 is fixed in version 2.22.4.post5+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74eb428b-658b-5129-9d03-b9b104a73461",
      "id": "CVE-2026-10803",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10803 affects version 2.22.4.post5+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0dd26257-db70-5e7f-bd1b-7482f38aa9b8",
      "id": "CVE-2026-2033",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-2033 is fixed in version 2.22.4.post5+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50d3a8e8-0727-5532-b974-21fa476a20ab",
      "id": "CVE-2026-2393",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-2393 does not affect version 2.22.4.post5+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2aeb3dc-85df-5c6d-8f41-7f6c2a4fe89d",
      "id": "CVE-2026-2614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-2614 is fixed in version 2.22.4.post5+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48182c15-3db7-5ed2-a212-af0280ac7147",
      "id": "CVE-2026-2635",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-2635 is fixed in version 2.22.4.post5+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76f8f0bc-e832-5001-bbe5-ad419adc7888",
      "id": "CVE-2026-2651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-2651 is fixed in version 2.22.4.post5+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9a602df-6477-5c25-a6a8-3a8c9d2f2f88",
      "id": "CVE-2026-2652",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-2652 does not affect version 2.22.4.post5+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f06d8ba3-b7d7-5eca-9756-675eaccb2951",
      "id": "CVE-2026-2734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2734 affects version 2.22.4.post5+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86c05162-af2d-56d3-95b9-b73b6451b373",
      "id": "CVE-2026-3198",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-3198 does not affect version 2.22.4.post5+tuxcare of mlflow. not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7748f1f0-a2b7-5f74-b03d-b5a2be6c938e",
      "id": "CVE-2026-33865",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33865 affects version 2.22.4.post5+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46435e63-3dc8-5e1a-ba7d-9d268031de2c",
      "id": "CVE-2026-33866",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33866 does not affect version 2.22.4.post5+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e485362b-d56c-5529-8e1f-d2f36773faa9",
      "id": "CVE-2026-4035",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-4035 affects version 2.22.4.post5+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d1ada8f-7448-5186-bed5-b97b896dec71",
      "id": "CVE-2026-4137",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-4137 is fixed in version 2.22.4.post5+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b529b546-db3b-5858-a639-063c02fc68c3",
      "id": "CVE-2025-55197",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55197 is fixed in version 5.9.0.post9+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd42b155-742b-55da-98b7-f8e2c2f786d2",
      "id": "CVE-2025-62707",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-62707 is fixed in version 5.9.0.post9+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76e503b9-2f00-5a14-9d42-cb7963cb8425",
      "id": "CVE-2025-62708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-62708 is fixed in version 5.9.0.post9+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf32a214-859a-55a2-b714-9a37003375a9",
      "id": "CVE-2025-66019",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66019 affects version 5.9.0.post9+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc63ecc4-0885-5206-aefb-3b3e0d654edf",
      "id": "CVE-2026-22690",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22690 affects version 5.9.0.post9+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f135b1ff-efb2-5184-bc13-96df17690408",
      "id": "CVE-2026-22691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22691 affects version 5.9.0.post9+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d3cc441-4087-53ef-a236-37be1f89041b",
      "id": "CVE-2026-24688",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24688 affects version 5.9.0.post9+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2ba54eb-0711-51b7-a2a3-f89373cbe7b1",
      "id": "CVE-2026-27024",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27024 affects version 5.9.0.post9+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa91862c-8c1a-561c-9ff6-cfcef5f47f80",
      "id": "CVE-2026-27025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27025 affects version 5.9.0.post9+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8885a944-1e46-50f4-a584-c17e4284c186",
      "id": "CVE-2026-27026",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27026 affects version 5.9.0.post9+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:829fd1c4-dd95-5048-a05a-622d2c3a9515",
      "id": "CVE-2026-27628",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27628 is fixed in version 5.9.0.post9+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82233c94-2450-5545-8ffa-b934af9b80f8",
      "id": "CVE-2026-27888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27888 affects version 5.9.0.post9+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b82d338b-2579-50ab-bb46-ee38949b944a",
      "id": "CVE-2026-28351",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-28351 affects version 5.9.0.post9+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd11854c-328b-554d-99a6-f52b98180091",
      "id": "CVE-2026-28804",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-28804 affects version 5.9.0.post9+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ccb3c82-3cb7-560d-82f9-fa6ad5d08261",
      "id": "CVE-2026-31826",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-31826 affects version 5.9.0.post9+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72422322-919a-5ef9-8e05-e035a83c1474",
      "id": "CVE-2026-33123",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33123 affects version 5.9.0.post9+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f19c05a0-7a5a-5c2f-aa43-eae3940e879b",
      "id": "CVE-2026-33699",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33699 affects version 5.9.0.post9+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ded4b868-2577-5542-a5ee-60f34332bf3a",
      "id": "CVE-2026-40260",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40260 affects version 5.9.0.post9+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1549af8c-8635-528e-8a0c-c4c87b7059e7",
      "id": "CVE-2026-41168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41168 is fixed in version 5.9.0.post9+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2fc2bc3-858e-57b0-8960-a5347ebe7a4b",
      "id": "CVE-2026-41312",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41312 is fixed in version 5.9.0.post9+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97bd6aea-dfa8-51ee-b17d-a10826fc9fae",
      "id": "CVE-2026-41313",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41313 is fixed in version 5.9.0.post9+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55fad0dd-fbb8-5cb8-8e15-50a1ec82c1f7",
      "id": "CVE-2026-41314",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41314 is fixed in version 5.9.0.post9+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b2f0f0d-90bd-575b-aa19-89c0e2dad827",
      "id": "CVE-2026-48155",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48155 is fixed in version 5.9.0.post9+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3c4e341-b7b5-5726-a8ac-91e11efc2cc4",
      "id": "CVE-2026-48156",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48156 is fixed in version 5.9.0.post9+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:244a67cb-36b4-5242-bbcd-e9968b90f71a",
      "id": "CVE-2026-48735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48735 affects version 5.9.0.post9+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42968407-6ea8-56c0-8e06-c4c5ee5fa8fa",
      "id": "CVE-2026-49460",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49460 is fixed in version 5.9.0.post9+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36e3dc6f-d096-531a-9ae1-aac49c78a555",
      "id": "CVE-2026-49461",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49461 is fixed in version 5.9.0.post9+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31eeae52-2ee5-5420-ab55-cb062d0671d9",
      "id": "CVE-2026-54530",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54530 affects version 5.9.0.post9+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:957e93a2-87a4-503b-8b4c-61c3920161ad",
      "id": "CVE-2026-54531",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54531 affects version 5.9.0.post9+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:409fa90c-386a-58a6-adb6-9c7a1053bf4c",
      "id": "CVE-2026-54651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54651 affects version 5.9.0.post9+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:770ed9f9-8a59-5327-987d-2c4c2133974f",
      "id": "CVE-2026-59935",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59935 affects version 5.9.0.post9+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:909433c7-ed9a-5fbd-90a6-2239efc65564",
      "id": "CVE-2026-59936",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59936 affects version 5.9.0.post9+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57c69c6d-5ab9-5581-9349-9470a7ff3e9a",
      "id": "CVE-2026-59937",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59937 affects version 5.9.0.post9+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0e8260e-f320-5adb-98eb-af303be6d8a6",
      "id": "CVE-2026-59938",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59938 affects version 5.9.0.post9+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d5e470d-4508-5a4d-bb8b-56cb0937e012",
      "id": "GHSA-4pxv-j86v-mhcw",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post9+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a9cf7e1-de9b-5236-89be-33867f5b6560",
      "id": "GHSA-7gw9-cf7v-778f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post9+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9335438e-edfb-508a-801b-df0acb632d61",
      "id": "GHSA-9m86-7pmv-2852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post9+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:add9e20b-ba17-5d3d-8de7-249a60904b94",
      "id": "GHSA-jj6c-8h6c-hppx",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post9+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8f963b3-9cea-51ba-9909-2d5696326e52",
      "id": "GHSA-jm82-fx9c-mx94",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-jm82-fx9c-mx94 is fixed in version 5.9.0.post9+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3534f263-571d-56ac-ae94-cd5eefd1f475",
      "id": "GHSA-x284-j5p8-9c5p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-x284-j5p8-9c5p affects version 5.9.0.post9+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b102f897-c52b-5a76-be6e-d6d9cde877ba",
      "id": "CVE-2023-28370",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28370 is fixed in version 6.1.0.post4+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:396cce65-23d8-5402-b3f3-f74969788521",
      "id": "CVE-2024-52804",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52804 is fixed in version 6.1.0.post4+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fed201a-fb47-5837-ac00-dbe30a3e0139",
      "id": "CVE-2025-47287",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-47287 is fixed in version 6.1.0.post4+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab0617f4-d70d-5f41-8091-00b5269f2fa7",
      "id": "CVE-2025-67724",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67724 affects version 6.1.0.post4+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6de8106a-f303-5a18-9a1a-32a5595566c8",
      "id": "CVE-2025-67725",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67725 affects version 6.1.0.post4+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c7daddb-6ad2-59a1-8fa2-f31672ac0bad",
      "id": "CVE-2026-31958",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-31958 is fixed in version 6.1.0.post4+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c6caea5-e8ce-57fa-b3d1-31806e3ebfe9",
      "id": "CVE-2026-35536",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-35536 is fixed in version 6.1.0.post4+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b435999c-5cc4-5414-a82e-6e8c68758e34",
      "id": "CVE-2026-49853",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49853 is fixed in version 6.1.0.post4+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f620e3cc-a39a-55ee-8467-3428a45ee9b4",
      "id": "CVE-2026-49854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49854 is fixed in version 6.1.0.post4+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57ead4d8-cdc6-529e-8874-0745eb41899f",
      "id": "CVE-2026-49855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49855 is fixed in version 6.1.0.post4+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b9639cc-70de-56db-8abd-6f621b057627",
      "id": "GHSA-753j-mpmx-qq6g",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-753j-mpmx-qq6g is fixed in version 6.1.0.post4+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3ef87a2-4944-5b84-acd2-8061d6567642",
      "id": "GHSA-78cv-mqj4-43f7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-78cv-mqj4-43f7 is fixed in version 6.1.0.post4+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f0aa6b3-b095-5aa1-8c34-4e610b99e94b",
      "id": "GHSA-pw6j-qg29-8w7f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-pw6j-qg29-8w7f is fixed in version 6.1.0.post4+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6fd7f3e-9724-54b3-ba3d-54f890c26d5c",
      "id": "GHSA-qppv-j76h-2rpx",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-qppv-j76h-2rpx is fixed in version 6.1.0.post4+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cdedc455-5629-502b-8f7b-18b22f86bf45",
      "id": "GHSA-w235-7p84-xx57",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-w235-7p84-xx57 is fixed in version 6.1.0.post4+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac9de487-01f3-5474-9959-b5d2b87151de",
      "id": "AIKIDO-2026-10554",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2026-10554 is fixed in version 0.25.2.post5+tuxcare of dulwich."
      },
      "affects": [
        {
          "ref": "pkg:pypi/dulwich@0.25.2.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:673579a1-ac8d-57b4-97b3-6cfe5c78bb7e",
      "id": "CVE-2026-42305",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42305 is fixed in version 0.25.2.post5+tuxcare of dulwich."
      },
      "affects": [
        {
          "ref": "pkg:pypi/dulwich@0.25.2.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a4a44d4-4839-53c6-b79a-e05cc077b4f8",
      "id": "CVE-2026-42563",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42563 is fixed in version 0.25.2.post5+tuxcare of dulwich."
      },
      "affects": [
        {
          "ref": "pkg:pypi/dulwich@0.25.2.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce2cdc04-a3cf-5176-8d67-a87028c7ed69",
      "id": "CVE-2026-47712",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47712 affects version 0.25.2.post5+tuxcare of dulwich."
      },
      "affects": [
        {
          "ref": "pkg:pypi/dulwich@0.25.2.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1f83675-b844-544c-9bcf-00f4a9f3cce4",
      "id": "CVE-2026-47734",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47734 is fixed in version 0.25.2.post5+tuxcare of dulwich."
      },
      "affects": [
        {
          "ref": "pkg:pypi/dulwich@0.25.2.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:745cc629-cb51-54c9-a58e-1e074d6c07a8",
      "id": "CVE-2026-52726",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52726 is fixed in version 0.25.2.post5+tuxcare of dulwich."
      },
      "affects": [
        {
          "ref": "pkg:pypi/dulwich@0.25.2.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1fb854b-7871-5f9c-8cff-1eb9d28f120f",
      "id": "CVE-2025-45768",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-45768 is fixed in version 2.10.1.post2+tuxcare of pyjwt."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:990a5a75-b449-542c-a4c3-08c448548d93",
      "id": "CVE-2026-32597",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32597 affects version 2.10.1.post2+tuxcare of pyjwt."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e45c5ee1-bbc2-538d-8627-a8c3b9fab7e5",
      "id": "CVE-2026-48522",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-48522 does not affect version 2.10.1.post2+tuxcare of pyjwt. already_fixed \u2014 CVE-2026-48522 describes PyJWKClient accepting non-HTTP(S) URI schemes (file://, ftp://, data:) which enables SSRF and token forgery. The target repository at version 2.10.1.post2+tuxcare (SHA 098e78a) already contains the exact defense recommended in the CVE. The fix was backported by TuxCare in commit afaaa88 as part of the PyJWT 2.13.0 security bundle. The same vulnerability reporter (Keijo ..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5951ca3a-968b-58dc-93f4-58b0b5b2db95",
      "id": "CVE-2026-48523",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48523 is fixed in version 2.10.1.post2+tuxcare of pyjwt."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d248b02-5006-5ea5-85f9-1c121d707d1d",
      "id": "CVE-2026-48524",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48524 is fixed in version 2.10.1.post2+tuxcare of pyjwt."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae2fec6c-70b2-584f-be82-1e70147db8b2",
      "id": "CVE-2026-48525",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48525 is fixed in version 2.10.1.post2+tuxcare of pyjwt."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04063afd-d45f-520a-9134-9be279f70c0a",
      "id": "CVE-2026-48526",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48526 is fixed in version 2.10.1.post2+tuxcare of pyjwt."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3413c2d8-e5a9-561f-8950-1dacf2403e96",
      "id": "CVE-2024-24762",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-24762 is fixed in version 0.0.6.post5+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee68ebdd-0871-53c5-a526-90242a535513",
      "id": "CVE-2024-53981",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-53981 is fixed in version 0.0.6.post5+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7dc43e18-8d17-5ccc-b99a-5b5e1f9f319f",
      "id": "CVE-2026-24486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24486 affects version 0.0.6.post5+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d58abcbb-84a2-5588-8b49-8ab3d2706a68",
      "id": "CVE-2026-40347",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40347 is fixed in version 0.0.6.post5+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e4eff8a-e540-5296-86dd-6de675af8467",
      "id": "CVE-2026-42561",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42561 affects version 0.0.6.post5+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d59a07b8-6be4-5ff1-886b-87181a3c45e4",
      "id": "CVE-2026-53537",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-53537 is fixed in version 0.0.6.post5+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f54c3af-8e6a-59bc-b2a0-78e52d1cba83",
      "id": "CVE-2026-53538",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-53538 is fixed in version 0.0.6.post5+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4fd7e19-4569-56ed-9733-dbdf5676a7bd",
      "id": "CVE-2026-53539",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53539 affects version 0.0.6.post5+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bcea74c0-2342-51b6-b470-3f5e2d565adb",
      "id": "CVE-2026-53540",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-53540 is fixed in version 0.0.6.post5+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:376a67c4-f10f-567c-b08b-52f44f24ec60",
      "id": "CVE-2025-55197",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55197 is fixed in version 5.9.0.post8+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72f63cc2-969c-5205-8b83-ad01296c1015",
      "id": "CVE-2025-62707",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-62707 is fixed in version 5.9.0.post8+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4806193c-a3ec-58a7-8a03-6387210316d7",
      "id": "CVE-2025-62708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-62708 is fixed in version 5.9.0.post8+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a99b95e-a892-5523-bad2-5c60b236d3a2",
      "id": "CVE-2025-66019",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66019 affects version 5.9.0.post8+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eedf161e-42c8-5b13-9dfc-f719cd0dfcd1",
      "id": "CVE-2026-22690",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22690 affects version 5.9.0.post8+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10b0635f-a94a-560f-8478-954081156b88",
      "id": "CVE-2026-22691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22691 affects version 5.9.0.post8+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7428ccb-8229-5d24-b09b-42f96c6ec7b6",
      "id": "CVE-2026-24688",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24688 affects version 5.9.0.post8+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12e28abc-a30c-5317-9e9d-bc00d3a5ab4b",
      "id": "CVE-2026-27024",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27024 affects version 5.9.0.post8+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7937c07d-961b-50d8-9a78-bc310abe1187",
      "id": "CVE-2026-27025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27025 affects version 5.9.0.post8+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9b4ab2b-31dd-5bd8-b69d-4598750c5a2f",
      "id": "CVE-2026-27026",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27026 affects version 5.9.0.post8+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb35fa2f-76b5-5605-b480-7be7bd8a1155",
      "id": "CVE-2026-27628",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27628 is fixed in version 5.9.0.post8+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:192114aa-f465-5d77-a986-9857c59ff7cb",
      "id": "CVE-2026-27888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27888 affects version 5.9.0.post8+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a85d619f-3b2d-529e-bd47-a96923fd094a",
      "id": "CVE-2026-28351",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-28351 affects version 5.9.0.post8+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d01183d6-be38-5665-9ac8-7fbf8862fd1a",
      "id": "CVE-2026-28804",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-28804 affects version 5.9.0.post8+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:159a7006-a07e-55cd-a0d3-0b152e8b6e10",
      "id": "CVE-2026-31826",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-31826 affects version 5.9.0.post8+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eeafee3e-262b-5b4a-856f-ff66f9d6893d",
      "id": "CVE-2026-33123",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33123 affects version 5.9.0.post8+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56344f1c-3a94-5dad-8a50-4ef7b39b282a",
      "id": "CVE-2026-33699",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33699 affects version 5.9.0.post8+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20fa288e-b656-56bd-830b-a1bd309227f2",
      "id": "CVE-2026-40260",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40260 affects version 5.9.0.post8+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:046239f1-9b6e-5acb-9d9a-b9f465754adb",
      "id": "CVE-2026-41168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41168 is fixed in version 5.9.0.post8+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:853acf8f-1933-5afa-b71a-83d3334c9718",
      "id": "CVE-2026-41312",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41312 is fixed in version 5.9.0.post8+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a84ab33-061e-55f0-accc-85610713e3a5",
      "id": "CVE-2026-41313",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41313 is fixed in version 5.9.0.post8+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:826755bd-bdbe-5cbb-a55a-eb0391ff3867",
      "id": "CVE-2026-41314",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41314 is fixed in version 5.9.0.post8+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34cd6ec2-7f92-582e-b563-d849beada371",
      "id": "CVE-2026-48155",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48155 affects version 5.9.0.post8+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52221e26-538f-5340-9fb5-e7f78a473a49",
      "id": "CVE-2026-48156",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48156 is fixed in version 5.9.0.post8+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:071e37a6-a2b3-58fa-8bdd-ddb5f4cc1c34",
      "id": "CVE-2026-48735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48735 affects version 5.9.0.post8+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0c6de41-09c2-5e75-bc56-0acd7b92351a",
      "id": "CVE-2026-49460",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49460 is fixed in version 5.9.0.post8+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c37ca8e4-e75d-5c66-b4b8-c41d57b45454",
      "id": "CVE-2026-49461",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49461 is fixed in version 5.9.0.post8+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0713829-839a-5240-8587-0ffa8ee2c7f0",
      "id": "CVE-2026-54530",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54530 affects version 5.9.0.post8+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6361a864-f55b-5b85-8846-8871f5f851fe",
      "id": "CVE-2026-54531",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54531 affects version 5.9.0.post8+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2351111b-5cf4-585e-ac90-6c2e0363ad96",
      "id": "CVE-2026-54651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54651 affects version 5.9.0.post8+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f2839af-c25d-51b2-b6a3-b91e7f3eebe0",
      "id": "CVE-2026-59935",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59935 affects version 5.9.0.post8+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bf4e24c-aaa4-587a-aab5-a602573a6f9d",
      "id": "CVE-2026-59936",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59936 affects version 5.9.0.post8+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:658a6bf1-88e5-536a-bd17-b0b98cccd1d8",
      "id": "CVE-2026-59937",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59937 affects version 5.9.0.post8+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:141047c4-bdd4-5b7e-9e0c-c33e4bbd3ad4",
      "id": "CVE-2026-59938",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59938 affects version 5.9.0.post8+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f066c11-ed39-5ab5-98be-b75897194c68",
      "id": "GHSA-4pxv-j86v-mhcw",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post8+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:217efcbd-233f-55e9-b4c7-65583ffc5191",
      "id": "GHSA-7gw9-cf7v-778f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post8+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55b3e52d-c739-5af7-9d5d-525afe760f00",
      "id": "GHSA-9m86-7pmv-2852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post8+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4edac9e3-a437-5053-898b-1a6d4936927b",
      "id": "GHSA-jj6c-8h6c-hppx",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post8+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46e6b17a-d204-590e-ad8d-7ea1d85007a6",
      "id": "GHSA-jm82-fx9c-mx94",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-jm82-fx9c-mx94 affects version 5.9.0.post8+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3796bda-5799-55bc-b01d-23badcb22f8d",
      "id": "GHSA-x284-j5p8-9c5p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-x284-j5p8-9c5p affects version 5.9.0.post8+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08a1ca54-ac90-572a-bfee-b6d151719a27",
      "id": "CVE-2024-47874",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47874 is fixed in version 0.27.0.post5+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f1ab58a-2573-56e4-b757-3548d5db8c14",
      "id": "CVE-2025-54121",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-54121 is fixed in version 0.27.0.post5+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07bffb31-d3f1-5cf6-adb6-060798c4e810",
      "id": "CVE-2025-62727",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-62727 does not affect version 0.27.0.post5+tuxcare of starlette. Version 0.27.0 is not vulnerable. Summary: The target repository (Starlette version 0.27.0) is NOT vulnerable to CVE-2025-62727. The vulnerable Range header parsing logic was introduced in version 0.39.0, and the target version 0.27.0 predates this introduction. The FileResponse class in version 0.27.0 does not implement any Range header parsing or processing functionality. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef2b987e-b472-56ba-afe8-b25f90b8688c",
      "id": "CVE-2026-48710",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48710 is fixed in version 0.27.0.post5+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f130fce4-016f-59ce-bfae-e6588dfd1bc3",
      "id": "CVE-2026-48817",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48817 is fixed in version 0.27.0.post5+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebbb82e6-cd27-59f1-8579-d7f1d59946fc",
      "id": "CVE-2026-48818",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48818 is fixed in version 0.27.0.post5+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afdbe96a-32f3-544b-829a-4ee4881768e0",
      "id": "CVE-2026-54282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54282 affects version 0.27.0.post5+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd686d26-45e0-5981-b413-7fd9adc7c5df",
      "id": "CVE-2026-54283",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54283 is fixed in version 0.27.0.post5+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c780349b-b9ef-563f-99b8-2af6314b847c",
      "id": "GHSA-93gm-qmq6-w238",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-93gm-qmq6-w238 is a false positive for starlette 0.27.0.post5+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b16c0d8b-f7c3-506e-9323-927fbc6f0659",
      "id": "CVE-2021-33503",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-33503 is fixed in version 1.25.11.post6+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92408a21-ee8e-5147-a12a-a99056e982df",
      "id": "CVE-2023-43804",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-43804 is fixed in version 1.25.11.post6+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4daa292-589d-59dd-a6b0-d070f52437da",
      "id": "CVE-2023-45803",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45803 is fixed in version 1.25.11.post6+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3d03cf0-5f6e-5ab4-8728-d9c258118746",
      "id": "CVE-2024-37891",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-37891 is fixed in version 1.25.11.post6+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e713a88-9be2-5238-b172-e3639e3a5529",
      "id": "CVE-2025-50181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-50181 is fixed in version 1.25.11.post6+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf8d7a70-d6fc-5744-822f-20c4c30d9843",
      "id": "CVE-2025-66418",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66418 is fixed in version 1.25.11.post6+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0d33786-becb-54b7-8dd7-3d5fdd2b2970",
      "id": "CVE-2025-66471",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66471 is fixed in version 1.25.11.post6+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6387ead4-5fc0-5f1d-a703-409cf0e0e8a4",
      "id": "CVE-2026-21441",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-21441 affects version 1.25.11.post6+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47e9a1f8-26c4-5d06-b83c-f3698d75da8c",
      "id": "CVE-2026-44431",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44431 is fixed in version 1.25.11.post6+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:050c8745-b7b4-545e-93c4-eab1a4f115a6",
      "id": "CVE-2025-55197",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55197 is fixed in version 5.9.0.post7+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:312cdcf7-316c-5f3e-8221-8e72103e8672",
      "id": "CVE-2025-62707",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-62707 is fixed in version 5.9.0.post7+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5f131b6-2120-55cc-86d8-79a79533a82c",
      "id": "CVE-2025-62708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-62708 is fixed in version 5.9.0.post7+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b751dd29-e58d-5927-993a-154d18fbba3c",
      "id": "CVE-2025-66019",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66019 affects version 5.9.0.post7+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d70610be-1d5e-5312-ae27-6526b4abc103",
      "id": "CVE-2026-22690",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22690 affects version 5.9.0.post7+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6fa7af2-2b91-5fb6-9851-41e9cf4a62dc",
      "id": "CVE-2026-22691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22691 affects version 5.9.0.post7+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0376041-fe33-56ec-a3b3-d0aac4cd43c6",
      "id": "CVE-2026-24688",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24688 affects version 5.9.0.post7+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd15dccc-b079-54a9-9569-3bb3d3ca1d4f",
      "id": "CVE-2026-27024",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27024 affects version 5.9.0.post7+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:613bf850-872c-5ad7-8b74-fe81f5e4951f",
      "id": "CVE-2026-27025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27025 affects version 5.9.0.post7+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61820f13-abaa-56de-911a-f33df663509b",
      "id": "CVE-2026-27026",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27026 affects version 5.9.0.post7+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9089653a-d786-58c2-a492-32b723dbc764",
      "id": "CVE-2026-27628",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27628 is fixed in version 5.9.0.post7+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71c71dcc-b08f-54a4-8dcc-766038bc0ec3",
      "id": "CVE-2026-27888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27888 affects version 5.9.0.post7+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c91441be-2f91-53a0-85ca-dcb6d11101dd",
      "id": "CVE-2026-28351",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-28351 affects version 5.9.0.post7+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a3cf27f-922d-506e-a22e-9769d81c4d4f",
      "id": "CVE-2026-28804",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-28804 affects version 5.9.0.post7+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7797b873-7b6a-5cd5-8a51-b92337ecffee",
      "id": "CVE-2026-31826",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-31826 affects version 5.9.0.post7+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:572f2a55-670c-5239-9749-79250feb1bef",
      "id": "CVE-2026-33123",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33123 affects version 5.9.0.post7+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd519a77-dbd9-5028-9f31-4d7d15625637",
      "id": "CVE-2026-33699",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33699 affects version 5.9.0.post7+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3bd179d-bf55-5eaf-8075-cb4aeda15b6b",
      "id": "CVE-2026-40260",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40260 affects version 5.9.0.post7+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1d60d68-1fc6-5ef8-8e7e-1f5adc9a7ab4",
      "id": "CVE-2026-41168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41168 is fixed in version 5.9.0.post7+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ee10411-a9db-5973-800d-0b2b7f4f3b9f",
      "id": "CVE-2026-41312",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41312 is fixed in version 5.9.0.post7+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:514a1b3d-3d0a-53a2-b585-a2f75b069dda",
      "id": "CVE-2026-41313",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41313 is fixed in version 5.9.0.post7+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c49d5a9b-b7f9-5159-a621-dc3a584a1159",
      "id": "CVE-2026-41314",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41314 is fixed in version 5.9.0.post7+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8631d248-46de-5b4c-b088-1300d4c86a8f",
      "id": "CVE-2026-48155",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48155 affects version 5.9.0.post7+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b5715da-192c-5b81-8547-65ddf8e097c9",
      "id": "CVE-2026-48156",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48156 is fixed in version 5.9.0.post7+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a26ed12-5558-588a-9a20-fbf9682460e0",
      "id": "CVE-2026-48735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48735 affects version 5.9.0.post7+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eda49bc6-f745-5325-8965-fb6ef4cfbeb1",
      "id": "CVE-2026-49460",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49460 is fixed in version 5.9.0.post7+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00dfb7b4-cc0a-5ff6-bd6a-3420833d4f0c",
      "id": "CVE-2026-49461",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49461 affects version 5.9.0.post7+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47543372-659f-58ed-8756-17a78c5ed797",
      "id": "CVE-2026-54530",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54530 affects version 5.9.0.post7+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b382a1e5-b106-5dbf-bdd7-b50d33928912",
      "id": "CVE-2026-54531",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54531 affects version 5.9.0.post7+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb458a21-deda-5b73-ba29-7511f9115429",
      "id": "CVE-2026-54651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54651 affects version 5.9.0.post7+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f08e0c71-a284-5d0a-a887-608828abb9dd",
      "id": "CVE-2026-59935",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59935 affects version 5.9.0.post7+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72a89dca-efd0-50f2-98f2-1347abed4ce4",
      "id": "CVE-2026-59936",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59936 affects version 5.9.0.post7+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00d028bb-888f-51bd-91b5-2165324d3fe8",
      "id": "CVE-2026-59937",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59937 affects version 5.9.0.post7+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9dd000be-fe20-52cd-8f88-4590d8debe5e",
      "id": "CVE-2026-59938",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59938 affects version 5.9.0.post7+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a80209bc-39e2-5d05-930b-096a2dc556f0",
      "id": "GHSA-4pxv-j86v-mhcw",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post7+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c54d143b-2e81-5ef4-84d8-c7917d31351a",
      "id": "GHSA-7gw9-cf7v-778f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post7+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5bea9222-77ce-57e5-b837-2b59de95cb3d",
      "id": "GHSA-9m86-7pmv-2852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post7+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4969cbd3-9051-5647-8046-c757d517205b",
      "id": "GHSA-jj6c-8h6c-hppx",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post7+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2906c8c1-258f-58a0-825b-d2dc55bfb6f5",
      "id": "GHSA-jm82-fx9c-mx94",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-jm82-fx9c-mx94 affects version 5.9.0.post7+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc47992a-80ec-5e55-9ba1-f872f0e26159",
      "id": "GHSA-x284-j5p8-9c5p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-x284-j5p8-9c5p affects version 5.9.0.post7+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8b79dba-c38f-5f55-a544-d1566652cbb7",
      "id": "CVE-2024-47874",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47874 is fixed in version 0.27.0.post4+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:067a8e82-5878-5a18-a002-333114f92dae",
      "id": "CVE-2025-54121",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-54121 is fixed in version 0.27.0.post4+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4f77041-3469-59e1-8d95-40dcc7088924",
      "id": "CVE-2025-62727",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-62727 does not affect version 0.27.0.post4+tuxcare of starlette. Version 0.27.0 is not vulnerable. Summary: The target repository (Starlette version 0.27.0) is NOT vulnerable to CVE-2025-62727. The vulnerable Range header parsing logic was introduced in version 0.39.0, and the target version 0.27.0 predates this introduction. The FileResponse class in version 0.27.0 does not implement any Range header parsing or processing functionality. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5145c7e7-8d2b-53e4-9a91-3cf64a8a12eb",
      "id": "CVE-2026-48710",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48710 is fixed in version 0.27.0.post4+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58bfd745-50ef-56a8-8829-dab729cf040a",
      "id": "CVE-2026-48817",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48817 is fixed in version 0.27.0.post4+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c320cda8-8209-5a9a-ae34-59406495e1df",
      "id": "CVE-2026-48818",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48818 is fixed in version 0.27.0.post4+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5928e03e-0ee2-5be9-8c6f-a8c1f181b3fb",
      "id": "CVE-2026-54282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54282 affects version 0.27.0.post4+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3cb51ad8-9b8b-575c-8a0e-a812fe845b04",
      "id": "CVE-2026-54283",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54283 affects version 0.27.0.post4+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f49e5300-ceb6-5eb5-b5ba-592a7a0b833a",
      "id": "GHSA-93gm-qmq6-w238",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-93gm-qmq6-w238 is a false positive for starlette 0.27.0.post4+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:016198bb-182d-5f40-8424-365c7d9abc2f",
      "id": "CVE-2024-24762",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-24762 is fixed in version 0.0.6.post4+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bcd31e5c-e915-578c-9174-232cf41a04b0",
      "id": "CVE-2024-53981",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-53981 is fixed in version 0.0.6.post4+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83d902cd-b2bc-5031-9adb-f66b48a02344",
      "id": "CVE-2026-24486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24486 affects version 0.0.6.post4+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d348627a-6710-5800-8b0e-507270424f09",
      "id": "CVE-2026-40347",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40347 is fixed in version 0.0.6.post4+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:956786f3-f206-532a-9754-460415cd1472",
      "id": "CVE-2026-42561",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42561 affects version 0.0.6.post4+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5c67c78-f4a6-5ee3-a493-e9b6703439d6",
      "id": "CVE-2026-53537",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53537 affects version 0.0.6.post4+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:241188ef-5367-54ad-b03a-58bbb0274bdb",
      "id": "CVE-2026-53538",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53538 affects version 0.0.6.post4+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6413d63d-2139-599b-a183-86971dbf75af",
      "id": "CVE-2026-53539",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53539 affects version 0.0.6.post4+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80d26880-c95d-574b-a31c-e40d1a690a12",
      "id": "CVE-2026-53540",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-53540 is fixed in version 0.0.6.post4+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72d93721-2ca3-54d5-967d-4afcf8210269",
      "id": "AIKIDO-2024-10216",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2024-10216 is fixed in version 20.1.0.post3+tuxcare of gunicorn."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gunicorn@20.1.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0cd84795-94a8-58b3-8c5f-72b731f5550b",
      "id": "AIKIDO-2026-10742",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2026-10742 is fixed in version 20.1.0.post3+tuxcare of gunicorn."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gunicorn@20.1.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c09b1c9-7ef5-5908-80cf-0697180d2a64",
      "id": "CVE-2024-1135",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-1135 is fixed in version 20.1.0.post3+tuxcare of gunicorn."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gunicorn@20.1.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c325e5fd-0e96-5e48-b986-c9ab91dbdaa6",
      "id": "CVE-2024-6827",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6827 is fixed in version 20.1.0.post3+tuxcare of gunicorn."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gunicorn@20.1.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1babbd17-bd79-5a51-83bc-3b556b3075de",
      "id": "CVE-2024-7923",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-7923 is fixed in version 20.1.0.post3+tuxcare of gunicorn."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gunicorn@20.1.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d280298-50d5-5e82-9507-8b0b0ad77e01",
      "id": "CVE-2026-26007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-26007 is fixed in version 44.0.3.post2+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@44.0.3.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03f28759-52f0-5e2c-941f-804f92189465",
      "id": "CVE-2026-34073",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34073 affects version 44.0.3.post2+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@44.0.3.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:920c14c2-78ec-5d98-bbcb-c4cf8743592d",
      "id": "GHSA-537c-gmf6-5ccf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-537c-gmf6-5ccf is fixed in version 44.0.3.post2+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@44.0.3.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7c7aa31-ecc6-5059-90e2-be25e1997e50",
      "id": "AIKIDO-2026-10742",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2026-10742 is fixed in version 23.0.0.post1+tuxcare of gunicorn."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gunicorn@23.0.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fba0da2-f48b-5f44-8cf2-3ab09668fa64",
      "id": "GHSA-537c-gmf6-5ccf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-537c-gmf6-5ccf is fixed in version 46.0.7.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@46.0.7.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91eced14-9613-5926-97b7-4ef69f598f5c",
      "id": "CVE-2026-25990",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25990 is fixed in version 11.3.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ce104e8-1b44-5bfa-9e80-08ddb953f6af",
      "id": "CVE-2026-40192",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40192 is fixed in version 11.3.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c030a4b9-80f7-5c40-844e-f214e37ffbbf",
      "id": "CVE-2026-42308",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42308 affects version 11.3.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07099ac2-c7b0-5c02-ba7c-e34840fedb05",
      "id": "CVE-2026-42309",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42309 affects version 11.3.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b919a5a8-5a4a-5163-a3fa-351ef312f8d1",
      "id": "CVE-2026-42310",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42310 affects version 11.3.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53e747b7-14e3-5caa-bed8-1c8444b0e45b",
      "id": "CVE-2026-54058",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54058 affects version 11.3.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d7975b7-9bd9-5944-985c-7860d08a042b",
      "id": "CVE-2026-54059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54059 affects version 11.3.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e0b0b5e-9752-5f4f-88b1-fc7c2ccc3b9a",
      "id": "CVE-2026-54060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54060 affects version 11.3.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07dae9c6-e0ce-5bfc-b9b3-545e2e2d1088",
      "id": "CVE-2026-55379",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55379 affects version 11.3.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78d2448b-d9f8-59df-87f8-30b7b2616459",
      "id": "CVE-2026-55380",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55380 affects version 11.3.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9693728b-441a-5591-92c4-7d8cc0e4a62f",
      "id": "CVE-2026-55798",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55798 affects version 11.3.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b698f46-e1c2-5ffd-9cf4-8389a2ba1628",
      "id": "CVE-2026-59197",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59197 affects version 11.3.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f593aa3e-677f-56ff-8a55-308181247622",
      "id": "CVE-2026-59198",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59198 affects version 11.3.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22e23103-7b2a-5523-ac01-68664947bcc0",
      "id": "CVE-2026-59199",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59199 affects version 11.3.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39e199da-f5b2-5b02-9253-7cb494c187f3",
      "id": "CVE-2026-59200",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59200 affects version 11.3.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:272e5274-9f85-55c9-8fbd-fb26176dedac",
      "id": "CVE-2026-59204",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59204 affects version 11.3.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91c624eb-a9c0-5437-a002-7234d895a0fc",
      "id": "CVE-2026-59205",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59205 affects version 11.3.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6799c4d-237c-5fc7-939a-3bad81f41fb3",
      "id": "CVE-2024-34069",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34069 is fixed in version 2.3.8.post2+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@2.3.8.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc02182d-4064-501e-bec1-a61bf2143934",
      "id": "CVE-2024-49766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-49766 affects version 2.3.8.post2+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@2.3.8.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90570776-2d54-5127-b470-101b84050917",
      "id": "CVE-2024-49767",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-49767 affects version 2.3.8.post2+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@2.3.8.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:948da832-99fd-5af3-9037-0b0c156b4644",
      "id": "CVE-2025-66221",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66221 is fixed in version 2.3.8.post2+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@2.3.8.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:777063f8-54d6-5ea7-9cbf-b6bddd658b71",
      "id": "CVE-2026-21860",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-21860 affects version 2.3.8.post2+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@2.3.8.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e53a01f9-e641-5ec9-989b-e47aba3ba2ee",
      "id": "CVE-2026-27199",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27199 affects version 2.3.8.post2+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@2.3.8.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94a82b95-7904-5dfa-8710-2733c5dec2cc",
      "id": "CVE-2025-50181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-50181 is fixed in version 1.26.20.post4+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.20.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb9c543f-da5c-58db-a695-2a223b835ad8",
      "id": "CVE-2025-66418",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66418 is fixed in version 1.26.20.post4+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.20.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64549165-b514-5052-b8cf-01c331cb0271",
      "id": "CVE-2025-66471",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66471 is fixed in version 1.26.20.post4+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.20.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:200e6279-9abd-5a92-a1a4-89c2f2f440ee",
      "id": "CVE-2026-21441",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-21441 is fixed in version 1.26.20.post4+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.20.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84e6677e-9c3e-5b99-a27a-8f0952b256ee",
      "id": "CVE-2026-44431",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44431 is fixed in version 1.26.20.post4+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.20.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab252ac9-1aa4-5b4b-a1e6-3db9a1e8cde6",
      "id": "AIKIDO-2026-10495",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2026-10495 is fixed in version 20.39.1.post1+tuxcare of virtualenv."
      },
      "affects": [
        {
          "ref": "pkg:pypi/virtualenv@20.39.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3270a5ad-74eb-5998-b5d3-a8618a34bb58",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-49081 affects version 3.8.6.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63410774-9302-5feb-95bb-a8bc54d9b6bd",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49082 is fixed in version 3.8.6.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbb0abd9-ae4d-5e20-81e8-09c74a5f14df",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23334 affects version 3.8.6.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6cd1b29b-0c5d-5f66-9c0e-5be9387ccef9",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23829 affects version 3.8.6.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88c182f3-c01f-5288-a238-8268f7aedec7",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27306 affects version 3.8.6.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1ff4f8b-1042-5039-9bde-153e7c963fb7",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-30251 is fixed in version 3.8.6.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50fd3b73-a8fa-5c6f-a8c9-8742db102333",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52304 affects version 3.8.6.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:050574c3-3ef3-5be1-b5c6-faaa46a500b1",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-53643 affects version 3.8.6.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3de0c766-87f4-5fd0-a30c-0b3fb0ea2479",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.6.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47519f22-5ba6-5e75-a344-f8f52d3f718c",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.6.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd3a270e-9287-5a2b-be8d-c48280492805",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.6.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:513c00f3-827c-5f2c-b5a7-29d76fd4269d",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.6.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ece83d27-50bc-5e4e-a969-5b23c45da220",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.6.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86a45a1d-933e-57fc-98f9-c78110958142",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.6.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2745d3e-1a18-53ec-968e-3a62eb81a83b",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.6.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:facd2b6e-7b40-5287-b132-673619014af0",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.6.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fff0296f-00b6-51e2-b72d-a676e445bda0",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22815 is fixed in version 3.8.6.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76f06dab-57e9-5a15-983d-4ffe462206aa",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34513 is fixed in version 3.8.6.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26d67d30-c0ee-56f2-b560-aa9b3f07c6c4",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34514 is fixed in version 3.8.6.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d91d957e-7864-554b-9d1d-c70212006517",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.6.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a4d1c3d-4305-52ea-bfd7-92cae813f6bd",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34516 is fixed in version 3.8.6.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f99f4671-3660-572c-9f74-ee9b36c35d7e",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34517 is fixed in version 3.8.6.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbcb4a16-46ef-5023-9c1c-abd7cc43dc98",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34518 is fixed in version 3.8.6.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30d02463-443e-57d5-ba24-3f78ea9f91a9",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34519 is fixed in version 3.8.6.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:586e8d4a-7142-510d-aaaf-925a6bd95154",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34520 is fixed in version 3.8.6.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77c14a09-d309-5bfb-92ab-549aec37afc8",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34525 is fixed in version 3.8.6.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a0e1c16-c7c0-599f-9caa-742992602b55",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.6.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf3f1b4c-0f1f-58fe-ac44-b1feba03ecd1",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47265 is fixed in version 3.8.6.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aeb05a59-aa17-5381-9eed-a76f7bfca730",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.6.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e40b4e9-1546-551c-b7d1-fc7ef04cf7ca",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.6.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1f357a8-6276-5f59-815a-eee3185e2260",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.6.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:542766a7-5849-57ae-80ff-8b0e99cb4fa7",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.6.post6+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec6ffb77-b493-5913-948f-c748c18f9ad4",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.6.post6+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f9ccdce-a03b-5e6b-8259-1c63612390da",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.6.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba98dc38-06ff-53a7-b092-b1af75ae2215",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.6.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:570a4823-4a3a-56e6-9364-21233de5ba3a",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.6.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c54e2eac-fcf1-5736-909b-54f2e8b335ac",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.6.post6+tuxcare of aiohttp. Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ecf99105-ff00-5da5-aa51-085876249645",
      "id": "CVE-2023-28370",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28370 is fixed in version 6.1.0.post3+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc127c0f-a8e4-53dd-af7d-9b7288eb0edf",
      "id": "CVE-2024-52804",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52804 is fixed in version 6.1.0.post3+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:546b0563-19c9-53c6-bc6a-373dc1a4845e",
      "id": "CVE-2025-47287",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-47287 is fixed in version 6.1.0.post3+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a731af6-a449-514e-96b0-42af683f09fb",
      "id": "CVE-2025-67724",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67724 affects version 6.1.0.post3+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74ce7c5c-55bd-5efa-9f4b-c79fc50fc18a",
      "id": "CVE-2025-67725",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67725 affects version 6.1.0.post3+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df3792e6-835c-5a5a-aedb-a58fe4d36a60",
      "id": "CVE-2026-31958",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-31958 is fixed in version 6.1.0.post3+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:966948a7-5013-5336-9136-2f3b1c032a74",
      "id": "CVE-2026-35536",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-35536 is fixed in version 6.1.0.post3+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68514003-7ac4-549b-bfb2-5cd821cd9780",
      "id": "CVE-2026-49853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49853 affects version 6.1.0.post3+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7932b236-a12c-55ae-8586-26544b8913a7",
      "id": "CVE-2026-49854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49854 affects version 6.1.0.post3+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:530a0be3-21e0-5154-b187-2721b4ae5727",
      "id": "CVE-2026-49855",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-49855 is fixed in version 6.1.0.post3+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:782e8186-2e85-5f4e-a74a-428f3f5bffe8",
      "id": "GHSA-753j-mpmx-qq6g",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-753j-mpmx-qq6g is fixed in version 6.1.0.post3+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8dbea13e-6933-5c58-8532-38e6c6f94745",
      "id": "GHSA-78cv-mqj4-43f7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-78cv-mqj4-43f7 is fixed in version 6.1.0.post3+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ad3f47b-fdb6-5118-8b7e-13e02e46fa55",
      "id": "GHSA-pw6j-qg29-8w7f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-pw6j-qg29-8w7f affects version 6.1.0.post3+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6dfbbf58-f996-501e-949a-875ffc02542a",
      "id": "GHSA-qppv-j76h-2rpx",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-qppv-j76h-2rpx is fixed in version 6.1.0.post3+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:236644db-3fb5-5266-97dd-0b8c34afe797",
      "id": "GHSA-w235-7p84-xx57",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-w235-7p84-xx57 is fixed in version 6.1.0.post3+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1957ec06-f24b-573c-8979-84a95f1dceab",
      "id": "CVE-2025-48379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48379 is fixed in version 11.2.1.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.2.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fd7c0b1-bf49-50da-9827-66ce2d9ac4da",
      "id": "CVE-2026-25990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25990 affects version 11.2.1.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.2.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f19cfc5-e6e8-5666-8f46-f491d6001178",
      "id": "CVE-2026-40192",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40192 is fixed in version 11.2.1.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.2.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38f68606-620a-5c34-a2cf-5793b27fbff4",
      "id": "CVE-2026-42308",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42308 affects version 11.2.1.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.2.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db90712f-294c-5a06-8783-ce47f0181949",
      "id": "CVE-2026-42309",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42309 affects version 11.2.1.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.2.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61817fba-d868-5431-967f-447285c44b4d",
      "id": "CVE-2026-42310",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42310 affects version 11.2.1.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.2.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4802caf-4007-50d7-a2ab-59754c24a3c4",
      "id": "CVE-2026-42311",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42311 affects version 11.2.1.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.2.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca082fcd-773c-5e1d-9d8a-f019bb5250a0",
      "id": "CVE-2026-54058",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54058 affects version 11.2.1.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.2.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5dc028ec-b4f4-5d11-880d-cbc13c2627cb",
      "id": "CVE-2026-54059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54059 affects version 11.2.1.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.2.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e01a05c7-6aac-50cc-a97f-52cfdd6c44ce",
      "id": "CVE-2026-54060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54060 affects version 11.2.1.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.2.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96570388-ea3f-5067-a36b-817127bd8691",
      "id": "CVE-2026-55379",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55379 affects version 11.2.1.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.2.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3c65990-80a2-5b37-970b-7d7fb80bff98",
      "id": "CVE-2026-55380",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55380 affects version 11.2.1.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.2.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b608d7d-a7d2-555e-8f9f-5bd2bb92c014",
      "id": "CVE-2026-55798",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55798 affects version 11.2.1.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.2.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88b56afe-83a5-5b54-93aa-eff08b9c0579",
      "id": "CVE-2026-59197",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59197 affects version 11.2.1.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.2.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60f51e00-c93d-501c-b059-df5374a53c8d",
      "id": "CVE-2026-59198",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59198 affects version 11.2.1.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.2.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e876777-b113-587e-bce8-fbc7a18e2f9a",
      "id": "CVE-2026-59199",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59199 affects version 11.2.1.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.2.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd546a75-131f-54b0-bcbb-9bdc0cf45ccb",
      "id": "CVE-2026-59200",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59200 affects version 11.2.1.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.2.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23fbaa14-1939-5834-923b-9916abd50c87",
      "id": "CVE-2026-59204",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59204 affects version 11.2.1.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.2.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f47f1047-69ef-58ce-bfef-6e883c6adb2a",
      "id": "CVE-2026-59205",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59205 affects version 11.2.1.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.2.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ee5dc82-1128-59e4-9f17-3c26e9fca563",
      "id": "CVE-2025-55197",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55197 is fixed in version 5.9.0.post6+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47fec6ea-0d9c-546d-b41f-084b3b1c4848",
      "id": "CVE-2025-62707",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-62707 is fixed in version 5.9.0.post6+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f4fa9ea-986a-5f0b-b25f-7b9846026cd5",
      "id": "CVE-2025-62708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-62708 is fixed in version 5.9.0.post6+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c7755aa-8752-599a-adbb-32afa7edbf2d",
      "id": "CVE-2025-66019",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66019 affects version 5.9.0.post6+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9288bc89-78a2-54b3-96ac-6a0b37e53f35",
      "id": "CVE-2026-22690",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22690 affects version 5.9.0.post6+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b962553-3054-547a-8f91-6af7140a8d6d",
      "id": "CVE-2026-22691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22691 affects version 5.9.0.post6+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:681b4d64-d55b-51f5-b526-44691d42b03d",
      "id": "CVE-2026-24688",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24688 affects version 5.9.0.post6+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c434948f-f91d-5ee9-ab52-f81c07e938aa",
      "id": "CVE-2026-27024",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27024 affects version 5.9.0.post6+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2bfb2f9-ca90-5a94-ab18-f851cee7a1a0",
      "id": "CVE-2026-27025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27025 affects version 5.9.0.post6+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4671333b-f8f7-5f7e-935c-e08e7e5579b0",
      "id": "CVE-2026-27026",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27026 affects version 5.9.0.post6+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6d8d3c1-a2b7-5c98-bb4e-b42774147fdb",
      "id": "CVE-2026-27628",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27628 is fixed in version 5.9.0.post6+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03f3081a-318d-5afa-a11d-7af309b7a806",
      "id": "CVE-2026-27888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27888 affects version 5.9.0.post6+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa203a77-92c5-5d10-9264-04fb14c16b3a",
      "id": "CVE-2026-28351",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-28351 affects version 5.9.0.post6+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0466ef86-9864-57d3-86cb-bff7cd21f904",
      "id": "CVE-2026-28804",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-28804 affects version 5.9.0.post6+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1527761a-2433-50bd-8d4a-cbd0446c20c8",
      "id": "CVE-2026-31826",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-31826 affects version 5.9.0.post6+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61ae47fc-e533-581b-9e9e-718ee972f183",
      "id": "CVE-2026-33123",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33123 affects version 5.9.0.post6+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4394697-51f6-5a93-a131-caea99759c74",
      "id": "CVE-2026-33699",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33699 affects version 5.9.0.post6+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49240f4d-b85c-5133-9ade-3f06149feea3",
      "id": "CVE-2026-40260",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40260 affects version 5.9.0.post6+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b932a841-0830-5952-9ebf-f98a21550ebe",
      "id": "CVE-2026-41168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41168 is fixed in version 5.9.0.post6+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8db99d35-5775-5e7a-920d-4f52423b52d4",
      "id": "CVE-2026-41312",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41312 is fixed in version 5.9.0.post6+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e405fb41-2b2c-5544-b673-dc47baca73cf",
      "id": "CVE-2026-41313",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41313 is fixed in version 5.9.0.post6+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ecb1dbb0-5039-5994-b0a6-aae0455a2d98",
      "id": "CVE-2026-41314",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41314 is fixed in version 5.9.0.post6+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f0075ab-b90f-5d36-bff1-e70e7aba149e",
      "id": "CVE-2026-48155",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48155 affects version 5.9.0.post6+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f5867da-fe8c-5f78-a99b-fe05efc78c5a",
      "id": "CVE-2026-48156",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48156 affects version 5.9.0.post6+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e975bd0-1005-5629-ada1-8aa33314b853",
      "id": "CVE-2026-48735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48735 affects version 5.9.0.post6+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:711f5a6a-92ff-5b0d-9c58-96fa996c091b",
      "id": "CVE-2026-49460",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49460 affects version 5.9.0.post6+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:815d9d33-e8a2-550b-8e28-eb88569f5f90",
      "id": "CVE-2026-49461",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49461 affects version 5.9.0.post6+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15ec715a-0bfc-50e4-a3db-2ebe435f3604",
      "id": "CVE-2026-54530",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54530 affects version 5.9.0.post6+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d24bb8b-f135-5ebd-b220-fbfb92b6ec32",
      "id": "CVE-2026-54531",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54531 affects version 5.9.0.post6+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd8ddb08-b311-5326-a2b0-84a3952d93a6",
      "id": "CVE-2026-54651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54651 affects version 5.9.0.post6+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a337e8ed-30f8-5078-9455-518d46cb357c",
      "id": "CVE-2026-59935",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59935 affects version 5.9.0.post6+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dba80f44-6581-50c9-92ee-e84c808bcf60",
      "id": "CVE-2026-59936",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59936 affects version 5.9.0.post6+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8d6992e-f4f6-5249-bfce-014fce3ace7e",
      "id": "CVE-2026-59937",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59937 affects version 5.9.0.post6+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24f5de1d-3e13-5cd8-b400-0aaa4c9a8b6c",
      "id": "CVE-2026-59938",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59938 affects version 5.9.0.post6+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c1616d0-aefd-5fea-9515-0c9fb5fe837e",
      "id": "GHSA-4pxv-j86v-mhcw",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post6+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:beae2978-e322-5618-b61b-90c211af6982",
      "id": "GHSA-7gw9-cf7v-778f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post6+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8b3db4f-45a1-57a4-94ae-ccb65c6d7e74",
      "id": "GHSA-9m86-7pmv-2852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post6+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb501a12-65e4-54d3-860b-dffd45d634b1",
      "id": "GHSA-jj6c-8h6c-hppx",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post6+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92286249-604d-55c7-a9c1-783c01cadfda",
      "id": "GHSA-jm82-fx9c-mx94",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-jm82-fx9c-mx94 affects version 5.9.0.post6+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c509f4b-93ba-5c57-a61f-42a85d459e8c",
      "id": "GHSA-x284-j5p8-9c5p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-x284-j5p8-9c5p affects version 5.9.0.post6+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eee21298-1140-58e8-a333-365f14c1a0e9",
      "id": "CVE-2023-48795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-48795 is fixed in version 3.0.0.post2+tuxcare of paramiko."
      },
      "affects": [
        {
          "ref": "pkg:pypi/paramiko@3.0.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e573ecb-cff0-5194-b77b-cf2487b1a551",
      "id": "CVE-2026-44405",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44405 is fixed in version 3.0.0.post2+tuxcare of paramiko."
      },
      "affects": [
        {
          "ref": "pkg:pypi/paramiko@3.0.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:072a96cf-dd8b-5a61-984f-5556f0297263",
      "id": "CVE-2025-65106",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-65106 affects version 0.3.83.post2+tuxcare of langchain-core."
      },
      "affects": [
        {
          "ref": "pkg:pypi/langchain-core@0.3.83.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d48ce457-096c-5578-9706-450b06f0c29c",
      "id": "CVE-2026-26013",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-26013 affects version 0.3.83.post2+tuxcare of langchain-core."
      },
      "affects": [
        {
          "ref": "pkg:pypi/langchain-core@0.3.83.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ab269fc-ee5e-5a99-9c38-883ec79518b5",
      "id": "CVE-2026-34070",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34070 is fixed in version 0.3.83.post2+tuxcare of langchain-core."
      },
      "affects": [
        {
          "ref": "pkg:pypi/langchain-core@0.3.83.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8cb1cb96-1a53-585f-a8ff-201fab0b1550",
      "id": "CVE-2026-44843",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-44843 is fixed in version 0.3.83.post2+tuxcare of langchain-core."
      },
      "affects": [
        {
          "ref": "pkg:pypi/langchain-core@0.3.83.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3ec54fd-8c01-5c8a-b359-ccf044511797",
      "id": "CVE-2024-24762",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-24762 is fixed in version 0.0.6.post3+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df0e8854-0d73-5541-9201-7a9a8a5242a4",
      "id": "CVE-2024-53981",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-53981 is fixed in version 0.0.6.post3+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3a22fcd-811e-56ce-9ac8-edbba3c6ed3c",
      "id": "CVE-2026-24486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24486 affects version 0.0.6.post3+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ba31470-cfdc-5fbd-83f9-769f5e9176e9",
      "id": "CVE-2026-40347",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40347 is fixed in version 0.0.6.post3+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61f30921-7162-59ae-aedb-7f8032a191b0",
      "id": "CVE-2026-42561",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42561 affects version 0.0.6.post3+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbd55459-54e6-55df-b16a-cb055ee050d8",
      "id": "CVE-2026-53537",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53537 affects version 0.0.6.post3+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:723108e6-8164-552f-87a9-7409737801a7",
      "id": "CVE-2026-53538",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53538 affects version 0.0.6.post3+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0d048a9-b8bf-54a2-a119-46e693cfe924",
      "id": "CVE-2026-53539",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53539 affects version 0.0.6.post3+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:552bf9cd-346d-5664-ad6c-1155dd93b325",
      "id": "CVE-2026-53540",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53540 affects version 0.0.6.post3+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4cb1c3b4-626b-596d-823c-8ce941c99dcf",
      "id": "AIKIDO-2026-10554",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2026-10554 is fixed in version 0.25.2.post4+tuxcare of dulwich."
      },
      "affects": [
        {
          "ref": "pkg:pypi/dulwich@0.25.2.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b55188d3-f5fa-5589-ac90-af4de14d5d82",
      "id": "CVE-2026-42305",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42305 is fixed in version 0.25.2.post4+tuxcare of dulwich."
      },
      "affects": [
        {
          "ref": "pkg:pypi/dulwich@0.25.2.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:151ce6b7-67ae-5bde-a303-711ee4822e8c",
      "id": "CVE-2026-42563",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42563 is fixed in version 0.25.2.post4+tuxcare of dulwich."
      },
      "affects": [
        {
          "ref": "pkg:pypi/dulwich@0.25.2.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47de35c0-e8e6-5afc-a104-9d54c09407c0",
      "id": "CVE-2026-47712",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47712 affects version 0.25.2.post4+tuxcare of dulwich."
      },
      "affects": [
        {
          "ref": "pkg:pypi/dulwich@0.25.2.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5bf2a51-304f-5fd5-a377-f0a39b8f0fce",
      "id": "CVE-2026-47734",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47734 is fixed in version 0.25.2.post4+tuxcare of dulwich."
      },
      "affects": [
        {
          "ref": "pkg:pypi/dulwich@0.25.2.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53883d95-cda3-5533-a801-39375d572174",
      "id": "CVE-2026-52726",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52726 affects version 0.25.2.post4+tuxcare of dulwich."
      },
      "affects": [
        {
          "ref": "pkg:pypi/dulwich@0.25.2.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38075cfc-eb5b-57c9-a29b-4470051d2629",
      "id": "CVE-2024-35195",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-35195 is fixed in version 2.31.0.post2+tuxcare of requests."
      },
      "affects": [
        {
          "ref": "pkg:pypi/requests@2.31.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e798d5c-347b-5988-850d-bf5c9224d255",
      "id": "CVE-2024-47081",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47081 is fixed in version 2.31.0.post2+tuxcare of requests."
      },
      "affects": [
        {
          "ref": "pkg:pypi/requests@2.31.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a73dea8c-0202-5bed-80c3-4a3fb295fbd1",
      "id": "CVE-2026-25645",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25645 is fixed in version 2.31.0.post2+tuxcare of requests."
      },
      "affects": [
        {
          "ref": "pkg:pypi/requests@2.31.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7cc02491-63fc-51d6-8036-c04f6a6d2be1",
      "id": "CVE-2025-55197",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55197 is fixed in version 5.9.0.post5+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef1a4cb3-5939-5181-944e-1886adc70c7a",
      "id": "CVE-2025-62707",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-62707 is fixed in version 5.9.0.post5+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4e8b8a6-b09e-5f77-8c16-a8de1fbb27fd",
      "id": "CVE-2025-62708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-62708 is fixed in version 5.9.0.post5+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6bbcdddb-0f31-58f2-8172-fc839859d65e",
      "id": "CVE-2025-66019",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66019 affects version 5.9.0.post5+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4b0ed6f-447c-54fb-9fc6-51c06cdc4ec4",
      "id": "CVE-2026-22690",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22690 affects version 5.9.0.post5+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:684011e3-3445-5d7e-8d6a-cc4951d3c7fc",
      "id": "CVE-2026-22691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22691 affects version 5.9.0.post5+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d18c820f-b891-5076-a1ee-251eb117ceee",
      "id": "CVE-2026-24688",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24688 affects version 5.9.0.post5+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02b58e27-a2d7-5781-939c-67cb1a4a841d",
      "id": "CVE-2026-27024",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27024 affects version 5.9.0.post5+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86191981-029b-5fd7-b93f-8cde6cf538d4",
      "id": "CVE-2026-27025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27025 affects version 5.9.0.post5+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:011aeea6-6edf-50fe-90da-661fbfc3093f",
      "id": "CVE-2026-27026",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27026 affects version 5.9.0.post5+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2385b72c-cb9d-5f1b-ad43-aa4d8fcaef34",
      "id": "CVE-2026-27628",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27628 is fixed in version 5.9.0.post5+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:018fccab-2ed1-5c69-8278-e3c174132d1f",
      "id": "CVE-2026-27888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27888 affects version 5.9.0.post5+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:224f28b8-901a-56b2-9e9f-d37810b5ff0c",
      "id": "CVE-2026-28351",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-28351 affects version 5.9.0.post5+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66f73b47-4e1f-5807-ad74-1a5ef57049b5",
      "id": "CVE-2026-28804",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-28804 affects version 5.9.0.post5+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:856fd14a-aa85-5f49-bfbc-37f955fe90d5",
      "id": "CVE-2026-31826",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-31826 affects version 5.9.0.post5+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:444c5f62-e096-56d6-89f1-9bc2de2cfec1",
      "id": "CVE-2026-33123",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33123 affects version 5.9.0.post5+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18eb934f-f76c-5a5d-a246-5a44af3d2d21",
      "id": "CVE-2026-33699",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33699 affects version 5.9.0.post5+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14395795-2de6-5f71-9091-bb2428c8d9af",
      "id": "CVE-2026-40260",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40260 affects version 5.9.0.post5+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7d65f5e-09a5-5452-907e-eeb0168504fa",
      "id": "CVE-2026-41168",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41168 affects version 5.9.0.post5+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5f358f4-991f-59e7-a505-28cafdff81f9",
      "id": "CVE-2026-41312",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41312 affects version 5.9.0.post5+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c68f1760-6011-5378-bf34-3d0072f76acb",
      "id": "CVE-2026-41313",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41313 is fixed in version 5.9.0.post5+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15ac5baa-a84e-526c-baec-7b37c9bdb933",
      "id": "CVE-2026-41314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41314 affects version 5.9.0.post5+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a785af7b-cb09-5e9e-89df-0864b38b5ad3",
      "id": "CVE-2026-48155",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48155 affects version 5.9.0.post5+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf0308df-e7a7-5369-b10e-7411db5c8f07",
      "id": "CVE-2026-48156",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48156 affects version 5.9.0.post5+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a8e357a-5309-5c34-a9d5-c2ee8a14f5ff",
      "id": "CVE-2026-48735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48735 affects version 5.9.0.post5+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f75fff6-a6ee-5f78-9995-df4149004630",
      "id": "CVE-2026-49460",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49460 affects version 5.9.0.post5+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b2d312e-808e-5af1-a3aa-b765844f4394",
      "id": "CVE-2026-49461",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49461 affects version 5.9.0.post5+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2476480d-d26a-532e-bcd4-04c882ca338e",
      "id": "CVE-2026-54530",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54530 affects version 5.9.0.post5+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d446aa50-ee1c-54a4-804c-b6f94a1362ce",
      "id": "CVE-2026-54531",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54531 affects version 5.9.0.post5+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e97d6f3-1396-59c5-b45a-e05a05b79745",
      "id": "CVE-2026-54651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54651 affects version 5.9.0.post5+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fc91885-2541-5c26-a84a-7c32209a499c",
      "id": "CVE-2026-59935",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59935 affects version 5.9.0.post5+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67e066e1-5e76-5703-b280-b5b856736d28",
      "id": "CVE-2026-59936",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59936 affects version 5.9.0.post5+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3da87084-550a-575a-8251-6799379793e0",
      "id": "CVE-2026-59937",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59937 affects version 5.9.0.post5+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4615fe7-509a-5e21-8ca0-b1caf12a559e",
      "id": "CVE-2026-59938",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59938 affects version 5.9.0.post5+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93aa1dae-0317-5dd0-a1fa-787ddbd5e327",
      "id": "GHSA-4pxv-j86v-mhcw",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post5+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1100f2a9-94e0-5823-b6f5-60aaa239771c",
      "id": "GHSA-7gw9-cf7v-778f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post5+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bbdac3c-61be-5a37-b386-c7f139654aae",
      "id": "GHSA-9m86-7pmv-2852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post5+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5bf4776b-ed3f-5e66-9fd6-f1bee360ff4f",
      "id": "GHSA-jj6c-8h6c-hppx",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post5+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb64fdfe-bdd2-5826-91a0-b2378003fdb7",
      "id": "GHSA-jm82-fx9c-mx94",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-jm82-fx9c-mx94 affects version 5.9.0.post5+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b20c38b2-782f-5817-a55f-5cb310da487e",
      "id": "GHSA-x284-j5p8-9c5p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-x284-j5p8-9c5p affects version 5.9.0.post5+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5abf155c-9889-54cf-b963-b624cbb2dbd6",
      "id": "AIKIDO-2026-10554",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2026-10554 is fixed in version 0.25.2.post3+tuxcare of dulwich."
      },
      "affects": [
        {
          "ref": "pkg:pypi/dulwich@0.25.2.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a21ddeb5-e138-54d3-8226-71fda7366205",
      "id": "CVE-2026-42305",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42305 is fixed in version 0.25.2.post3+tuxcare of dulwich."
      },
      "affects": [
        {
          "ref": "pkg:pypi/dulwich@0.25.2.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f071d529-a1b8-5ed4-af3b-c57ddcdae3a8",
      "id": "CVE-2026-42563",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42563 is fixed in version 0.25.2.post3+tuxcare of dulwich."
      },
      "affects": [
        {
          "ref": "pkg:pypi/dulwich@0.25.2.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1d935c3-096c-50cb-b042-1e7f6ba80785",
      "id": "CVE-2026-47712",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47712 affects version 0.25.2.post3+tuxcare of dulwich."
      },
      "affects": [
        {
          "ref": "pkg:pypi/dulwich@0.25.2.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78606c46-68df-5f1c-a5b7-c5f48d3a7d15",
      "id": "CVE-2026-47734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47734 affects version 0.25.2.post3+tuxcare of dulwich."
      },
      "affects": [
        {
          "ref": "pkg:pypi/dulwich@0.25.2.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51ed4503-076d-5766-8d97-babe1a48a3c3",
      "id": "CVE-2026-52726",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52726 affects version 0.25.2.post3+tuxcare of dulwich."
      },
      "affects": [
        {
          "ref": "pkg:pypi/dulwich@0.25.2.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89e5a85c-4cc2-56f8-8138-367345113a63",
      "id": "CVE-2023-47627",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-47627 is fixed in version 3.8.5.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:517fe24a-c080-5b51-935b-43a6dded8258",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49081 is fixed in version 3.8.5.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df4bb445-b41d-5010-90f6-39ede5582964",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49082 is fixed in version 3.8.5.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c07620be-0800-5afc-8e01-b09d05fa07ef",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23334 is fixed in version 3.8.5.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51095d14-024a-5e3b-834f-245dd39f24b1",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23829 is fixed in version 3.8.5.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a0052f6-fd8d-5739-b1cc-30be956cc607",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27306 affects version 3.8.5.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0955eaa-aa78-51e0-b93d-e39d8ec4ca56",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-30251 affects version 3.8.5.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b360fb1c-91cd-598a-82e7-64875bd1210b",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52304 is fixed in version 3.8.5.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0789bd54-3018-54c8-8fa1-07d4a5e16ec0",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-53643 affects version 3.8.5.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa63673a-0690-5ee3-9bee-0d94c5cefd10",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.5.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3ca63a4-6d01-5bbe-9675-99b5e83e307c",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.5.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c714609-d08d-5abe-9f65-2da4231403b3",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.5.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce49e816-5436-554a-a249-9620aeb6677e",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.5.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c8ae3ea-2f46-5e4f-b212-9c3f9e13da19",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.5.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1c68ff7-3a90-507c-a4ee-775fa53e551d",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.5.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec1f5935-b58e-55b7-a86a-74169dfc4c4f",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.5.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07cb3e38-6abd-509f-bea9-99c0f32fd713",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.5.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd565a45-1bc3-54ac-9ff9-7ab6fcefe58b",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22815 is fixed in version 3.8.5.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ac05439-a89f-5601-9f2a-a35749c97f1f",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34513 is fixed in version 3.8.5.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6c42752-4127-5291-82cd-1de155df461a",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34514 is fixed in version 3.8.5.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bfb073f-9e42-54d7-94c1-4ed9d21dc6db",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.5.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c17cae5-b5fb-564d-9677-74b03dabf2bb",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34516 is fixed in version 3.8.5.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02490d43-8473-5764-bbd5-c8b3536c86e9",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34517 is fixed in version 3.8.5.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbf941d6-34ed-5638-b8e6-691fcec903c8",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34518 is fixed in version 3.8.5.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bcfcffc-65d7-55a8-a915-1cb2891485ad",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34519 is fixed in version 3.8.5.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9b584b3-6526-548a-a7d8-3a7f7be1de2d",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34520 is fixed in version 3.8.5.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb0294d3-da79-57cc-bbe8-c03ad260bc3b",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34525 affects version 3.8.5.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f21ab033-1355-56d8-a835-f2802a2bd48d",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.5.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:999d0168-e66e-5364-8291-15431b026c3f",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.5.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff658453-7167-57ec-8a5f-f4abeadc5f29",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.5.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:544f33a5-23e9-5b13-88ca-bf29c09b430b",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.5.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cde98fd5-6c16-5a1b-9471-d5aba2d9e81e",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.5.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2cfff0b2-ab81-51f7-acfb-233c2bf6a13d",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.5.post9+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bead6039-ef84-5b7c-beca-24e00cca5431",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.5.post9+tuxcare of aiohttp. not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67f3e097-5294-5149-8fbf-c7f73796cbf9",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.5.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d697ff88-fe1f-5e5d-8db5-ffb3116b9087",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.5.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5040e0df-01c0-52d7-8b9a-73e66934f7cb",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.5.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:192905be-eec8-5696-a164-0aefb0e52d50",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.5.post9+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:333d9a82-223e-549b-bdf3-9eb5f2a05f85",
      "id": "GHSA-pjjw-qhg8-p2p9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.5.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ab63c3a-c78a-5222-abca-cfebe948ec2a",
      "id": "CVE-2023-32681",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-32681 is fixed in version 2.30.0.post2+tuxcare of requests."
      },
      "affects": [
        {
          "ref": "pkg:pypi/requests@2.30.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e02e950-7ded-5e2f-b7e6-4bb1711e0bb2",
      "id": "CVE-2024-35195",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-35195 is fixed in version 2.30.0.post2+tuxcare of requests."
      },
      "affects": [
        {
          "ref": "pkg:pypi/requests@2.30.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:828f3313-8a9e-5a0a-886c-d6d22a843eb7",
      "id": "CVE-2024-47081",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47081 is fixed in version 2.30.0.post2+tuxcare of requests."
      },
      "affects": [
        {
          "ref": "pkg:pypi/requests@2.30.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5604f1bc-f3cf-5d5e-b83f-217ace99dcf7",
      "id": "CVE-2026-25645",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25645 is fixed in version 2.30.0.post2+tuxcare of requests."
      },
      "affects": [
        {
          "ref": "pkg:pypi/requests@2.30.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96068f98-d857-51b1-8328-1c6190bbe515",
      "id": "CVE-2024-12797",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-12797 is a false positive for cryptography 45.0.7.post3+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@45.0.7.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4120564d-4995-5626-b90e-1b6bd741fce6",
      "id": "CVE-2026-26007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-26007 is fixed in version 45.0.7.post3+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@45.0.7.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78b99737-b41b-50ab-b674-981d75f1a340",
      "id": "CVE-2026-34073",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34073 is fixed in version 45.0.7.post3+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@45.0.7.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b08e794-8012-5a74-9433-0efef4539a04",
      "id": "CVE-2026-39892",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-39892 is fixed in version 45.0.7.post3+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@45.0.7.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8701440e-d8d6-5b53-a280-db4f305b06bd",
      "id": "GHSA-537c-gmf6-5ccf",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-537c-gmf6-5ccf does not affect version 45.0.7.post3+tuxcare of cryptography. not_affected \u2014 The source repository does not contain OpenSSL source code. The vulnerability (GHSA-537c-gmf6-5ccf) affects OpenSSL bundled in binary wheels distributed on PyPI, not the cryptography source code itself. OpenSSL is downloaded and compiled during the wheel build process via build_openssl.sh, not present in the repository."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@45.0.7.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b0f18b7-2452-53c7-886a-c865cb32c7e7",
      "id": "CVE-2021-34141",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-34141 is fixed in version 1.21.0.post1+tuxcare of numpy."
      },
      "affects": [
        {
          "ref": "pkg:pypi/numpy@1.21.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe271436-a1c5-5a5d-b2c2-0383407d7eea",
      "id": "CVE-2025-58367",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58367 is fixed in version 6.2.3.post2+tuxcare of deepdiff."
      },
      "affects": [
        {
          "ref": "pkg:pypi/deepdiff@6.2.3.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26e6cd2b-7b74-5a11-bc16-2d6ff91d3049",
      "id": "CVE-2026-33155",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-33155 is fixed in version 6.2.3.post2+tuxcare of deepdiff."
      },
      "affects": [
        {
          "ref": "pkg:pypi/deepdiff@6.2.3.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c0606b4-4f7f-537a-87f4-577812fb11cb",
      "id": "CVE-2024-6839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6839 affects version 4.0.2.post2+tuxcare of flask-cors."
      },
      "affects": [
        {
          "ref": "pkg:pypi/flask-cors@4.0.2.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdf965e3-ba37-5819-875b-763a82495194",
      "id": "CVE-2024-6844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6844 is fixed in version 4.0.2.post2+tuxcare of flask-cors."
      },
      "affects": [
        {
          "ref": "pkg:pypi/flask-cors@4.0.2.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02b3b6c2-b3fa-5818-957f-5dcc3603e359",
      "id": "CVE-2024-6866",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6866 is fixed in version 4.0.2.post2+tuxcare of flask-cors."
      },
      "affects": [
        {
          "ref": "pkg:pypi/flask-cors@4.0.2.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69fda830-31da-5840-abac-1e85ec4e5b09",
      "id": "CVE-2025-64340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64340 is fixed in version 2.14.7.post2+tuxcare of fastmcp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/fastmcp@2.14.7.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6f70ab5-82d1-5c61-b485-902b7e59113f",
      "id": "CVE-2026-27124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27124 is fixed in version 2.14.7.post2+tuxcare of fastmcp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/fastmcp@2.14.7.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88152a93-4549-5e21-b248-acda2136e970",
      "id": "CVE-2026-32871",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32871 is fixed in version 2.14.7.post2+tuxcare of fastmcp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/fastmcp@2.14.7.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6e0592a-0055-5fc7-af13-6c974caf5b20",
      "id": "CVE-2023-29159",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-29159 is fixed in version 0.13.6.post3+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.13.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02ad1ea8-6338-5d7c-8f5f-b4896c33787a",
      "id": "CVE-2023-30798",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-30798 is fixed in version 0.13.6.post3+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.13.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7569694e-daa0-5755-bb43-7276dbc08682",
      "id": "CVE-2024-47874",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47874 is fixed in version 0.13.6.post3+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.13.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b42bfec4-0bb1-56e6-b973-74a505daaa1a",
      "id": "CVE-2025-54121",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-54121 is fixed in version 0.13.6.post3+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.13.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1beeb0f5-b635-5e3e-8ce2-1fc6bb67981d",
      "id": "CVE-2025-62727",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-62727 affects version 0.13.6.post3+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.13.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3190cbc1-386d-5372-b11e-54ba48149207",
      "id": "CVE-2026-48710",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48710 affects version 0.13.6.post3+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.13.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abb72e03-b86b-5970-ab13-e0277f851424",
      "id": "CVE-2026-48817",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48817 affects version 0.13.6.post3+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.13.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46b57e97-221f-5a07-9c15-b2d1ef3e0b22",
      "id": "CVE-2026-48818",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48818 affects version 0.13.6.post3+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.13.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a317fa25-280c-52ee-b864-050e7c85a7b6",
      "id": "CVE-2026-54282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54282 affects version 0.13.6.post3+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.13.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc488c15-2c3c-58c8-b479-546a3a6ae843",
      "id": "CVE-2026-54283",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54283 affects version 0.13.6.post3+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.13.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:beb8875c-e77a-50bc-bd6b-cb21d6ce4cb0",
      "id": "GHSA-3qj8-93xh-pwh2",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-3qj8-93xh-pwh2 is a false positive for starlette 0.13.6.post3+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.13.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fe1a4b9-2c35-5fd4-8134-df817870fb75",
      "id": "GHSA-93gm-qmq6-w238",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-93gm-qmq6-w238 is fixed in version 0.13.6.post3+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.13.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ace08ff-930f-532c-8aa9-3a9b09f31a19",
      "id": "GHSA-qj8w-rv5x-2v9h",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-qj8w-rv5x-2v9h is a false positive for starlette 0.13.6.post3+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.13.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5537ecb1-43db-5d99-aadf-90c38022569c",
      "id": "CVE-2024-47874",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47874 is fixed in version 0.27.0.post3+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c6901b2-3df0-5b5c-9f9a-0eb9d7485954",
      "id": "CVE-2025-54121",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-54121 is fixed in version 0.27.0.post3+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ec2ff0a-3762-5a1f-9059-ede38a542439",
      "id": "CVE-2025-62727",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-62727 does not affect version 0.27.0.post3+tuxcare of starlette. Version 0.27.0 is not vulnerable. Summary: The target repository (Starlette version 0.27.0) is NOT vulnerable to CVE-2025-62727. The vulnerable Range header parsing logic was introduced in version 0.39.0, and the target version 0.27.0 predates this introduction. The FileResponse class in version 0.27.0 does not implement any Range header parsing or processing functionality. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cdf61494-6bcd-50f4-80ad-b9307584a005",
      "id": "CVE-2026-48710",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-48710 is fixed in version 0.27.0.post3+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff7bd94b-e7dc-5946-9aa8-f3336a242c66",
      "id": "CVE-2026-48817",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48817 affects version 0.27.0.post3+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d43eb590-4ce4-5dca-8dfd-622b6cdf90ab",
      "id": "CVE-2026-48818",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48818 affects version 0.27.0.post3+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40069c55-b309-5b4f-9965-da4450954942",
      "id": "CVE-2026-54282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54282 affects version 0.27.0.post3+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9b07f78-6b90-5250-8311-e49145a3acb0",
      "id": "CVE-2026-54283",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54283 affects version 0.27.0.post3+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5703a9ac-71f4-5fc3-bb74-68c464fcb07b",
      "id": "GHSA-93gm-qmq6-w238",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-93gm-qmq6-w238 is a false positive for starlette 0.27.0.post3+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:698e42a8-e38b-5701-af92-d835a24b10c4",
      "id": "AIKIDO-2026-10554",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2026-10554 is fixed in version 0.25.2.post2+tuxcare of dulwich."
      },
      "affects": [
        {
          "ref": "pkg:pypi/dulwich@0.25.2.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fdc739e6-fec4-596a-aa40-7d714edb2664",
      "id": "CVE-2026-42305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42305 affects version 0.25.2.post2+tuxcare of dulwich."
      },
      "affects": [
        {
          "ref": "pkg:pypi/dulwich@0.25.2.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ef3c700-e190-5e3b-8bf1-fb0286dc5619",
      "id": "CVE-2026-42563",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-42563 is fixed in version 0.25.2.post2+tuxcare of dulwich."
      },
      "affects": [
        {
          "ref": "pkg:pypi/dulwich@0.25.2.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e96e7f13-2c49-5ab4-8a42-72b60bba3fc7",
      "id": "CVE-2026-47712",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47712 affects version 0.25.2.post2+tuxcare of dulwich."
      },
      "affects": [
        {
          "ref": "pkg:pypi/dulwich@0.25.2.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33554b35-651e-5e0b-a9f2-a069069b44f7",
      "id": "CVE-2026-47734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47734 affects version 0.25.2.post2+tuxcare of dulwich."
      },
      "affects": [
        {
          "ref": "pkg:pypi/dulwich@0.25.2.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5ad4e2b-a0c6-53dc-8c4a-b41bba4e38d4",
      "id": "CVE-2026-52726",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52726 affects version 0.25.2.post2+tuxcare of dulwich."
      },
      "affects": [
        {
          "ref": "pkg:pypi/dulwich@0.25.2.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea46e15a-846d-505f-979c-bda552173221",
      "id": "CVE-2024-49768",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-49768 is fixed in version 2.1.2.post2+tuxcare of langgraph-checkpoint."
      },
      "affects": [
        {
          "ref": "pkg:pypi/langgraph-checkpoint@2.1.2.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c63293ee-c6e2-5056-83d1-0216a23fa3bd",
      "id": "CVE-2024-49769",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-49769 is fixed in version 2.1.2.post2+tuxcare of langgraph-checkpoint."
      },
      "affects": [
        {
          "ref": "pkg:pypi/langgraph-checkpoint@2.1.2.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2b16c55-a8f2-5145-8485-a087630e50a7",
      "id": "CVE-2025-64439",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64439 is fixed in version 2.1.2.post2+tuxcare of langgraph-checkpoint."
      },
      "affects": [
        {
          "ref": "pkg:pypi/langgraph-checkpoint@2.1.2.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c64edbf-9601-53b5-bf1b-a5893ee7fa9b",
      "id": "CVE-2026-27794",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27794 is fixed in version 2.1.2.post2+tuxcare of langgraph-checkpoint."
      },
      "affects": [
        {
          "ref": "pkg:pypi/langgraph-checkpoint@2.1.2.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8374ffb7-100e-5862-a745-1efa885bbd7d",
      "id": "CVE-2026-48775",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48775 affects version 2.1.2.post2+tuxcare of langgraph-checkpoint."
      },
      "affects": [
        {
          "ref": "pkg:pypi/langgraph-checkpoint@2.1.2.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56588b7d-b5d9-5810-983e-01a0aa26b15b",
      "id": "CVE-2024-37059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37059 affects version 2.22.4.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf2f66e6-c4e3-5cc1-9a56-21530daefb2e",
      "id": "CVE-2025-10279",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-10279 is fixed in version 2.22.4.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c52c4a20-c818-5bae-b1d3-766f94df3829",
      "id": "CVE-2025-14279",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-14279 is fixed in version 2.22.4.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b24a572-10c0-587f-b982-dfe1939e1a8e",
      "id": "CVE-2025-14287",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-14287 is fixed in version 2.22.4.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7410acf2-6282-54ba-95bc-fab292b8c9a5",
      "id": "CVE-2025-15031",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-15031 is fixed in version 2.22.4.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:577d9c6b-c802-5513-a1f0-29135c75f7c4",
      "id": "CVE-2025-15036",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-15036 does not affect version 2.22.4.post4+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b460f998-b05c-5ff9-867f-064141606e75",
      "id": "CVE-2025-15379",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-15379 affects version 2.22.4.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fdbd85c8-6557-5418-80c5-164ef6ff2492",
      "id": "CVE-2025-15381",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-15381 affects version 2.22.4.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:943493b9-b6c5-58c8-aaa3-09bad4f4cfc6",
      "id": "CVE-2026-0545",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-0545 does not affect version 2.22.4.post4+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81e4b415-2583-5ae7-88dd-0f7932565b54",
      "id": "CVE-2026-0596",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-0596 is fixed in version 2.22.4.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93e9924b-74e0-5d88-a40a-1b43e889c6d0",
      "id": "CVE-2026-10803",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10803 affects version 2.22.4.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1038bcd-466e-5cde-8ae6-13929d903ec7",
      "id": "CVE-2026-2033",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-2033 is fixed in version 2.22.4.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:370fbcbf-0fb1-55a8-b6e0-1adb154d1e88",
      "id": "CVE-2026-2393",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-2393 does not affect version 2.22.4.post4+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:727d17fe-ef20-570d-9ed2-a1c7ed1fa667",
      "id": "CVE-2026-2614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-2614 is fixed in version 2.22.4.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:026b7d43-00b9-538f-9e95-e6bae261a442",
      "id": "CVE-2026-2635",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-2635 is fixed in version 2.22.4.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34baa59d-0f98-54be-bcd8-6c39499651dc",
      "id": "CVE-2026-2651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2651 affects version 2.22.4.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0bd0b6d8-1ee7-5a5e-b480-0415b9d5ac35",
      "id": "CVE-2026-2652",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-2652 does not affect version 2.22.4.post4+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9150bc1b-9203-53a2-9c11-6e49f420f4be",
      "id": "CVE-2026-2734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2734 affects version 2.22.4.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7d686f6-eeda-5dd2-a15d-21e04b4c5a14",
      "id": "CVE-2026-3198",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-3198 does not affect version 2.22.4.post4+tuxcare of mlflow. not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8c50872-4962-5cfb-a059-6111d2345edb",
      "id": "CVE-2026-33865",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33865 affects version 2.22.4.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1db728a4-2bd1-5ad9-9a27-672e2243e294",
      "id": "CVE-2026-33866",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33866 does not affect version 2.22.4.post4+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5693ed2-13a9-5871-8d8c-aaba781368d6",
      "id": "CVE-2026-4035",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-4035 affects version 2.22.4.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0909fd1-3014-5eef-8514-5ca2e841c1c7",
      "id": "CVE-2026-4137",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-4137 is fixed in version 2.22.4.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:298bdaba-c633-5031-8506-9f3cff321eab",
      "id": "CVE-2024-47081",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47081 is fixed in version 2.32.3.post2+tuxcare of requests."
      },
      "affects": [
        {
          "ref": "pkg:pypi/requests@2.32.3.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f17de22-de51-5e2b-8021-c91de7191fb7",
      "id": "CVE-2026-25645",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25645 is fixed in version 2.32.3.post2+tuxcare of requests."
      },
      "affects": [
        {
          "ref": "pkg:pypi/requests@2.32.3.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c441e7d0-64db-5493-828f-b7a08839e2bf",
      "id": "CVE-2023-6709",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-6709 is fixed in version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10fa3b67-86da-5fc1-a817-dde32f27e6a2",
      "id": "CVE-2023-6753",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-6753 is fixed in version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:700057c4-c37f-5241-a1d9-42fe276dbf41",
      "id": "CVE-2023-6831",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-6831 affects version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11cc4c65-dc9e-57bb-8c6e-5c709d27f57c",
      "id": "CVE-2023-6909",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-6909 is fixed in version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18f0d82f-918c-5db4-ba90-8dea621b0ee4",
      "id": "CVE-2023-6940",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-6940 affects version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25f990f8-2ead-5a90-96b0-046c9558b798",
      "id": "CVE-2023-6974",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-6974 is fixed in version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b598b923-5b50-5f65-bd4f-a94965f2f339",
      "id": "CVE-2023-6975",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-6975 is fixed in version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86f07185-f6ee-5fc5-8968-4cfc36900f92",
      "id": "CVE-2023-6976",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-6976 affects version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88cf94d0-e249-58f5-863e-ad6c16aa4992",
      "id": "CVE-2023-6977",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-6977 affects version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6288a205-6a66-502f-b913-7d8d72bcfd70",
      "id": "CVE-2024-1483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-1483 affects version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f92e32ae-c2fe-56a5-bbf2-929aea611155",
      "id": "CVE-2024-1558",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-1558 affects version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84bb895e-3d8d-5e29-b69b-9190f6216589",
      "id": "CVE-2024-1560",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-1560 affects version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60dfa3af-cd2d-547d-a652-8156b2415450",
      "id": "CVE-2024-1593",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-1593 is fixed in version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51e709ce-b678-5a51-adf7-e646de891460",
      "id": "CVE-2024-1594",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-1594 affects version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33e01053-b0e0-56c0-8b30-c2ca2501ca58",
      "id": "CVE-2024-27132",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-27132 is fixed in version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a1d5e28-d859-5626-97a5-d003d773d224",
      "id": "CVE-2024-27133",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-27133 is fixed in version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21031469-f0b9-54d0-a55c-096292a5d428",
      "id": "CVE-2024-27134",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-27134 is fixed in version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b068a72b-b3e8-5a08-9ad8-99ef46d38b47",
      "id": "CVE-2024-2928",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-2928 is fixed in version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24d72d83-30f9-5747-b8df-351c4e8fe816",
      "id": "CVE-2024-3099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-3099 affects version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44edffc1-e011-5824-b131-374276645f9b",
      "id": "CVE-2024-3573",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-3573 is fixed in version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b91173a2-f501-53b6-ade8-2eaa66cfa297",
      "id": "CVE-2024-37052",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-37052 does not affect version 2.9.1.post4+tuxcare of mlflow. already_fixed \u2014 The target MLflow 2.9.1 codebase contains the fix for CVE-2024-37052 (unsafe pickle deserialization in scikit-learn model loading). The MLFLOW_ALLOW_PICKLE_DESERIALIZATION environment variable check was added in prior TuxCare backports (commits d58ee98ca for initial guard, 98a32847a for CVE-2024-37056, cf8bc9c26 for CVE-2024-37053). However, the defense defaults to True (allowing deserializatio..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1fb642ff-d656-57f0-a51e-bd1637fe522c",
      "id": "CVE-2024-37053",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-37053 is fixed in version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:194fa65b-fbf1-5c3c-ba72-4ffb9d84b35e",
      "id": "CVE-2024-37054",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37054 affects version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f36373e-8cf1-56b2-ac6b-2d8601ec42dc",
      "id": "CVE-2024-37055",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-37055 is fixed in version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5112940f-3c1b-5e6c-bb6b-99adf7da14e5",
      "id": "CVE-2024-37056",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-37056 is fixed in version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ef55ea9-5a4d-51a7-a466-3066540bf1f3",
      "id": "CVE-2024-37057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37057 affects version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:383bd45d-bc4a-5e18-a21d-350135c8aab4",
      "id": "CVE-2024-37058",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37058 affects version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c6c8196-6f63-585f-bc9e-c71b7f7d169a",
      "id": "CVE-2024-37059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37059 affects version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:505b0755-6b17-559c-ab97-18428ddf4be4",
      "id": "CVE-2024-37060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37060 affects version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46d6a49a-1898-5fe4-ba92-8cb218e8cbcb",
      "id": "CVE-2024-37061",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37061 affects version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a6a10e9-d604-593d-a08a-65563a8880f7",
      "id": "CVE-2024-4263",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-4263 affects version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b01f52ae-8e90-512a-9fd9-2f40c50f1410",
      "id": "CVE-2024-6838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6838 is fixed in version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:596484a7-596b-5894-a85e-fce94fc3d5ee",
      "id": "CVE-2024-8859",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-8859 is fixed in version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:775cf943-81c2-5447-8939-3832de9e0a0b",
      "id": "CVE-2025-0453",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-0453 affects version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6fc4a600-1085-57e7-b60c-8a12435dafc7",
      "id": "CVE-2025-10279",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-10279 is fixed in version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c9f2437-2b5f-5d3e-a426-3963dc2fde61",
      "id": "CVE-2025-11200",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-11200 is fixed in version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dce351df-da2d-5f70-a7c5-1180687e4662",
      "id": "CVE-2025-11201",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-11201 is fixed in version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bdc1eb1-ccfe-5cd2-837a-6cb0e09f7a3c",
      "id": "CVE-2025-14279",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-14279 is fixed in version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60272f8a-937d-5268-80b3-41cc5d6fc597",
      "id": "CVE-2025-14287",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-14287 is fixed in version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:372a7494-fea5-56f4-810b-f158b12b8323",
      "id": "CVE-2025-1474",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-1474 affects version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5aef8b26-b1d5-5259-9528-a651777061bc",
      "id": "CVE-2025-15031",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-15031 affects version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dadcd5cd-f71a-5e8d-aaa3-65137fc8f2b1",
      "id": "CVE-2025-15036",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-15036 affects version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efd0c73a-7810-5252-8574-12d57b183412",
      "id": "CVE-2025-15379",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-15379 affects version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ad25432-e6ad-50de-8432-bb816c8a0913",
      "id": "CVE-2025-15381",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-15381 does not affect version 2.9.1.post4+tuxcare of mlflow. not_affected \u2014 MLflow version 2.9.1 does not contain tracing and assessment features. These features appear to have been introduced in a later version of mlflow. The vulnerability pattern described in CVE-2025-15381 (missing permission validators on tracing and assessment endpoints when basic-auth is enabled) cannot exist in a version that does not have these endpoints."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01bd7299-84dd-5c8f-9c1f-ff742d503cf7",
      "id": "CVE-2025-52967",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52967 is fixed in version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eaf29952-d8d9-56c3-8b9f-e6b83a5884b7",
      "id": "CVE-2026-0545",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-0545 affects version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06950008-612c-5b41-ae96-46523e17e366",
      "id": "CVE-2026-0596",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-0596 affects version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b698bc42-2a4f-55db-a293-8db4ed2b47bf",
      "id": "CVE-2026-10803",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10803 affects version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a073349e-b3ab-5acc-a441-cf62b18bd710",
      "id": "CVE-2026-2033",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-2033 is fixed in version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0cf5d0b8-2df3-559b-a673-758111eeecea",
      "id": "CVE-2026-2393",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2393 affects version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b36fd017-3f15-5aaa-875b-26864579e7ad",
      "id": "CVE-2026-2614",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-2614 does not affect version 2.9.1.post4+tuxcare of mlflow. Version 2.9.1 is not vulnerable. Summary: The target repository (MLflow v2.9.1.post4+tuxcare) does not contain the vulnerable code pattern described in CVE-2026-2614. The vulnerability was introduced in version 3.5.0 (September 2025) when prompt registry support was added to webhooks. The target version predates the introduction of the vulnerable feature by approximately 21 months."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d62246d-baab-5dbd-826d-5ea9db3cb613",
      "id": "CVE-2026-2635",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-2635 is fixed in version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9aeb6ea-ebd2-5d22-afc9-faa1ff654fe9",
      "id": "CVE-2026-2651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2651 affects version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5782404e-905e-58ff-9594-6aea3c01056a",
      "id": "CVE-2026-2652",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2652 affects version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7158e26c-a3d6-5c3a-aa28-b8741932d411",
      "id": "CVE-2026-2734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2734 affects version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04cd8acb-e993-581a-a3dd-3f2d8534dabc",
      "id": "CVE-2026-3198",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-3198 does not affect version 2.9.1.post4+tuxcare of mlflow. not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-3198. The vulnerability describes missing authorization checks for Gateway API list endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in MLflow 3.9.0's basic-auth integrated server. Version 2.9.1 has a fundamentally different architecture: the Gateway runs as a separate FastAPI application with no integration to the Fl..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bafdc6a7-be3e-57ce-a44d-d341ccfe35d1",
      "id": "CVE-2026-33865",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33865 affects version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f6a90a4-014f-5809-a94c-3e6695090420",
      "id": "CVE-2026-33866",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33866 affects version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e193bc3e-43cf-5080-8ea7-f965cab0dc3c",
      "id": "CVE-2026-4035",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-4035 affects version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6369e1ba-7d7d-5e3c-a86b-ce0e18d5f29d",
      "id": "CVE-2026-4137",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-4137 affects version 2.9.1.post4+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65775589-42be-5dd5-a07e-7a9d181aeb3c",
      "id": "CVE-2024-37059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37059 affects version 2.22.4.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32cbf3b5-e214-5b54-b08c-70189f4a971e",
      "id": "CVE-2025-10279",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-10279 is fixed in version 2.22.4.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f97da0a2-c53f-5b1e-8dcd-62ca646327c4",
      "id": "CVE-2025-14279",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-14279 is fixed in version 2.22.4.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13c8f309-7df7-51db-ae04-ec4e695f2ab9",
      "id": "CVE-2025-14287",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-14287 is fixed in version 2.22.4.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa0f30ab-7288-5b3f-a7d7-60c59a7f2970",
      "id": "CVE-2025-15031",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-15031 is fixed in version 2.22.4.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e938ffb-ac44-5a66-9e3b-adc4f3da28c9",
      "id": "CVE-2025-15036",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-15036 does not affect version 2.22.4.post3+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dde1a440-2075-5034-8d00-7af3c78609c3",
      "id": "CVE-2025-15379",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-15379 affects version 2.22.4.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:febfd223-ac55-5c93-9852-323e8ee582fc",
      "id": "CVE-2025-15381",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-15381 affects version 2.22.4.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbce944e-de56-5a96-93b8-85ff07df2854",
      "id": "CVE-2026-0545",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-0545 does not affect version 2.22.4.post3+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23419c45-15ac-50a5-b92b-f7229e16e210",
      "id": "CVE-2026-0596",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-0596 is fixed in version 2.22.4.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bfe80df-627b-52eb-9f09-16f276568f16",
      "id": "CVE-2026-10803",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10803 affects version 2.22.4.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:944a0918-00ac-58bf-8043-88048e993c98",
      "id": "CVE-2026-2033",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-2033 is fixed in version 2.22.4.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e077b428-6797-50a9-aa96-1a6b983ef42f",
      "id": "CVE-2026-2393",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-2393 does not affect version 2.22.4.post3+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:177c414a-92ca-5625-ae17-6f9ee05e714e",
      "id": "CVE-2026-2614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-2614 is fixed in version 2.22.4.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b4b7588-6cef-57b9-8c1e-c5ab5e2bc397",
      "id": "CVE-2026-2635",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-2635 is fixed in version 2.22.4.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7bc6c2c-ae46-5a62-95cc-5f150cdc5f10",
      "id": "CVE-2026-2651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2651 affects version 2.22.4.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cca368df-dbfd-5b92-9db4-a312b039b4b6",
      "id": "CVE-2026-2652",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-2652 does not affect version 2.22.4.post3+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e82e36b-3a3f-5f0f-bc7a-505d8176c31c",
      "id": "CVE-2026-2734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2734 affects version 2.22.4.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a25fc04d-6910-59fc-b1b8-65e5ccb5c5fe",
      "id": "CVE-2026-3198",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-3198 does not affect version 2.22.4.post3+tuxcare of mlflow. not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a01b49eb-dea7-509c-b52d-d9b931f81f4e",
      "id": "CVE-2026-33865",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33865 affects version 2.22.4.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3eb255b7-1c72-5b6a-86e4-34413e36c4da",
      "id": "CVE-2026-33866",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33866 does not affect version 2.22.4.post3+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1f6f0cb-50b9-5b22-9317-8ef1e052aeae",
      "id": "CVE-2026-4035",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-4035 affects version 2.22.4.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d9ef427-5bad-5f7c-aa90-9a85dad68e00",
      "id": "CVE-2026-4137",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-4137 affects version 2.22.4.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b540b8d-30e2-5cd0-af84-ab617626ef72",
      "id": "CVE-2022-33124",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-33124 is a false positive for aiohttp 3.8.1.post10+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14d148f2-45e5-50a0-a519-6cf5b5e3f5cd",
      "id": "CVE-2023-37276",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-37276 is fixed in version 3.8.1.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8364c7b-5dc9-5c03-b24e-24d683845723",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49081 is fixed in version 3.8.1.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcbcc155-c50d-5cb8-bbda-b13ba73337b6",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49082 is fixed in version 3.8.1.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2971b38c-4456-5e00-9d29-d5e2d25516e0",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23334 is fixed in version 3.8.1.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43256a51-890c-5033-b97b-71c2f6ea6852",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23829 is fixed in version 3.8.1.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f312bde1-06f3-5cb3-b081-9c0a9677787f",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-27306 is fixed in version 3.8.1.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7b2490b-1a9c-54f3-b333-147ef2574f74",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-30251 is fixed in version 3.8.1.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4bcd4a5e-e480-5da5-b3e2-1d7b887cd21e",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52304 is fixed in version 3.8.1.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3473a38-af9b-5ee1-ad72-b0f2e7f5d0e0",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53643 is fixed in version 3.8.1.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13030cea-8d53-5e9d-a005-8cb20aa11515",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.1.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5acc7db3-83df-56a5-9ef4-74ed087b635b",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.1.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:061cf140-9a78-5d7b-a6a4-0b17a84e78fc",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.1.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d7320d5-8477-5a14-bfcc-0d688c1a31a3",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.1.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9959a10-e767-5a03-911c-37437b83eabb",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.1.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:833c4b5d-a526-5199-a2ca-34af776cf1b1",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.1.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:335346c6-cc1f-5d98-9ecf-42f725bf56af",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.1.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:366d53fb-69ca-51f5-ba9f-13320f9e81bc",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.1.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91c9f638-81d7-5f05-a995-4cd522b6d6c1",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22815 is fixed in version 3.8.1.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5985b390-8f34-59e8-9f8a-ec2bd5dd76a0",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34513 is fixed in version 3.8.1.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26a34c2e-84a3-54eb-8c75-6ecbdcbd4796",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34514 affects version 3.8.1.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70a5de75-22de-506e-9d1d-0e418ba895ef",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.1.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb38dc7e-ebd5-5477-a9ee-bb59655534af",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34516 affects version 3.8.1.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ad4b367-6234-5904-a2e3-0299e21f4d0f",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34517 is fixed in version 3.8.1.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1c45880-fbc7-5ec8-8579-34b1d533bdc9",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34518 is fixed in version 3.8.1.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a56686ad-74c4-52eb-8c29-e481cb60c67c",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34519 affects version 3.8.1.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f287cf06-d298-5d84-aa03-e54d98be09d3",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34520 is fixed in version 3.8.1.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f22f974b-8585-5803-8600-e4caae16ae19",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34525 affects version 3.8.1.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95462169-cfae-5bbc-81fe-34fa222c26c0",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.1.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30129b4d-294b-5a2c-901c-defda9638fd4",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.1.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58eefa66-804a-5686-8293-bd7bdd7defa5",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.1.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0192d714-313a-5918-9565-3d9a1f42272a",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.1.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c413c82-b6e5-54e6-add9-6b561a250877",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.1.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d96235e-2c92-584c-a0b5-b4c2dbfd78ac",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.1.post10+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f78e84a-b085-5989-8dd6-994e8fa373d6",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.1.post10+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b96bad6e-2443-5daa-8457-a485d2785e2b",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.1.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c391780-b6f2-5063-95e5-8a3a7564205b",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.1.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12c487ee-d7a9-5d35-9d00-0524ecf66838",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.1.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11e05be1-f67e-56d8-bb49-fa478fb56cb1",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.1.post10+tuxcare of aiohttp. CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe"
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3b7a295-c727-5cf3-a3d5-e67ef2b0b1a2",
      "id": "GHSA-pjjw-qhg8-p2p9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-pjjw-qhg8-p2p9 is fixed in version 3.8.1.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f60ce3c-05c8-53de-901b-c5a222b9c07a",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-49081 affects version 3.8.6.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a01dba13-77d9-5841-8028-454c1973851f",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49082 is fixed in version 3.8.6.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68e99824-5b04-5daf-b1bd-2fe9383c0bb1",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23334 affects version 3.8.6.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:932fce01-b68b-5afe-862e-cfa87d1dc885",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23829 affects version 3.8.6.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:227cbaf3-5e10-58d6-87d1-a65389ee8bb0",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27306 affects version 3.8.6.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d339766-4df5-56c9-a933-49c0ece3794a",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-30251 is fixed in version 3.8.6.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0aeee880-8414-5078-99f6-c6aeab3d211e",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52304 affects version 3.8.6.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97330b33-8821-5cab-a451-10c1ba30ac59",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-53643 affects version 3.8.6.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34546da9-b28b-5588-a10f-110dd3ea2f03",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.6.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f0a3b36-deca-53d7-8f0e-d8d74040fa99",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.6.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51b23eef-927a-5632-94af-b40bb48a331d",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.6.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5902f83-ff24-5979-b836-da36b9d2f46a",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.6.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9de7b7f4-6527-5c81-aeb1-97feaf7f3a5f",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.6.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a2a134c-5879-5562-8e4a-4302faebf6c9",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.6.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e540434b-1dc0-58a8-8708-1efabbbc56db",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.6.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb65e2e9-f2b6-55b4-8a49-909fc89727d0",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.6.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2ad6b71-ec05-5259-8067-2a49f83b990b",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22815 is fixed in version 3.8.6.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b11c6746-2c1f-5816-af89-ff33dc5039e0",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34513 is fixed in version 3.8.6.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:303fc95d-c8df-5dd1-bdd4-01975c59be39",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34514 is fixed in version 3.8.6.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7c222df-3278-5c48-9246-c82c9feeba2d",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.6.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fad686e0-e1f8-505b-a383-31e927cf3c6c",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34516 is fixed in version 3.8.6.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4b29e64-995a-5374-a550-27c66e5c3f5e",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34517 is fixed in version 3.8.6.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6dce131c-64dd-5ce1-a4ae-a1b9789d20ca",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34518 is fixed in version 3.8.6.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78dbf8c4-48d3-5e92-b7d7-514e262f4bc6",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34519 is fixed in version 3.8.6.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de146ea2-5066-5782-a3ea-4baf0a9880a1",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34520 is fixed in version 3.8.6.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:373f3ae2-5365-5551-aa46-594a862bdfe0",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34525 is fixed in version 3.8.6.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b11ef170-8be8-53d0-ae55-33096d06f46e",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.6.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbc4406a-557b-5229-9056-bcd954b1c1a3",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.6.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d02f56fc-7e8d-5ad2-b484-b8981ae18a48",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.6.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e9a907f-dd08-5d4a-9bbd-be3a06b1380c",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.6.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9392a008-89df-5ff6-a870-f8dd90bd4e30",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.6.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f323e3c-e5b5-56e7-9d45-51f5abea7bcb",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.6.post5+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a49451c-d7ac-511d-bdc0-34aa40d4e116",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.6.post5+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fecf7e3f-a67c-5e07-892b-1d96147ac8e8",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.6.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a3dd544-21c8-52d7-90b0-3525c76378f8",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.6.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:103dc50f-2e3a-5728-942d-53e3c11a03c7",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.6.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d71db426-f2a5-54cb-8834-d395e1ae2e3a",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.6.post5+tuxcare of aiohttp. Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8c4f403-a376-5bd8-afa6-ababe6a53566",
      "id": "CVE-2023-6709",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-6709 is fixed in version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a81ee43-c288-5929-8df3-c34f5f70c0f8",
      "id": "CVE-2023-6753",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-6753 is fixed in version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64bb700c-141f-51c5-8637-61b212f272d8",
      "id": "CVE-2023-6831",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-6831 affects version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c446384e-8b41-5b4d-a6f5-3397b5cc3f2e",
      "id": "CVE-2023-6909",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-6909 is fixed in version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69443f61-00f8-5bf0-89a7-fd386c9a5386",
      "id": "CVE-2023-6940",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-6940 affects version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72610d42-18b0-517a-8c3b-6ca83661dc7c",
      "id": "CVE-2023-6974",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-6974 is fixed in version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fc446c9-574c-5b0c-b21f-9f20e7b82300",
      "id": "CVE-2023-6975",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-6975 is fixed in version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb50c4e5-aedd-5817-af55-ad9af5ef9868",
      "id": "CVE-2023-6976",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-6976 affects version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df139ac1-f523-516a-a410-b38344f74384",
      "id": "CVE-2023-6977",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-6977 affects version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0ee584f-b47e-5c18-8d7e-e8aad8dbbf5b",
      "id": "CVE-2024-1483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-1483 affects version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f8c1430-a2ef-55aa-88fc-217bd217108e",
      "id": "CVE-2024-1558",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-1558 affects version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1fc819d-09db-5211-afd2-a5ae8dde5f9d",
      "id": "CVE-2024-1560",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-1560 affects version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ac2ec4a-eb1f-5248-bc87-148695746884",
      "id": "CVE-2024-1593",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-1593 is fixed in version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b609dbd2-21c0-51a8-afc8-18873683500e",
      "id": "CVE-2024-1594",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-1594 affects version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2be65de-d35b-5dd3-8709-5d5b28e1ab0e",
      "id": "CVE-2024-27132",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-27132 is fixed in version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6e70a2b-b90a-5f71-9c8b-c621af136ddb",
      "id": "CVE-2024-27133",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-27133 is fixed in version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd20c792-83fa-5ad1-9936-57acd7513cf5",
      "id": "CVE-2024-27134",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-27134 is fixed in version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e719b452-d3c5-5aa5-97e4-fbffd5861edf",
      "id": "CVE-2024-2928",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-2928 is fixed in version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a10a393-ec20-5669-b2db-9490c8295e06",
      "id": "CVE-2024-3099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-3099 affects version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47cdfef3-610f-544c-99bd-c46b79169e99",
      "id": "CVE-2024-3573",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-3573 is fixed in version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0bebbfd-2e0e-5f13-ae51-a00f078a26f2",
      "id": "CVE-2024-37052",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-37052 does not affect version 2.9.1.post3+tuxcare of mlflow. already_fixed \u2014 The target MLflow 2.9.1 codebase contains the fix for CVE-2024-37052 (unsafe pickle deserialization in scikit-learn model loading). The MLFLOW_ALLOW_PICKLE_DESERIALIZATION environment variable check was added in prior TuxCare backports (commits d58ee98ca for initial guard, 98a32847a for CVE-2024-37056, cf8bc9c26 for CVE-2024-37053). However, the defense defaults to True (allowing deserializatio..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7d9c787-1d5a-546d-9e00-1b080d744e6e",
      "id": "CVE-2024-37053",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37053 affects version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aad51d0d-32b9-53d0-a979-f497b38f2166",
      "id": "CVE-2024-37054",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37054 affects version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a56889e-f1f1-5476-9860-9eeff1a24ba8",
      "id": "CVE-2024-37055",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37055 affects version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0bda42dd-bbfa-5580-9703-93a71928e922",
      "id": "CVE-2024-37056",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-37056 is fixed in version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6820b8e-f781-506a-9790-bbd7c87eff10",
      "id": "CVE-2024-37057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37057 affects version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df21d196-71fd-5b59-8976-16e68b6365ca",
      "id": "CVE-2024-37058",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37058 affects version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17919029-cb80-51ce-bc2a-1e70bc4ceb08",
      "id": "CVE-2024-37059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37059 affects version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbaed002-a4fd-5a2f-ae70-6658fa64c30a",
      "id": "CVE-2024-37060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37060 affects version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42125db8-45ea-542e-8598-16fbd17eec3f",
      "id": "CVE-2024-37061",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37061 affects version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a658ac3-219e-52be-85c7-d841d4c370d2",
      "id": "CVE-2024-4263",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-4263 affects version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba383c57-59b0-5cfd-801b-7d68bb7864a0",
      "id": "CVE-2024-6838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6838 affects version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b415730f-a09f-510d-8f89-52c50631600d",
      "id": "CVE-2024-8859",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8859 affects version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee6aa589-ff13-52e1-919e-3ad301f8e640",
      "id": "CVE-2025-0453",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-0453 affects version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4557a948-0e51-53ca-91d8-68995832b23c",
      "id": "CVE-2025-10279",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-10279 is fixed in version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:919d78b1-7ce1-566f-bebb-d52c32e1d518",
      "id": "CVE-2025-11200",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-11200 is fixed in version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a50936e-d8e6-5125-94ac-08356a85dfae",
      "id": "CVE-2025-11201",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-11201 is fixed in version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:460ab0e6-4d00-583f-8927-eb4727b8b58d",
      "id": "CVE-2025-14279",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-14279 is fixed in version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:460d8dcf-8e9d-5da3-845c-a68250dfa9d6",
      "id": "CVE-2025-14287",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-14287 is fixed in version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ce03432-3f1c-5e1b-9ca7-7c458556a897",
      "id": "CVE-2025-1474",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-1474 affects version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:336015c7-eef9-5c54-85a2-6599fb1affbc",
      "id": "CVE-2025-15031",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-15031 affects version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0f65000-e039-53a1-84ab-9409cb94e057",
      "id": "CVE-2025-15036",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-15036 affects version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e61dd86d-00ff-56d5-9ad9-219c310b2e2d",
      "id": "CVE-2025-15379",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-15379 affects version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71958809-44af-5b9a-96aa-1912f75f6f1c",
      "id": "CVE-2025-15381",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-15381 does not affect version 2.9.1.post3+tuxcare of mlflow. not_affected \u2014 MLflow version 2.9.1 does not contain tracing and assessment features. These features appear to have been introduced in a later version of mlflow. The vulnerability pattern described in CVE-2025-15381 (missing permission validators on tracing and assessment endpoints when basic-auth is enabled) cannot exist in a version that does not have these endpoints."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7af303e-b6be-58bf-b626-e1911e589fbf",
      "id": "CVE-2025-52967",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52967 is fixed in version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95e271c6-856f-5bb9-9f67-e6c0dd9fad88",
      "id": "CVE-2026-0545",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-0545 affects version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45822c2e-7be4-5531-b9d3-1bb2e2639447",
      "id": "CVE-2026-0596",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-0596 affects version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9053b621-bc49-58f7-b8d0-18b22d3d83ca",
      "id": "CVE-2026-10803",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10803 affects version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b98d8b85-c710-5879-b7e3-b333ca09ff96",
      "id": "CVE-2026-2033",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-2033 is fixed in version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f36e250-46f5-51f0-b3f5-33827fbee4dd",
      "id": "CVE-2026-2393",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2393 affects version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d849225a-9854-5764-a142-475269455b55",
      "id": "CVE-2026-2614",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-2614 does not affect version 2.9.1.post3+tuxcare of mlflow. Version 2.9.1 is not vulnerable. Summary: The target repository (MLflow v2.9.1.post4+tuxcare) does not contain the vulnerable code pattern described in CVE-2026-2614. The vulnerability was introduced in version 3.5.0 (September 2025) when prompt registry support was added to webhooks. The target version predates the introduction of the vulnerable feature by approximately 21 months."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7aacc418-4c92-5b54-a71d-24d81cc5326e",
      "id": "CVE-2026-2635",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-2635 is fixed in version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7affdf8-3a6c-5d6e-a9cc-b5e5ae699621",
      "id": "CVE-2026-2651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2651 affects version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb76fd92-d64a-5b3a-adbb-8f374f2b92e2",
      "id": "CVE-2026-2652",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2652 affects version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:128eea42-12ee-5d42-8cae-061aba52c434",
      "id": "CVE-2026-2734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2734 affects version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6623801-580a-53d0-bccc-a0a04f3271e6",
      "id": "CVE-2026-3198",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-3198 does not affect version 2.9.1.post3+tuxcare of mlflow. not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-3198. The vulnerability describes missing authorization checks for Gateway API list endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in MLflow 3.9.0's basic-auth integrated server. Version 2.9.1 has a fundamentally different architecture: the Gateway runs as a separate FastAPI application with no integration to the Fl..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb747d4f-81e7-5fef-aa95-257f293ef0c0",
      "id": "CVE-2026-33865",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33865 affects version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27f15a2e-ab57-52ab-85f5-8af99882bbd9",
      "id": "CVE-2026-33866",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33866 affects version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1c91cd9-4ae5-5645-893d-38d577d0742c",
      "id": "CVE-2026-4035",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-4035 affects version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:624cc8b4-dc92-514b-a8af-24300f19150c",
      "id": "CVE-2026-4137",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-4137 affects version 2.9.1.post3+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:680034d3-f443-5858-90e4-87d568a17936",
      "id": "CVE-2023-47627",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-47627 is fixed in version 3.8.5.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5fa2baa-3fcd-507d-b3a2-c540e2c383c7",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49081 is fixed in version 3.8.5.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6be9619-9419-50f0-9edd-98e3283d2d6d",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49082 is fixed in version 3.8.5.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53d02538-417d-5740-a43f-4cc9e2f3f6cc",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23334 is fixed in version 3.8.5.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:929ce0b9-754d-5838-a782-10b609d8a9cb",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23829 is fixed in version 3.8.5.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1ceec44-791d-5521-9a73-11e5690d05e0",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27306 affects version 3.8.5.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8871f13-7f4b-5ef6-b0a6-71dad97784ac",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-30251 affects version 3.8.5.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f3bc2a3-328c-556c-970f-9dc8b02f6754",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52304 is fixed in version 3.8.5.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9fdf1da6-02f3-5998-bec2-c985a7e14da0",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-53643 affects version 3.8.5.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae4b2c61-3af8-5576-8dfc-37ed0d113487",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.5.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46e28674-a275-5b10-882b-ab32c6ae281c",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.5.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9da42a9c-25ae-5d9f-a195-4ac40ae32f20",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.5.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1041a158-deb0-5d37-afdf-780d9f5778b7",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.5.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6774247-db2a-5a96-b514-20d8bd2990cb",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.5.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:506b8dfd-f0a5-5da7-a2cc-bbeb865c8b09",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.5.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b82fd592-9770-50ad-88aa-74524acd651a",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.5.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d0b07fd-2f9e-52e3-bc80-6e7718c1d3d6",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.5.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58af9158-005c-5d3b-9b22-d5967942bda5",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22815 is fixed in version 3.8.5.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d49b05d-63ce-51dc-8437-fc28a1cba561",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34513 affects version 3.8.5.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1905ac9a-0431-5c9c-892a-9bd6fad73291",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34514 is fixed in version 3.8.5.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:720af91a-5ffc-5c99-9cfc-66c70a1f189d",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.5.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ddd8bf0b-409f-5853-8078-51be1e346d02",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34516 is fixed in version 3.8.5.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:543c4df2-756d-5125-aac0-affca2a7d837",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34517 is fixed in version 3.8.5.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:616ec777-2ef2-52f0-8e2e-61605a10c85e",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34518 is fixed in version 3.8.5.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b51b452-5d26-596d-aff1-8be898d2a0df",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34519 is fixed in version 3.8.5.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d5be243-09ba-5307-9532-0f36bc3371b4",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34520 is fixed in version 3.8.5.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19f1ef03-b7a0-57a1-a723-32b3d842b09a",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34525 affects version 3.8.5.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08a328c8-bab6-5115-a0cc-847671ffad8f",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.5.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04c7ec76-db1c-5189-a260-3ab9ca121be4",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.5.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2253169-f954-5bce-9e75-5050fb5660e1",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.5.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c56c1f50-bc0b-5d3d-b1c6-c0b94b3dd16f",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.5.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46dec0ae-18e0-5021-87d7-170b8a896afd",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.5.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e3a46c0-d6c5-5cb6-bd32-4ac42a3a9567",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.5.post8+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01e14e07-cdbf-5504-a09d-3647caa09712",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.5.post8+tuxcare of aiohttp. not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:716ed250-419c-5467-9f2e-e70acad08b70",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.5.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e918ce34-eae2-5256-a8d7-1ea967531084",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.5.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db43ebe6-6313-5e61-bb6e-2e3e53383bb9",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.5.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba8ff716-f330-59ad-9e4e-9d0a5a519a0e",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.5.post8+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf76a3b0-0e5c-51c4-b147-c3340d43e7f1",
      "id": "GHSA-pjjw-qhg8-p2p9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.5.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8faa83d-3709-52e4-b558-c0ef0c5885f5",
      "id": "CVE-2023-37276",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-37276 is fixed in version 3.8.4.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b849ef05-4632-58e1-9cd0-b60a98cb1bcc",
      "id": "CVE-2023-47627",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-47627 affects version 3.8.4.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f3eabc1-effc-5ca9-b8a6-e4f5fdebed0b",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-49081 affects version 3.8.4.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ccc77cdd-6c08-5eef-b29d-144dcd087b56",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-49082 affects version 3.8.4.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fabe402-e568-5dd1-aa34-81bf9faf31a9",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23334 affects version 3.8.4.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd51ccbb-fffe-5ce8-9159-0abeedd39ae2",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23829 affects version 3.8.4.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74a28e1f-4a67-5e15-9e97-ff3fb26b06c9",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27306 affects version 3.8.4.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a79d55e4-3f4f-5404-aa82-700d9ce1aa3c",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-30251 affects version 3.8.4.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee08b847-ddd0-56ca-bb01-94684472f82e",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52304 affects version 3.8.4.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c18a3735-2f15-541b-811d-dd3ff798d78c",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-53643 affects version 3.8.4.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28fed8d1-8067-5b39-a2d6-88a02891d2d2",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.4.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd03ff70-573b-57a9-8398-5c59ca73a0e0",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.4.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:151a9867-51c1-596a-8151-a264de75795d",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.4.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36d7cb62-5df1-57a0-9875-b45eb8a1e3b6",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.4.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee983ab5-f866-5c89-a9dd-c47318feb26b",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.4.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8512d40-3b42-5c1e-b2d7-f7459e4c4924",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.4.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bcf2558-e6ea-5ea1-b59a-e3a16d49f815",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.4.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51a93e8d-02c8-55c0-9c95-6d9c6034e907",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.4.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca8251c1-2332-54a8-8685-2e472333a3c8",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22815 is fixed in version 3.8.4.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1ee5a99-c200-5873-a06c-3b02ce58319e",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34513 is fixed in version 3.8.4.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae9cbb2c-9f5c-5347-a696-436c3463473a",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34514 is fixed in version 3.8.4.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:863d5f1b-ec41-5ab5-ace6-4c744c4617c4",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34515 is fixed in version 3.8.4.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:edec3567-164a-5f19-9413-c215953f2f9a",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34516 is fixed in version 3.8.4.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6e7aa6d-089e-5824-b507-803c0ce456b1",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34517 is fixed in version 3.8.4.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:723763b5-f3e7-5416-9c53-b954795b4348",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34518 is fixed in version 3.8.4.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be030821-cb73-5906-becd-42e901052903",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34519 is fixed in version 3.8.4.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:331aaaa7-d0f7-579b-a78d-f3d016d8c5bb",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34520 is fixed in version 3.8.4.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bec9393f-5b46-590d-a4b4-cf226bcf0c8d",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34525 affects version 3.8.4.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48a1ea0d-0fc4-5b8f-88d4-3de3b575482c",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.4.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db884211-827c-52b7-b9e6-8b442ffc7a0e",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.4.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28e5ddad-bc6c-5d08-87ce-5b5da6375a69",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.4.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd2601fc-c9a5-56bf-b7da-aa8cef9b361a",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.4.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99506301-e0b6-5186-a757-7a932c030ebe",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.4.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8767d74-1c2f-503e-9fe3-632bdc7b6174",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.4.post4+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.4.post4+tuxcare. The vulnerability requires the server_hostname parameter feature, which was not added until version 3.9.0+ (August 2023), six months after version 3.8.4 was released (February 2023). The target version cannot receive the malicious input described in the CVE."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1902d51-57f6-5625-acd6-1e2045754ab9",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.4.post4+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.4.post4+tuxcare) does not contain the DigestAuthMiddleware component. This feature was introduced in aiohttp version 3.12, which postdates the target version. The vulnerability cannot manifest because the affected code does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c549adcd-43cb-5c77-ae31-d444f085e2d8",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.4.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef3a2c28-a095-5211-8c75-556b507d89c3",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.4.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cadea0a1-972d-584f-ae51-62f73b745eed",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.4.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b41d52b8-8c89-5fff-9806-a7f9da918f84",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54280 affects version 3.8.4.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:941333cc-dba1-598e-8217-13ebc1ce7e1d",
      "id": "GHSA-pjjw-qhg8-p2p9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.4.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84377ff9-1b76-5919-b3b7-de1f106a56da",
      "id": "CVE-2022-33124",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-33124 is a false positive for aiohttp 3.8.1.post9+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a947b4a7-0816-5a99-be7f-fcc28590b66f",
      "id": "CVE-2023-37276",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-37276 is fixed in version 3.8.1.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:930025f8-b7a8-5bb2-92e0-8225a8e87370",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49081 is fixed in version 3.8.1.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6a151ac-54b4-5291-8ca4-dc3926b46d82",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49082 is fixed in version 3.8.1.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f23caa1e-1681-5bad-be52-4139c95df362",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23334 is fixed in version 3.8.1.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:526f7248-fb86-55b8-b7b4-848d2b395528",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23829 is fixed in version 3.8.1.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0157721b-c848-55d7-8756-43aa94eb5b37",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-27306 is fixed in version 3.8.1.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efb5e29f-50f6-5192-98e5-d86043c9db11",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-30251 is fixed in version 3.8.1.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:097feef1-cfe3-5db6-8f58-60b2884cfe8a",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52304 is fixed in version 3.8.1.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bce9a7f0-4340-5ec6-813c-c3e91d00700f",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53643 is fixed in version 3.8.1.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b13a68c-98e4-5b21-bb7d-a85f56e659f9",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.1.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62001f04-9ea0-5206-94ea-a8b4c52494d7",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.1.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d999fc5-6aa4-56e0-9abc-91ffa6111cef",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.1.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77a39559-3f82-5edd-a6d3-6021d4d92613",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.1.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93c29790-5675-5bd6-ada0-4616102aed46",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.1.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cac6d6a5-90c2-509c-b6de-898216f746db",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.1.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57545f10-8d1a-509a-8add-192dce43c4af",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.1.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:483712d8-c74b-5f81-82ee-9750442e6d7e",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.1.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77ae42cb-5d7c-506c-be2c-a2c4c3baecb8",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22815 is fixed in version 3.8.1.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eafe9b2c-760c-5e15-9a7a-e35ce2b2b06f",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34513 is fixed in version 3.8.1.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06396d7e-13c1-5757-a578-0453f492cc13",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34514 affects version 3.8.1.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:429f8a43-5a09-59bf-bec2-a3cfb9422360",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.1.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d62863e0-ebf5-5da2-ab07-13c708fb43da",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34516 affects version 3.8.1.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aaee17a2-e191-5ac2-ae9e-38aa4b4835d3",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34517 is fixed in version 3.8.1.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd9b9247-1527-5060-9f82-a4367cd0266c",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34518 affects version 3.8.1.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53cdb994-c96c-5d8f-8981-17f1db41c4a8",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34519 affects version 3.8.1.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15f03de7-a0e4-5061-ab55-61080fc83d25",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34520 affects version 3.8.1.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b7b39cc-7d16-5780-9ca7-ee3d11d372fe",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34525 affects version 3.8.1.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfe4bd6e-6796-528d-895d-e1fd733802af",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.1.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fad0220-2c42-5d67-9059-b082efbf3f0b",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.1.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db32fac0-6136-5f12-8748-c660b9b4b3a8",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.1.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64254e88-6533-51cb-ade7-58ad9bbfb599",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.1.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d670aa79-c618-5e18-bfd6-79ecb5a1b261",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.1.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92429e4e-cd6a-5843-bc50-878cbc6f7b6b",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.1.post9+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3849c41d-9559-5991-9662-5961eb4e67da",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.1.post9+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6675cad5-e9e4-59e5-8e24-ded8870b6c4e",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.1.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aaec1eb7-b754-594b-ae1e-d182b4006c55",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.1.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ab1dc7c-decb-523c-b92a-7bd085fc1945",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.1.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8441b45-6a92-5adc-8a20-063152857b2e",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.1.post9+tuxcare of aiohttp. CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe"
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca3c6746-7c3d-574c-a90f-a231f2e69ced",
      "id": "GHSA-pjjw-qhg8-p2p9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-pjjw-qhg8-p2p9 is fixed in version 3.8.1.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9966509-772b-5eda-a8fa-6de02ce374bd",
      "id": "CVE-2023-37276",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-37276 is fixed in version 3.8.4.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd641909-6480-58b8-98a6-8233927cc89f",
      "id": "CVE-2023-47627",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-47627 affects version 3.8.4.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a6dc66d-94ad-5660-b674-a800ae29a3bd",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-49081 affects version 3.8.4.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba39dff7-afb3-520d-ac3c-f26938c2690a",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-49082 affects version 3.8.4.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf912af7-0f22-56cb-89ee-0956612c02ac",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23334 affects version 3.8.4.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf698f3b-5c1c-573a-818f-4b6a0436f8b8",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23829 affects version 3.8.4.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a2c0a62-db2c-5136-a195-e74cc7656c1a",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27306 affects version 3.8.4.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a810c6c4-cf15-51af-a51a-8b32a57cacfe",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-30251 affects version 3.8.4.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9cac98ed-accf-50ec-9f88-d437b80a874c",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52304 affects version 3.8.4.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93b9a53f-91cf-5eeb-a885-e1f8bb5b70a3",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-53643 affects version 3.8.4.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfd580eb-dfa6-5d08-a62f-ad59b5c1a430",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.4.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2069ab58-9cdd-5f33-9377-28514c326caf",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.4.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0df9ae07-ee38-5d5a-a9e3-96f4f436ef62",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.4.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61579206-fd9e-5224-8b69-d0e3917a1e56",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.4.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6467686-e132-5405-b0ab-c051e775183d",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.4.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ca86a5d-4670-5c55-830a-3a2d4a53303b",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.4.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59c7ae9b-2025-58f3-a162-21936ce5fcd9",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.4.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:207ac3f1-21e0-573c-ba30-26ba0126c919",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.4.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:592568e0-1624-5131-a279-0a4c2af32b3e",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22815 affects version 3.8.4.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf79ec1a-bf00-5e24-9bb5-8303f37c6063",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34513 is fixed in version 3.8.4.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6d0fa19-5543-5be7-88d3-645bbeb67208",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34514 affects version 3.8.4.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37d961d7-206d-54cd-a290-a8f6e73c3640",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.4.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:020f1bc4-f2eb-5211-bf9e-337c1d26fabd",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34516 is fixed in version 3.8.4.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:820815aa-5a5b-5749-989a-20b38f342467",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34517 is fixed in version 3.8.4.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c217af1d-76b2-5466-a73f-7810ca5ab9a6",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34518 affects version 3.8.4.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b274050d-56c0-5f38-90b1-d7dbaef041b0",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34519 is fixed in version 3.8.4.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7107963-8944-5f21-9e20-6716bc0f8566",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34520 is fixed in version 3.8.4.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e4091f3-fcba-5d46-8eda-a3e5674c967a",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34525 affects version 3.8.4.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0cd9e962-7ad1-5d8d-a7cf-e227094ba3fb",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.4.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6cd84fc-74f6-5e9a-9bc1-1cc12595ce7a",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.4.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ec6e5a0-fa02-5937-a83c-bf8d42940790",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.4.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48a820dc-013b-5983-880a-d5e50ab151d1",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.4.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93015e74-0678-5fe9-aca7-d2a9354f6759",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.4.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b54bfa2d-12d7-5f40-8a86-62b7e197193e",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.4.post3+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.4.post4+tuxcare. The vulnerability requires the server_hostname parameter feature, which was not added until version 3.9.0+ (August 2023), six months after version 3.8.4 was released (February 2023). The target version cannot receive the malicious input described in the CVE."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e5b10f6-2a5f-544a-ab0f-aff523be62b1",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.4.post3+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.4.post4+tuxcare) does not contain the DigestAuthMiddleware component. This feature was introduced in aiohttp version 3.12, which postdates the target version. The vulnerability cannot manifest because the affected code does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7463d8a-d5b6-55ca-b9e6-e8f17daa94ea",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.4.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:810da87f-8b37-599d-9b28-6b37e7adbcd5",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.4.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c7d0431-f72f-5fbc-850c-89ac5c93a036",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.4.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68cbe27b-39e7-53e4-bea1-ca643d448be2",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54280 affects version 3.8.4.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b85d32e4-7c0d-55b0-9bd2-aba42d3ae041",
      "id": "GHSA-pjjw-qhg8-p2p9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.4.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f27ec0fd-e677-5647-9ac1-afdf9e14c938",
      "id": "CVE-2023-47627",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-47627 is fixed in version 3.8.5.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b419f0f-11fc-596e-a8c6-e8fdcacced48",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49081 is fixed in version 3.8.5.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e01b7f3-6399-5ea9-8ec2-f40fe4e06705",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49082 is fixed in version 3.8.5.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09ef42e6-ce1a-5d3d-ad52-3b8e4ef75502",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23334 is fixed in version 3.8.5.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:248b5334-4284-56d6-be23-759d9310f30b",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23829 is fixed in version 3.8.5.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04f5b892-556e-5d66-8018-badcce6462ce",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27306 affects version 3.8.5.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:515c07d9-2988-5f06-97e7-62fcc9b6df05",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-30251 affects version 3.8.5.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4919d6e-4431-54dd-83d8-4f0570df8394",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52304 is fixed in version 3.8.5.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d302e8c-1806-5137-9d55-cefe8cbb4ae0",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-53643 affects version 3.8.5.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:492a30bd-17fc-553a-b7d2-7c5dcd03ee90",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.5.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fe35872-0eba-56c6-aa7c-d19526914609",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.5.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83664bdf-13d6-5b6e-92f5-3e0bb4951ec0",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.5.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b2c2444-34a2-5e12-af51-ba1c968b095e",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.5.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e262d1e-db80-5544-90a8-2f1f549bc504",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.5.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:027cae3c-a84c-56b8-97f6-f3692b25a80e",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.5.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77bbc8d7-6b28-5758-80e7-85864364cd21",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.5.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63239ae6-0b6e-5023-b627-48f0113b0da7",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.5.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac902b60-088c-5ab3-9107-b5c1ce3be24d",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22815 is fixed in version 3.8.5.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c9b6adc-e4da-5d0b-9c75-e1f409ae41bf",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34513 affects version 3.8.5.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea932632-2c2b-5545-a715-ed67327ea3ef",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34514 affects version 3.8.5.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1cd88448-cca2-50c5-9090-c4c868bca1a1",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.5.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44b89b39-a1fd-52ca-bb06-037b545daccb",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34516 is fixed in version 3.8.5.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:575f3075-3ce3-56bb-8f5f-1b70e7d330c3",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34517 is fixed in version 3.8.5.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d36b5f0d-35ee-5c62-94cd-17d05bf0cb24",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34518 affects version 3.8.5.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:755a304c-e106-5399-a62c-5e446bd8191f",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34519 is fixed in version 3.8.5.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7cfd793-e6d3-53f6-8c94-6ad0418645be",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34520 is fixed in version 3.8.5.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c88d66c2-6a6c-5a20-b17c-64373e53874c",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34525 affects version 3.8.5.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a62b9c00-8f85-5522-9d30-bb64ae15f5f8",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.5.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45bc1691-4199-52e3-a8df-6e9c0ebbebbf",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.5.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa2df144-d389-5350-9873-b2a12e44fb6b",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.5.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91d8172f-b0ab-5959-91ea-3626cbcf4aff",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.5.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17453484-fb93-5011-ae0e-c97d0cd611c4",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.5.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ea031e1-ad30-569b-aaed-dc8cbf8bb11a",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.5.post7+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:431d7bd3-35db-589b-b6b3-43ea0e15027e",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.5.post7+tuxcare of aiohttp. not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fcc8720-d0a4-5ca5-b176-1027ca4e08cd",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.5.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:feb2dd95-4f12-568c-b69a-5ba874003238",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.5.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ae41298-4bdf-5722-8b86-20a38a0efdb9",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.5.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a06c6d4-6c35-5e83-b2bb-6f683ac97246",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.5.post7+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5c375c4-9e6c-504b-8169-89ddf2917952",
      "id": "GHSA-pjjw-qhg8-p2p9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.5.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6fdb954-e21e-56b0-af4a-e79c3126eafa",
      "id": "AIKIDO-2026-10554",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2026-10554 is fixed in version 0.25.2.post1+tuxcare of dulwich."
      },
      "affects": [
        {
          "ref": "pkg:pypi/dulwich@0.25.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24d71cfa-1a68-5beb-abcc-5a3ea4ac1226",
      "id": "CVE-2026-42305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42305 affects version 0.25.2.post1+tuxcare of dulwich."
      },
      "affects": [
        {
          "ref": "pkg:pypi/dulwich@0.25.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ce6e6fb-0155-5ffe-bd56-f890d4ea5013",
      "id": "CVE-2026-42563",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42563 affects version 0.25.2.post1+tuxcare of dulwich."
      },
      "affects": [
        {
          "ref": "pkg:pypi/dulwich@0.25.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a32e5bf-9bfb-52d5-8474-eea02e8f847d",
      "id": "CVE-2026-47712",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47712 affects version 0.25.2.post1+tuxcare of dulwich."
      },
      "affects": [
        {
          "ref": "pkg:pypi/dulwich@0.25.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51445a79-d647-5576-9aa5-649ed145cb92",
      "id": "CVE-2026-47734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47734 affects version 0.25.2.post1+tuxcare of dulwich."
      },
      "affects": [
        {
          "ref": "pkg:pypi/dulwich@0.25.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bae8ba65-488f-5bfa-ba44-479e2e53751b",
      "id": "CVE-2026-52726",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52726 affects version 0.25.2.post1+tuxcare of dulwich."
      },
      "affects": [
        {
          "ref": "pkg:pypi/dulwich@0.25.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ae4600a-9bc8-52d3-97d9-8e7409741d25",
      "id": "CVE-2025-69219",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69219 is fixed in version 4.13.3.post1+tuxcare of apache-airflow-providers-http."
      },
      "affects": [
        {
          "ref": "pkg:pypi/apache-airflow-providers-http@4.13.3.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35b95432-f2d8-5835-b988-e03385de1c45",
      "id": "CVE-2024-49768",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-49768 is fixed in version 2.1.2.post1+tuxcare of langgraph-checkpoint."
      },
      "affects": [
        {
          "ref": "pkg:pypi/langgraph-checkpoint@2.1.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d02bfee8-7605-566a-bdfc-a56077870901",
      "id": "CVE-2024-49769",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-49769 affects version 2.1.2.post1+tuxcare of langgraph-checkpoint."
      },
      "affects": [
        {
          "ref": "pkg:pypi/langgraph-checkpoint@2.1.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ef707e6-3565-5c3a-b02f-6ac71d0ccb38",
      "id": "CVE-2025-64439",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64439 is fixed in version 2.1.2.post1+tuxcare of langgraph-checkpoint."
      },
      "affects": [
        {
          "ref": "pkg:pypi/langgraph-checkpoint@2.1.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4946ee68-a45a-5963-9bde-181aad028a21",
      "id": "CVE-2026-27794",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27794 affects version 2.1.2.post1+tuxcare of langgraph-checkpoint."
      },
      "affects": [
        {
          "ref": "pkg:pypi/langgraph-checkpoint@2.1.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35eec0c9-1089-556c-90ee-d16f6c719ed8",
      "id": "CVE-2026-48775",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48775 affects version 2.1.2.post1+tuxcare of langgraph-checkpoint."
      },
      "affects": [
        {
          "ref": "pkg:pypi/langgraph-checkpoint@2.1.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7ecc63e-1332-56f0-a337-1e5a6d50e4c3",
      "id": "CVE-2026-41481",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41481 is fixed in version 0.3.11.post1+tuxcare of langchain-text-splitters."
      },
      "affects": [
        {
          "ref": "pkg:pypi/langchain-text-splitters@0.3.11.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fec810a6-ee43-5d74-b945-fec046547216",
      "id": "GHSA-fv5p-p927-qmxr",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-fv5p-p927-qmxr is fixed in version 0.3.11.post1+tuxcare of langchain-text-splitters."
      },
      "affects": [
        {
          "ref": "pkg:pypi/langchain-text-splitters@0.3.11.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b4eae1a-baf1-55a9-9009-d10d935a7638",
      "id": "CVE-2022-2309",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-2309 affects version 5.4.0.post1+tuxcare of lxml."
      },
      "affects": [
        {
          "ref": "pkg:pypi/lxml@5.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77316de9-1a59-58f0-bf3b-8666756ab538",
      "id": "CVE-2026-41066",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41066 is fixed in version 5.4.0.post1+tuxcare of lxml."
      },
      "affects": [
        {
          "ref": "pkg:pypi/lxml@5.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1c1a356-41e4-5d24-8c12-1787a59338f5",
      "id": "CVE-2022-2309",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-2309 affects version 4.9.4.post1+tuxcare of lxml."
      },
      "affects": [
        {
          "ref": "pkg:pypi/lxml@4.9.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c49cdea1-c8dd-586b-a85e-90f6d883f980",
      "id": "CVE-2026-41066",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41066 is fixed in version 4.9.4.post1+tuxcare of lxml."
      },
      "affects": [
        {
          "ref": "pkg:pypi/lxml@4.9.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2061300c-ad92-5072-b326-2c7c53e5a7bc",
      "id": "CVE-2026-1839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-1839 is fixed in version 4.57.6.post1+tuxcare of transformers."
      },
      "affects": [
        {
          "ref": "pkg:pypi/transformers@4.57.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf7f7a46-b077-59da-b35a-a7bcab835d79",
      "id": "CVE-2026-4372",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-4372 affects version 4.57.6.post1+tuxcare of transformers."
      },
      "affects": [
        {
          "ref": "pkg:pypi/transformers@4.57.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42de60b3-10c0-5d1a-8e84-5a81073e60eb",
      "id": "CVE-2026-5241",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-5241 affects version 4.57.6.post1+tuxcare of transformers."
      },
      "affects": [
        {
          "ref": "pkg:pypi/transformers@4.57.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8667dd0f-b84d-5500-a99c-5cf4eadd9fca",
      "id": "CVE-2023-47248",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-47248 is fixed in version 12.0.1.post1+tuxcare of pyarrow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyarrow@12.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7464a89b-fd8a-5fde-8020-a59c6e660048",
      "id": "CVE-2025-71176",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-71176 is fixed in version 7.4.4.post1+tuxcare of pytest."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pytest@7.4.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2742ec71-3d23-5473-9890-6a0048e4f6bb",
      "id": "CVE-2025-71176",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-71176 is fixed in version 8.4.2.post1+tuxcare of pytest."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pytest@8.4.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:edd3571c-fefc-52e6-b352-4fce0c54d473",
      "id": "CVE-2024-3660",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-3660 affects version 2.15.0.post1+tuxcare of keras."
      },
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88792db7-f9d6-5b77-91d4-d8f090844f4a",
      "id": "CVE-2024-55459",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-55459 affects version 2.15.0.post1+tuxcare of keras."
      },
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9fa05bc-d0af-5384-b574-ada2c2f58c1a",
      "id": "CVE-2025-12058",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-12058 affects version 2.15.0.post1+tuxcare of keras."
      },
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6740360d-ef2c-57c2-87f8-ac512d0d3701",
      "id": "CVE-2025-12060",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-12060 is fixed in version 2.15.0.post1+tuxcare of keras."
      },
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f909d94-7647-5e67-b121-fa31528a07a9",
      "id": "CVE-2025-12638",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-12638 is a false positive for keras 2.15.0.post1+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75b7f8a6-9f02-5a9f-a61b-10c1f4d787c5",
      "id": "CVE-2025-9906",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-9906 affects version 2.15.0.post1+tuxcare of keras."
      },
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9a24c09-87d6-5fb2-a0af-2c0ecd877267",
      "id": "CVE-2026-0897",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-0897 affects version 2.15.0.post1+tuxcare of keras."
      },
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4258f2a9-0e4b-5858-a18d-ec4d230785bf",
      "id": "CVE-2026-1462",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-1462 does not affect version 2.15.0.post1+tuxcare of keras. Not applicable to keras 2.15.0: TFSMLayer was introduced in Keras 3.x; class and file (keras/src/export/tfsm_layer.py) do not exist in 2.x line. Per NVD, scoped to keras 3.13.0. Ref: https://nvd.nist.gov/vuln/detail/CVE-2026-1462"
      },
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e44064fa-690e-5f8c-bc85-a2e75d059559",
      "id": "GHSA-28jp-44vh-q42h",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-28jp-44vh-q42h is a false positive for keras 2.15.0.post1+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7199b33f-6bcd-55c8-8293-ca021da744db",
      "id": "GHSA-5478-v2w6-c6q7",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-5478-v2w6-c6q7 is a false positive for keras 2.15.0.post1+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/keras@2.15.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb387252-4d27-568d-83f1-30702f22abf7",
      "id": "CVE-2025-64340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64340 affects version 2.14.7.post1+tuxcare of fastmcp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/fastmcp@2.14.7.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20be0f88-4c2d-51a9-a926-181ccf21ee3a",
      "id": "CVE-2026-27124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27124 is fixed in version 2.14.7.post1+tuxcare of fastmcp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/fastmcp@2.14.7.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0206990-197c-5c73-9481-d7231a0b4f46",
      "id": "CVE-2026-32871",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32871 is fixed in version 2.14.7.post1+tuxcare of fastmcp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/fastmcp@2.14.7.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cce123dc-cec4-563d-a75e-bfa4df0b9372",
      "id": "CVE-2025-55197",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55197 is fixed in version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7dced148-7ed1-5d0b-9b39-b806a8c6a968",
      "id": "CVE-2025-62707",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-62707 is fixed in version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa8c2ca4-5e9e-5bc8-b16f-2882364f373f",
      "id": "CVE-2025-62708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-62708 is fixed in version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33d192b8-9dd1-55bf-968b-39d5eda3f846",
      "id": "CVE-2025-66019",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66019 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c127a6d-e266-58fd-a1be-3fb057dfe723",
      "id": "CVE-2026-22690",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22690 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac9e3ef7-1951-54cf-8829-4aff1418ecc2",
      "id": "CVE-2026-22691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22691 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7c85462-f73f-5942-a979-6f63ce66e2ee",
      "id": "CVE-2026-24688",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24688 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c5255fb-429f-588f-b8e6-2329365b2645",
      "id": "CVE-2026-27024",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27024 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c920e343-dd6d-5162-ae04-83d8a8039dc2",
      "id": "CVE-2026-27025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27025 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0111da5b-c1f5-5c1f-831c-85b85d42b85c",
      "id": "CVE-2026-27026",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27026 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a19b053c-9c4a-5096-98d2-b9c3372a1fdb",
      "id": "CVE-2026-27628",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27628 is fixed in version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf8af589-4d70-51bd-9ece-955a059c480c",
      "id": "CVE-2026-27888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27888 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b354f1fd-03ae-58dc-a523-46c7090f253f",
      "id": "CVE-2026-28351",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-28351 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75a928aa-a73d-5b17-a7f1-94e6aeebe174",
      "id": "CVE-2026-28804",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-28804 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a1a6fb3-e9f9-5db7-bf63-81772d189e30",
      "id": "CVE-2026-31826",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-31826 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:230b4d4b-f06a-5b0a-ab4b-3de2f742249d",
      "id": "CVE-2026-33123",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33123 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d1d72ae-55fd-5574-9c69-8e59da417f47",
      "id": "CVE-2026-33699",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33699 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ab1c242-3dfd-5f73-ac17-ba132ff83689",
      "id": "CVE-2026-40260",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40260 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52105181-8b10-5b55-b032-faf36b474868",
      "id": "CVE-2026-41168",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41168 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0af7b9b-3f0a-5cb3-93a5-5047483a38aa",
      "id": "CVE-2026-41312",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41312 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ddfcc83-4e72-5173-b33b-05173a1fa956",
      "id": "CVE-2026-41313",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41313 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71af69ca-1bde-5265-92f4-189175ada235",
      "id": "CVE-2026-41314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41314 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:794af869-4405-5d32-be9a-52bdcfba3c08",
      "id": "CVE-2026-48155",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48155 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f9057c2-70eb-5f25-a981-4949fe5a20c8",
      "id": "CVE-2026-48156",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48156 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15620ce5-e9a3-5e13-89c8-719212996b8e",
      "id": "CVE-2026-48735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48735 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08693af5-e419-5f54-a2f3-f70eb74ce26f",
      "id": "CVE-2026-49460",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49460 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ba315a4-2973-5a35-8fc1-9ade448a626c",
      "id": "CVE-2026-49461",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49461 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b0d557e-51ee-53f4-9c4a-3960c525db4a",
      "id": "CVE-2026-54530",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54530 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48c63b84-518f-5d51-9f38-8a1fb7967947",
      "id": "CVE-2026-54531",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54531 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93002daa-f7f6-5c58-b483-9b82c160527d",
      "id": "CVE-2026-54651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54651 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f169968-6d44-5878-bccd-0fc0d2ab125c",
      "id": "CVE-2026-59935",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59935 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:278e0323-3087-5562-8742-1c289df144b9",
      "id": "CVE-2026-59936",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59936 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e20f3af5-d3d6-5d20-82a6-3053ae6fe6ac",
      "id": "CVE-2026-59937",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59937 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7afd15a-1fdf-53dc-b2ee-4e62af30af44",
      "id": "CVE-2026-59938",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59938 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:490d180f-1beb-57fe-8de6-0673e86488d2",
      "id": "GHSA-4pxv-j86v-mhcw",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16b351c1-8738-5113-a2d9-d92015f150f1",
      "id": "GHSA-7gw9-cf7v-778f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a040e3e9-8e64-5150-ab29-a66955e64b70",
      "id": "GHSA-9m86-7pmv-2852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46bc5ff9-1a20-598b-a7eb-7ab24dc8e563",
      "id": "GHSA-jj6c-8h6c-hppx",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c240ff19-da5f-57c2-8ce5-4d5af52bc461",
      "id": "GHSA-jm82-fx9c-mx94",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-jm82-fx9c-mx94 affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6e4ecda-ac68-5b91-997d-b33e1cd8ecb5",
      "id": "GHSA-x284-j5p8-9c5p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-x284-j5p8-9c5p affects version 5.9.0.post4+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d6beb4b-fc1e-5a68-875a-cd87af2acec8",
      "id": "CVE-2026-25990",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25990 is fixed in version 11.3.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d66cac93-23e3-5075-a739-f7c6b0024769",
      "id": "CVE-2026-40192",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40192 is fixed in version 11.3.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc266347-4f74-557d-a4c7-39403ade570a",
      "id": "CVE-2026-42308",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42308 affects version 11.3.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c005d3c4-aeff-5404-a1df-c7bbdf1de2ea",
      "id": "CVE-2026-42309",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42309 affects version 11.3.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36fe5647-2a86-5b98-b4c3-49e9aa220b2d",
      "id": "CVE-2026-42310",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42310 affects version 11.3.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fc1a4a6-791b-51df-bb91-3c56d65196fa",
      "id": "CVE-2026-54058",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54058 affects version 11.3.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:924b5982-d46f-56fa-9c01-b70fd75126ab",
      "id": "CVE-2026-54059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54059 affects version 11.3.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5bf89f4e-690e-5565-a36c-4aef5ce0afef",
      "id": "CVE-2026-54060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54060 affects version 11.3.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98395d1f-2f64-5459-8626-fa6069d426b5",
      "id": "CVE-2026-55379",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55379 affects version 11.3.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:435144bf-d799-587f-a761-c318319c8060",
      "id": "CVE-2026-55380",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55380 affects version 11.3.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de9cc2b7-4695-5403-8aa6-d75c0387d13d",
      "id": "CVE-2026-55798",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55798 affects version 11.3.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44f97682-8d54-5aea-8d02-a12c1216c162",
      "id": "CVE-2026-59197",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59197 affects version 11.3.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6c46ae5-9bd8-505f-b6fc-aab0c651af4c",
      "id": "CVE-2026-59198",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59198 affects version 11.3.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68f9c47e-6eee-5d7b-b1f8-80714bea699d",
      "id": "CVE-2026-59199",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59199 affects version 11.3.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5402b0af-eb0d-5cca-8d0b-22a37065aed8",
      "id": "CVE-2026-59200",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59200 affects version 11.3.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:645a749d-957b-583e-a958-cd0f7a0676a7",
      "id": "CVE-2026-59204",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59204 affects version 11.3.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d574f4fe-a4c9-5390-8ee3-7d2c02fa6aef",
      "id": "CVE-2026-59205",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59205 affects version 11.3.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9944e60-418a-55c1-ab83-1fba91259102",
      "id": "CVE-2024-12797",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-12797 is a false positive for cryptography 45.0.7.post2+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@45.0.7.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8bbd0d1-9b86-5439-a873-7d73df4b688b",
      "id": "CVE-2026-26007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-26007 is fixed in version 45.0.7.post2+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@45.0.7.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:402039fc-04d5-5357-b0d9-071614a98fd0",
      "id": "CVE-2026-34073",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34073 affects version 45.0.7.post2+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@45.0.7.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5804a57b-94f5-55cb-868f-8f0360046fa0",
      "id": "CVE-2026-39892",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-39892 is fixed in version 45.0.7.post2+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@45.0.7.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abdf9999-32e5-5248-9e66-502745a08ec1",
      "id": "GHSA-537c-gmf6-5ccf",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-537c-gmf6-5ccf does not affect version 45.0.7.post2+tuxcare of cryptography. not_affected \u2014 The source repository does not contain OpenSSL source code. The vulnerability (GHSA-537c-gmf6-5ccf) affects OpenSSL bundled in binary wheels distributed on PyPI, not the cryptography source code itself. OpenSSL is downloaded and compiled during the wheel build process via build_openssl.sh, not present in the repository."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@45.0.7.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc808ca3-0e7e-5f36-98e3-6577c0adfc23",
      "id": "CVE-2022-33124",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-33124 is a false positive for aiohttp 3.8.1.post8+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82c37d67-ca33-5211-bd8e-254f7e8fdaf6",
      "id": "CVE-2023-37276",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-37276 is fixed in version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:921d6ec5-fcd3-5de1-841f-22ff98f126b8",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49081 is fixed in version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbe9fd23-2da0-5a67-8c43-e73cafc125be",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49082 is fixed in version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d181b42f-2793-55a1-987f-f6e4d2584d9e",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23334 is fixed in version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14cb1447-5f6f-5043-ac67-139d3908cf99",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23829 is fixed in version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2929e88-8813-5a5e-841f-fb469e68b5fa",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-27306 is fixed in version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d4ca5ac-5050-5835-8bbd-5e27e7045343",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-30251 is fixed in version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91e9ba74-abc6-5224-ab4b-416feeb9fb3a",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52304 is fixed in version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f2c72c7-3325-5be3-9b5a-ebac6cf70d9a",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53643 is fixed in version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3fcf7844-4e51-57ea-beed-72c0d09c63ec",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6073b5a2-89b0-59fa-89a0-3a7ae2862978",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53648aec-49c7-522a-928f-4ee6afcc4c38",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a185841-4ad4-5a55-a8f1-30aef965ede8",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4b0678b-239b-5dc8-b40b-fa11018c47a6",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52636317-43d5-50bf-9505-ba4348e3065d",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec12651e-6373-5a49-a668-45263d66c818",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0c7237a-80d5-5892-9a4e-02a1e3e9e998",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7728934b-1f04-5824-b1f5-ee63b6e3ca28",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22815 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57df598f-1702-5ce1-9b3a-3b7db3b539b1",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34513 is fixed in version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3564fabb-920d-59c6-9f68-685d30c368e9",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34514 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb6cf5cc-4206-5c50-a623-02072dee7305",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd08252e-5584-5eef-9ba8-20d2b5378cf3",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34516 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b965b7be-3c56-5626-bcaf-dc1dd0e5d304",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34517 is fixed in version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5cfd8cf8-7e50-5fd5-90e8-ae30cc027480",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34518 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32694423-fba6-57d8-bc9e-cd535aa0c57f",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34519 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26716d6f-2487-5208-b3cd-1b0cf8cb5cb7",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34520 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b85c733-f2bf-53f5-a6f2-0b0cfa1dbd48",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34525 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83e6f788-b589-53bc-862b-ddd8317485cf",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33bff859-502b-588d-a171-60521b1a9fb2",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a81c8324-277d-5ac7-be64-213f2fcdb1d9",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db182ab3-48c6-5e27-9b6e-c2046fa2b965",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff0f051e-4d90-5e93-a017-99c19034dbad",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ffe79d00-37a7-53dd-aec7-97d28ed1291a",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.1.post8+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40d38dae-3fc7-57f6-85c5-019ea070cf93",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.1.post8+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b663646-2231-5737-b03c-8a0358190373",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c62cfdf-c7b0-5cee-a911-a46df74361af",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63d1401b-d509-594f-89b5-2f61ee15847e",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc1e9983-1a75-52cf-9c9d-f5a9b30c02cf",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.1.post8+tuxcare of aiohttp. CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe"
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7d1b761-5a75-571d-881c-281173d0d2bd",
      "id": "GHSA-pjjw-qhg8-p2p9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-pjjw-qhg8-p2p9 is fixed in version 3.8.1.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2507522e-5e21-5e23-acb2-ec5b0d7a6831",
      "id": "CVE-2023-47627",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-47627 is fixed in version 3.8.5.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc379078-9d3b-574c-ba44-4f5e0a841e45",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49081 is fixed in version 3.8.5.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3954de1b-506f-563b-9c84-fdb9e20b6e80",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49082 is fixed in version 3.8.5.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d61244d0-910d-5c5d-9ef5-1f440d9e8ec4",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23334 is fixed in version 3.8.5.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad77548a-2cbe-5f36-90fc-7a74c4ab7552",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23829 is fixed in version 3.8.5.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab3b0514-9be4-5382-a062-e32826b19b21",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27306 affects version 3.8.5.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4cf24b97-258e-5711-9fb1-b2040dd16eb8",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-30251 affects version 3.8.5.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ae3f659-571d-5fc8-83ad-ac1d5febe6a9",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52304 is fixed in version 3.8.5.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3153bf05-59fc-5459-949e-80290607b3b8",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-53643 affects version 3.8.5.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:154af351-8d62-574a-9120-3d5193c28050",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.5.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40910355-b89e-5561-b93e-bda5445910ad",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.5.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1bf122c-0d69-5665-a423-5ecc68884df2",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.5.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18bf4ed2-54d1-522b-8095-f953097f6f48",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.5.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed99ae82-c68f-5b88-953e-1d032cc86486",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.5.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53df9f67-59c0-58e9-b700-45d4f4bd33b2",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.5.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff39e29a-3e79-54ca-bee0-11bd2252edf0",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.5.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e7077f8-c3c2-54a3-b1d6-b20561602cf1",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.5.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5599863-ef79-51f6-80c7-fd23d164d69b",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22815 affects version 3.8.5.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c43791aa-4576-5376-b464-9ca8c7dafa6e",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34513 affects version 3.8.5.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7415a158-e333-5121-99c0-cd56671e0223",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34514 affects version 3.8.5.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b2eba98-f23b-5ebe-9f0a-d13d67292ea1",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.5.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8e3d2f4-f849-53cc-8adb-7f506b41fb57",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34516 is fixed in version 3.8.5.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4eac8ea7-ca5b-513c-bf8f-cb0d0de96a54",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34517 affects version 3.8.5.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3768b7c-0773-57f7-86f6-afd5e14633ec",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34518 affects version 3.8.5.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f759fcbd-5d83-58ee-b5d8-ece28a47cf78",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34519 affects version 3.8.5.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee7f7dfe-7fac-5429-aa68-915a50fa2a73",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34520 is fixed in version 3.8.5.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:496ccbcf-c3e1-5af0-a178-328a5258af51",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34525 affects version 3.8.5.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0c5cd99-ed4c-5735-8682-b1eef40ab88d",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.5.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49afe2fb-b4d8-5f99-9fe7-1046676f933d",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.5.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc95301d-7c8d-544e-82a9-c10f5593539b",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.5.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9aee6279-2751-5a5a-8426-50c4b7d3ebc6",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.5.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8cd982a-5529-5fe8-a37b-ed407f3f3739",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.5.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:689dd72c-f98a-567c-84f1-cdfc989ec04f",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.5.post6+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf2bdb86-b161-53c3-bf14-dabfed03037b",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.5.post6+tuxcare of aiohttp. not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ba81399-3cbb-5042-a914-3b8187aeeb06",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.5.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d50574da-3e8f-56c3-8da2-2cdb7b6b1a52",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.5.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e65f0c8-bf2c-5529-84ef-61ff73a471f0",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.5.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9f5a2ab-4f03-58c1-b033-34720571120f",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.5.post6+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb78472b-4ce5-5c0a-9f02-9a89092d95ff",
      "id": "GHSA-pjjw-qhg8-p2p9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.5.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5221851-7662-54d7-b968-40f99733b32d",
      "id": "CVE-2023-47627",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-47627 is fixed in version 3.8.5.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94b39d03-3117-56c0-8e1c-c011512672f3",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49081 is fixed in version 3.8.5.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:291975c1-897e-529d-8c7e-76b49f73c3e5",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49082 is fixed in version 3.8.5.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54e5fc34-6fcd-55b7-9957-6395ef140318",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23334 is fixed in version 3.8.5.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a4e172a-fee2-562b-bdd3-afa1d9f1c975",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23829 is fixed in version 3.8.5.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:086de1a4-5ac6-5d20-8107-d83cf8cb44a6",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27306 affects version 3.8.5.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22bd14a6-4d96-58e3-b2c4-ca1faf9dbea2",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-30251 affects version 3.8.5.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:114f9ca9-daf3-5268-b455-b1c95623f429",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52304 is fixed in version 3.8.5.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7dfa5d4-7c2f-5b73-9320-c6cedc492fff",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-53643 affects version 3.8.5.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:817b4709-e453-519f-a971-448a6e001e6d",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.5.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a3e78db-c978-530e-9836-f28fa9d3a747",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.5.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea064bc3-b3ea-5feb-9917-74a98d9db56a",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.5.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6b9098c-36c9-5052-8d6a-8e8a2d04fe1a",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.5.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e756b8a3-9e60-5719-96ed-8eda4de360d2",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.5.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:538ad527-c648-5848-883f-e0a8426169f4",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.5.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33a77bbd-a693-5d92-9789-8df2ff372626",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.5.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:255c694a-fd50-59da-92f5-9744fa8d3c4c",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.5.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ccc5e587-46bc-56b8-b01f-c192b7980d94",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22815 affects version 3.8.5.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dda441b3-d6a1-5498-8547-298cf9ddf9b2",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34513 affects version 3.8.5.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6099872e-16bb-5ca5-93ca-bfe03d7ceaea",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34514 affects version 3.8.5.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e875538b-0d2e-57b9-9c48-26461053108e",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.5.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b13c0f92-7b62-5cc0-adff-d8ba696e9220",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34516 is fixed in version 3.8.5.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e471f0df-4f15-5f16-8063-0e2727be690b",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34517 affects version 3.8.5.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36a98d0f-3121-57b5-a59c-12eaa4e8e223",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34518 affects version 3.8.5.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db21b84b-a8e8-57b9-9cb3-b8229a9b4a3d",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34519 affects version 3.8.5.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af2acd64-eb54-57b6-835d-589032cef7d2",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34520 affects version 3.8.5.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:230bab29-de55-54c2-9c81-b34e6a13a839",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34525 affects version 3.8.5.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2f31e92-88b6-574d-9dc9-96e9c183ea86",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.5.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06d37247-c0de-5208-8510-8a765bda16a1",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.5.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:637db210-7387-5428-b211-4e470ca77625",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.5.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17c9cb80-4003-5e68-b40a-0ca4982f5972",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.5.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c408e970-cdd8-5d07-a20e-c3416dc5fe1e",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.5.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98ba69a5-974e-5a88-acf6-b3086e2849dd",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.5.post5+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e5dcc4e-904a-500c-8823-7ae5fb217cc6",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.5.post5+tuxcare of aiohttp. not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7dec14fb-f7aa-5b1d-9cb6-3e9e623c8df9",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.5.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cafd9b86-1117-5bcd-bae9-19c9152baa40",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.5.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6afc54e-f584-535d-8751-bc4a70c53480",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.5.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6907f253-22a5-50c2-a757-4d79882aab90",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.5.post5+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0baa0bfd-6386-5ced-8bf9-aab42900d227",
      "id": "GHSA-pjjw-qhg8-p2p9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.5.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ca51692-c63e-5a7f-a6e5-b51077a1f2fd",
      "id": "CVE-2023-37276",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-37276 is fixed in version 3.8.4.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc4e0267-f4bf-5206-9268-4abd386c7d29",
      "id": "CVE-2023-47627",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-47627 affects version 3.8.4.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81a36dc7-92ac-5dfd-8751-cf922ab832b2",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-49081 affects version 3.8.4.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22d65425-79f4-55b2-a83d-cdb883e13e1a",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-49082 affects version 3.8.4.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f376d77e-4685-52ae-99a6-afbd29bbaf4f",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23334 affects version 3.8.4.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c84e6697-d520-5f9c-98d1-8728eb2f2d66",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23829 affects version 3.8.4.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec89ea39-e1d8-581a-b16b-b534f16d941f",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27306 affects version 3.8.4.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42dbf069-e516-5f86-9b27-13f8c078a9a8",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-30251 affects version 3.8.4.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4bb32a37-e521-53de-a0f4-c878d2fc2df3",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52304 affects version 3.8.4.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:208638e7-b79c-5868-9b6a-c2d54ebd85f1",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-53643 affects version 3.8.4.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0bca31d2-c1e1-5717-95dd-7d32052f6523",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.4.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc77913d-f37d-5bc9-9377-bf75db1110ad",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.4.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7a36228-bfbc-532d-9a1a-4a67b438522a",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.4.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25d1e74d-c977-5b33-b375-e3863fa9dd2f",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.4.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3024e8ad-68f6-53ee-b126-aba3632efcac",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.4.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94601d9d-8f9a-5c92-81ad-7b91543f32c6",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.4.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06c56b44-d422-5877-8d09-660ae132b9a4",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.4.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f505eda-4a08-5c42-86b8-d5ccd585c0a3",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.4.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:897508b2-c577-52a9-b401-72d47c3eaad2",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22815 affects version 3.8.4.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76bf1246-99d9-5766-9488-a1febcd47c32",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34513 is fixed in version 3.8.4.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8bb9e82-eb85-5de5-9722-b3dd23050262",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34514 affects version 3.8.4.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c515cd8a-fb2d-57f2-95b9-27431ea7d93a",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.4.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:703d647e-7a94-55ac-9cfc-875a76281b42",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34516 is fixed in version 3.8.4.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5e0c84b-b118-58fb-94e5-380718e9bce6",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34517 affects version 3.8.4.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbd9c7bc-8824-5f28-a33c-7d573c2b479c",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34518 affects version 3.8.4.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9edcfde6-2f30-5da0-adfe-9092908d5555",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34519 is fixed in version 3.8.4.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfafa3e8-f454-56a2-aba9-58a79a064465",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34520 is fixed in version 3.8.4.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9394a005-3f84-5523-81d9-47ad93ee4a1a",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34525 affects version 3.8.4.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2780c616-d452-5dff-8a7f-ccb4caff992f",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.4.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe8e5202-3d9e-5f79-a918-a86b3a2d95b5",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.4.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:936336db-4f75-5e25-9315-625d3f23f2aa",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.4.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3932ad9e-9bd8-53fb-a6eb-856cce5af653",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.4.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b351d26-9a02-598d-ab17-2f5e354fcb12",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.4.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a39447ed-b24b-5531-b1f6-36bc45dc78ed",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.4.post2+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.4.post4+tuxcare. The vulnerability requires the server_hostname parameter feature, which was not added until version 3.9.0+ (August 2023), six months after version 3.8.4 was released (February 2023). The target version cannot receive the malicious input described in the CVE."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f90c68ea-8778-5f02-8d1c-045923e25885",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.4.post2+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.4.post4+tuxcare) does not contain the DigestAuthMiddleware component. This feature was introduced in aiohttp version 3.12, which postdates the target version. The vulnerability cannot manifest because the affected code does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:244165a3-fbf4-5a91-bdac-4526643552b2",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.4.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86067029-c280-55e1-af1c-cde7815e706e",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.4.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86a4b278-d036-5fe4-b016-00c3d2bd287b",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.4.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d1ab96f-6e47-5dbd-ac84-da7d13670b22",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54280 affects version 3.8.4.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18030291-9d33-509a-8c3e-c48b0475fcb3",
      "id": "GHSA-pjjw-qhg8-p2p9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.4.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe65d30c-385f-5c53-8afa-80f96c7a453d",
      "id": "CVE-2021-33503",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-33503 is fixed in version 1.25.11.post5+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4172af88-7a61-5872-9700-ac1c661caa76",
      "id": "CVE-2023-43804",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-43804 is fixed in version 1.25.11.post5+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bcdc3c1-4c03-5b31-a304-43fa5706fa25",
      "id": "CVE-2023-45803",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45803 is fixed in version 1.25.11.post5+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:566aa46d-7697-5a96-bb62-46fbd1da1f95",
      "id": "CVE-2024-37891",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-37891 is fixed in version 1.25.11.post5+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62858adf-6ed4-53f0-91bd-fbcb54e98d91",
      "id": "CVE-2025-50181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-50181 is fixed in version 1.25.11.post5+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d064c6d-7d7c-5feb-a6a5-8c6aab4cdaf7",
      "id": "CVE-2025-66418",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66418 is fixed in version 1.25.11.post5+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49ac08f2-d582-5892-bab6-143fd800db11",
      "id": "CVE-2025-66471",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66471 is fixed in version 1.25.11.post5+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:005bbebc-1a52-5e7d-88cd-12ea58a5ed2d",
      "id": "CVE-2026-21441",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-21441 affects version 1.25.11.post5+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2dff7d9b-0d02-52c5-985a-7f81a8c26c28",
      "id": "CVE-2026-44431",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44431 affects version 1.25.11.post5+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f444583-6a24-5ea3-95a2-5fdbc34b7158",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-49081 affects version 3.8.6.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f97cc248-90bd-5356-81e0-d9173557c5e7",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49082 is fixed in version 3.8.6.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e32eed8-a928-5833-a003-b721209add39",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23334 affects version 3.8.6.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb2cba2c-5154-5dc9-98f1-06f60e377d78",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23829 affects version 3.8.6.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a97c0449-678c-5b68-8d0d-bc5a8eed7d62",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27306 affects version 3.8.6.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3258bbfa-f644-544e-a52f-03a3058b5e4f",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-30251 is fixed in version 3.8.6.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87bfbbb3-8fe3-5573-bac6-a244299084bc",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52304 affects version 3.8.6.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ceb62b70-9220-52fc-9ab0-0b3ee8a45d74",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-53643 affects version 3.8.6.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:803750ad-1523-5f00-91dc-52b4cd954caa",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.6.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34a35702-9981-52a9-95cd-616a1b7d9ab8",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.6.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d61ba558-8007-5a23-841c-0097d528dab2",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.6.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7316941-b600-5147-8361-e4ca8a7ea9f9",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.6.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d746c110-7a8b-5d84-8ecb-0aa7e91cda2a",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.6.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6d6052f-b58d-5767-93f7-bc99b647ed74",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.6.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63baa90e-648e-52f3-9395-ffb1703e5009",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.6.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7718d283-f419-5f7d-b07c-77e205ce647d",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.6.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:896118f5-7120-5db6-8e89-705517b8508d",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22815 is fixed in version 3.8.6.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eccc6b62-aa71-5405-a86d-fe783216bf1b",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34513 is fixed in version 3.8.6.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbe44a37-0529-59d0-b7e6-5a51de9f3441",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34514 affects version 3.8.6.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b15093cc-90ab-53e0-a13a-27a797c0a77f",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.6.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8d2f25e-00e3-5108-85d0-8271d08fd1b0",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34516 is fixed in version 3.8.6.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20459496-e0e7-5452-8087-dfdf45704530",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34517 is fixed in version 3.8.6.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:754e2e4c-0a02-51fe-8646-0cd61805f6c7",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34518 affects version 3.8.6.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dabd228a-cc36-543f-95d4-4feae550a2c4",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34519 is fixed in version 3.8.6.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d618b0af-5032-57ea-8c30-8b762850b6c7",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34520 is fixed in version 3.8.6.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ff2663d-8e4d-5a99-b313-e3e62e2937ba",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34525 is fixed in version 3.8.6.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af411995-4821-5a41-9468-a0e9d8e69971",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.6.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5392b600-3479-5503-b10a-431ac5054c34",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.6.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ed85e70-f04a-549e-b596-24756aee93f9",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.6.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6a9dee3-5d08-527c-af60-faea39048d40",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.6.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f1cf95c-669c-5f60-823c-b621cbe1a58b",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.6.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f00d033f-1381-5827-8119-b0dac81420be",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.6.post4+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f64cf2cd-34d2-58f3-875e-0d1f5a12b712",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.6.post4+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c85f626-414e-58ba-aa86-7b36dc468e2d",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.6.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4f58d80-e955-59f7-8f1e-c314c8fc6ff2",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.6.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5596fbee-60c3-5847-9351-0d2d5f3b7752",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.6.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f460987f-6f1f-5331-82f2-81254299efab",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.6.post4+tuxcare of aiohttp. Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46845ef2-9427-5c3b-9ec2-94132f07d7a1",
      "id": "CVE-2026-25990",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25990 is fixed in version 10.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5775e6e-81a8-5579-9d85-3efb898cae10",
      "id": "CVE-2026-40192",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40192 is fixed in version 10.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0c24512-ab03-5842-ae68-42ff6bf9c7c6",
      "id": "CVE-2026-42308",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42308 affects version 10.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:675d245b-c3d3-5d87-b78a-4b12d2867b60",
      "id": "CVE-2026-42310",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42310 affects version 10.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61a8648f-628d-5a52-8c64-af47be620555",
      "id": "CVE-2026-42311",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42311 affects version 10.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9319112f-0762-5773-87b0-97b2a5f806c6",
      "id": "CVE-2026-54058",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54058 affects version 10.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d73aa2dc-5889-5093-a6b5-5dd5c9730533",
      "id": "CVE-2026-54059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54059 affects version 10.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fd40dbc-3043-5724-a179-82ef6db3a48b",
      "id": "CVE-2026-54060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54060 affects version 10.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e7bb2b7-97c8-5ace-abb9-4cb29b56cbdb",
      "id": "CVE-2026-55379",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55379 affects version 10.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f7d6ae3-fc8d-507f-8c6a-42cb921d8e44",
      "id": "CVE-2026-55380",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55380 affects version 10.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:edab5cd2-d48e-539c-af21-5d38b8568992",
      "id": "CVE-2026-55798",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55798 affects version 10.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9906f1a8-4316-5925-956e-236d7624a891",
      "id": "CVE-2026-59197",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59197 affects version 10.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37c6e332-24e4-5681-b6db-4050cf9e0803",
      "id": "CVE-2026-59198",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59198 affects version 10.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41972094-6e29-566e-92fe-a878e0bb68e7",
      "id": "CVE-2026-59199",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59199 affects version 10.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5316f2a-552a-5b11-9b07-4d25a3677d41",
      "id": "CVE-2026-59200",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59200 affects version 10.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c537876a-5deb-5ea3-a1b5-4eb60b5c4f4e",
      "id": "CVE-2026-59204",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59204 affects version 10.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfac7d75-940e-571a-8eeb-b5d586be64de",
      "id": "CVE-2026-59205",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59205 affects version 10.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56b570e2-082c-5712-98e3-22a7ddfe3523",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-49081 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12cb4bf4-0ccf-58ec-8c38-ae1d4ba766e2",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49082 is fixed in version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6c11800-6536-5c4a-b849-ac5fac3878b8",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23334 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16af813d-bc67-5605-b7b2-76f8f7850e7b",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23829 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2741d217-bc6f-5d8d-ab0a-9ba4cb54079b",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27306 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ccd095b6-bf2f-51b3-a0c3-f7ac68e3e3b6",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-30251 is fixed in version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4d5b549-524e-5077-9ed5-3dec7f48fab9",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52304 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:839ee2bb-f1d2-5f8c-b711-a3618f7502e5",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-53643 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec59f775-e5b3-56e3-b809-d9ecf1242c92",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be262416-0742-5e7b-83fa-be29cc08b94d",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c6b5eec-e142-50d2-9329-40dd355aaf7f",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6674be27-b66f-5334-a858-b88d0e39f804",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60d369e5-6c98-5bd7-a335-72d63ceb238b",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f58fdc1c-1f53-5ccb-8f08-91fa4b8b26d3",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c5a295c-6abc-5082-a826-188a2a0b1f06",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2497f4c-ef10-5aff-8a20-8bd067718563",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:093880df-b5d8-5684-aeec-0a4a5408e318",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22815 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a8f8911-a519-5f12-8ce2-933590a093e0",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34513 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ea649f2-97f7-54f8-ba13-cc9ef151f78c",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34514 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c8a458d-be1a-5e4a-b6d6-783ef8cd08c1",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:deac2fb0-06d7-55c2-9056-856385577b02",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34516 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9d0c7c6-3a5f-5297-9e96-ba548a043e31",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34517 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9084c4f5-4414-5dc7-b980-6e1ec911d9ba",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34518 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36a08db5-d61e-5c38-ae35-8aeeef8b2f1f",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34519 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40e27d29-6e23-5d69-aa9d-8dcd708342c5",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34520 is fixed in version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4915f281-2245-5f7d-ba2b-838095aac910",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34525 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ca0d99e-2108-54a4-a6a1-2cdb81caa899",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2477986-95e8-5fe3-ad0b-9700ade50b5a",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3265b9cb-b1e2-59cd-87ab-dc73de3393b6",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06dcfc4a-0adf-5f48-a15b-0803c2f8ec54",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:002aebb5-ed81-5dee-9b1f-b5867681f01b",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:961a7e1a-6462-55f1-9a2f-7b5809322240",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.6.post3+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bea350cc-b477-53da-a279-0a2f0874696b",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.6.post3+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f8f4362-d5b6-59ee-82ad-552c45a9ece6",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7352166-0cf8-59d2-8217-a00032d18b2f",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c43adb7-2c8b-5a72-88d2-b2a4877034aa",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.6.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8581331-38a2-58ee-b9bb-cacb110e8ed6",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.6.post3+tuxcare of aiohttp. Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:beebd70f-1621-51de-837f-b9efaf18a162",
      "id": "CVE-2023-28370",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28370 is fixed in version 6.1.0.post2+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a99baeef-7a17-502e-af65-af5c82f58d21",
      "id": "CVE-2024-52804",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52804 is fixed in version 6.1.0.post2+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7c803eb-8bfd-5d7f-8838-9deda73bbf3d",
      "id": "CVE-2025-47287",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-47287 is fixed in version 6.1.0.post2+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7144733d-b66c-552f-b788-a1149fbea0ee",
      "id": "CVE-2025-67724",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67724 affects version 6.1.0.post2+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59557910-0acb-576f-a909-96c79f18171a",
      "id": "CVE-2025-67725",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67725 affects version 6.1.0.post2+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfe7f712-a60c-5e8c-ac9d-b0db574798c4",
      "id": "CVE-2026-31958",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-31958 is fixed in version 6.1.0.post2+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32f896a1-f3cd-5baf-94de-836d3dc4296f",
      "id": "CVE-2026-35536",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-35536 is fixed in version 6.1.0.post2+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df0a6d44-1b92-56d9-b9d6-8fee9690e3c3",
      "id": "CVE-2026-49853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49853 affects version 6.1.0.post2+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba85e927-ac20-5601-ada8-8456f271c232",
      "id": "CVE-2026-49854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49854 affects version 6.1.0.post2+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9fdbb84-18df-56c5-ae6c-35870d85733b",
      "id": "CVE-2026-49855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49855 affects version 6.1.0.post2+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e0eff7f-07a8-5fc8-863f-09faf470b6bd",
      "id": "GHSA-753j-mpmx-qq6g",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-753j-mpmx-qq6g is fixed in version 6.1.0.post2+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbee4f47-897b-54ac-81b0-33b4726e860e",
      "id": "GHSA-78cv-mqj4-43f7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-78cv-mqj4-43f7 is fixed in version 6.1.0.post2+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b503c22-328a-57b6-ad94-5b5fe0501fb0",
      "id": "GHSA-pw6j-qg29-8w7f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-pw6j-qg29-8w7f affects version 6.1.0.post2+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd98ec99-d46e-54c3-8759-87329c8a2659",
      "id": "GHSA-qppv-j76h-2rpx",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-qppv-j76h-2rpx is fixed in version 6.1.0.post2+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc2f686f-416e-5e4a-b034-88e698d3e382",
      "id": "GHSA-w235-7p84-xx57",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-w235-7p84-xx57 is fixed in version 6.1.0.post2+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dad01203-abeb-5dbb-919c-b7cf9e00dc2c",
      "id": "CVE-2026-27448",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27448 is fixed in version 24.3.0.post2+tuxcare of pyopenssl."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyopenssl@24.3.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1cfd16e5-d717-562f-98bc-72e7e0da0281",
      "id": "CVE-2026-27459",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27459 is fixed in version 24.3.0.post2+tuxcare of pyopenssl."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyopenssl@24.3.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31df8ba2-21a6-56b9-8b58-85c48d9a5b2e",
      "id": "CVE-2025-65106",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-65106 affects version 0.3.83.post1+tuxcare of langchain-core."
      },
      "affects": [
        {
          "ref": "pkg:pypi/langchain-core@0.3.83.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:edbccda0-e578-5bf5-bd50-89071afd4752",
      "id": "CVE-2026-26013",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-26013 affects version 0.3.83.post1+tuxcare of langchain-core."
      },
      "affects": [
        {
          "ref": "pkg:pypi/langchain-core@0.3.83.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f7d97df-8c7a-51be-8749-6fb2391b3d5b",
      "id": "CVE-2026-34070",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34070 is fixed in version 0.3.83.post1+tuxcare of langchain-core."
      },
      "affects": [
        {
          "ref": "pkg:pypi/langchain-core@0.3.83.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6570cc0e-da6f-5b57-8ba0-9ba84f868ea1",
      "id": "CVE-2026-44843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44843 affects version 0.3.83.post1+tuxcare of langchain-core."
      },
      "affects": [
        {
          "ref": "pkg:pypi/langchain-core@0.3.83.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc404611-7e04-5b70-8c66-58fe6b2f282b",
      "id": "CVE-2026-27448",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27448 is fixed in version 25.3.0.post1+tuxcare of pyopenssl."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyopenssl@25.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30f24c83-5748-5205-8bf6-aad9ed9716b2",
      "id": "CVE-2026-27459",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27459 is fixed in version 25.3.0.post1+tuxcare of pyopenssl."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyopenssl@25.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d114fc34-85fe-5005-ae13-5216285bdfc8",
      "id": "CVE-2026-27448",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27448 is fixed in version 24.3.0.post1+tuxcare of pyopenssl."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyopenssl@24.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7394511c-c36e-585d-a869-21f373165ea6",
      "id": "CVE-2026-27459",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27459 is fixed in version 24.3.0.post1+tuxcare of pyopenssl."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyopenssl@24.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23bf3df0-8ddd-5788-bfa7-2b51a67880c5",
      "id": "CVE-2026-27448",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27448 is fixed in version 23.3.0.post1+tuxcare of pyopenssl."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyopenssl@23.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f880df9-70f0-5577-9bfc-e7066dd6636a",
      "id": "CVE-2026-27459",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27459 is fixed in version 23.3.0.post1+tuxcare of pyopenssl."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyopenssl@23.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cdd65362-92f3-573c-a6bc-c2867289facd",
      "id": "CVE-2023-6709",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-6709 is fixed in version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b043afea-771a-5a20-a051-e54c6f6f8263",
      "id": "CVE-2023-6753",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-6753 is fixed in version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c417710-059b-5567-a2cd-451c50f952a0",
      "id": "CVE-2023-6831",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-6831 affects version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4290a4a1-6d2c-5953-87af-b06c7dd05165",
      "id": "CVE-2023-6909",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-6909 is fixed in version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:221498f1-9af5-5500-baf1-0f5678b325f0",
      "id": "CVE-2023-6940",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-6940 affects version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:607faeef-4968-570d-90db-b943617cfb37",
      "id": "CVE-2023-6974",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-6974 is fixed in version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0b480fd-f931-568f-ba7f-da55764ee972",
      "id": "CVE-2023-6975",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-6975 is fixed in version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15022ff6-fe20-5e3d-abf6-c052cc0f74c1",
      "id": "CVE-2023-6976",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-6976 affects version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f65ced4-a3eb-566c-b71f-701bb5ee23c1",
      "id": "CVE-2023-6977",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-6977 affects version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d01b4c6-72a3-5499-8d3f-6a84f3546c1e",
      "id": "CVE-2024-1483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-1483 affects version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de679acc-cd06-5410-96e5-f1d32da70337",
      "id": "CVE-2024-1558",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-1558 affects version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:041e2d58-c3b5-5430-83be-7ba2cfffa742",
      "id": "CVE-2024-1560",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-1560 affects version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75383691-f0bc-53c7-8aeb-87f12493ebc0",
      "id": "CVE-2024-1593",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-1593 is fixed in version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f70fa449-5874-530c-a403-131d761e96f0",
      "id": "CVE-2024-1594",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-1594 affects version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:267de71d-a78c-595d-b19a-a26667fec451",
      "id": "CVE-2024-27132",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-27132 is fixed in version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0cbeb77b-daf5-5424-a1c4-fbe55f90b79a",
      "id": "CVE-2024-27133",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-27133 is fixed in version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92f07dc3-017c-5462-9857-ae9de705210c",
      "id": "CVE-2024-27134",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-27134 is fixed in version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8d60ac9-1d68-5b2f-ba89-74478a9f83bc",
      "id": "CVE-2024-2928",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-2928 is fixed in version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59b57e5f-bff1-58ca-b6aa-1f2f71864ffa",
      "id": "CVE-2024-3099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-3099 affects version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c8d2cd1-73a4-5094-ac89-27c70deb4fc7",
      "id": "CVE-2024-3573",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-3573 is fixed in version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfc7b56d-cb91-5aff-8258-d9dcb0689095",
      "id": "CVE-2024-37052",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-37052 does not affect version 2.9.1.post2+tuxcare of mlflow. already_fixed \u2014 The target MLflow 2.9.1 codebase contains the fix for CVE-2024-37052 (unsafe pickle deserialization in scikit-learn model loading). The MLFLOW_ALLOW_PICKLE_DESERIALIZATION environment variable check was added in prior TuxCare backports (commits d58ee98ca for initial guard, 98a32847a for CVE-2024-37056, cf8bc9c26 for CVE-2024-37053). However, the defense defaults to True (allowing deserializatio..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12e1aa73-3dfd-5e95-8ac5-4a08b6034700",
      "id": "CVE-2024-37053",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37053 affects version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac9d2c71-1606-517b-8133-a8144060d6c6",
      "id": "CVE-2024-37054",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37054 affects version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0156bf1-99c4-560a-9010-315ac3dc5c64",
      "id": "CVE-2024-37055",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37055 affects version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3cefe2bd-06ea-5ec9-ba8d-20763e33142e",
      "id": "CVE-2024-37056",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-37056 is fixed in version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b52dc552-997c-5eb2-b04c-cc80c3f1762d",
      "id": "CVE-2024-37057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37057 affects version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48d3834f-a78c-547e-9440-abeb9d3f03d2",
      "id": "CVE-2024-37058",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37058 affects version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6b517fc-29f7-54fb-8a60-0a64caf99857",
      "id": "CVE-2024-37059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37059 affects version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:196a489f-8279-5c97-bae2-a593459ec464",
      "id": "CVE-2024-37060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37060 affects version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:128abd1c-3e84-5851-8d54-dd420608fead",
      "id": "CVE-2024-37061",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37061 affects version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab9fb75f-55ef-519e-a676-31fe6c824af2",
      "id": "CVE-2024-4263",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-4263 affects version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d298a7a-6386-53c2-8926-585c3aee5eda",
      "id": "CVE-2024-6838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6838 affects version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08db8f66-bd31-535e-806b-34a17eb5a002",
      "id": "CVE-2024-8859",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8859 affects version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:889a7f5f-49ec-5b10-8a48-d9d6c0b7fcc9",
      "id": "CVE-2025-0453",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-0453 affects version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:346f815d-6919-52fd-b1b4-4b8e5f061191",
      "id": "CVE-2025-10279",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-10279 is fixed in version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:219d62b4-c9f3-5331-9cbb-8d7171531d54",
      "id": "CVE-2025-11200",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11200 affects version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26adabd5-4c1f-526b-be4d-87d894b23c54",
      "id": "CVE-2025-11201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11201 affects version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbb432ca-7c04-5b33-9447-1995a22621a9",
      "id": "CVE-2025-14279",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-14279 is fixed in version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b14d952e-19b8-530b-8f0b-cde5289fe4c7",
      "id": "CVE-2025-14287",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-14287 is fixed in version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:562e3875-3fc9-5bc9-8544-70da85223490",
      "id": "CVE-2025-1474",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-1474 affects version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:215f4c33-e342-591e-9732-0b5e5e2ea5b4",
      "id": "CVE-2025-15031",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-15031 affects version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:083a3aeb-4cd7-5c7a-8a2f-ac67ae210bf6",
      "id": "CVE-2025-15036",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-15036 affects version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a8c5b1c-12e0-5bf4-a0f3-06555e6f7edb",
      "id": "CVE-2025-15379",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-15379 affects version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44bb767f-e6c0-533e-945c-7f58d7f42101",
      "id": "CVE-2025-15381",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-15381 does not affect version 2.9.1.post2+tuxcare of mlflow. not_affected \u2014 MLflow version 2.9.1 does not contain tracing and assessment features. These features appear to have been introduced in a later version of mlflow. The vulnerability pattern described in CVE-2025-15381 (missing permission validators on tracing and assessment endpoints when basic-auth is enabled) cannot exist in a version that does not have these endpoints."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2925ad9-5832-5317-afe1-e59e664c57aa",
      "id": "CVE-2025-52967",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52967 is fixed in version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f03bfe1-7967-59b5-afd4-b2e8932cb97f",
      "id": "CVE-2026-0545",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-0545 affects version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8c36cd3-4094-58d7-b01c-94d585e2338d",
      "id": "CVE-2026-0596",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-0596 affects version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:371750d8-f0c5-5038-9699-7c17fafdfd81",
      "id": "CVE-2026-10803",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10803 affects version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ce1d04c-4d5c-5d33-96ce-abab342192ea",
      "id": "CVE-2026-2033",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-2033 is fixed in version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2362b73-8fd5-5dbe-863a-2efcb0f3f25d",
      "id": "CVE-2026-2393",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2393 affects version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0381247-e572-518c-8a38-3424176ca05c",
      "id": "CVE-2026-2614",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-2614 does not affect version 2.9.1.post2+tuxcare of mlflow. Version 2.9.1 is not vulnerable. Summary: The target repository (MLflow v2.9.1.post4+tuxcare) does not contain the vulnerable code pattern described in CVE-2026-2614. The vulnerability was introduced in version 3.5.0 (September 2025) when prompt registry support was added to webhooks. The target version predates the introduction of the vulnerable feature by approximately 21 months."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a99741b-2b64-58b8-8f55-089f32e24235",
      "id": "CVE-2026-2635",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-2635 is fixed in version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5cf32e8d-5030-5901-8ceb-bdcd1684cb0c",
      "id": "CVE-2026-2651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2651 affects version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a7f24fc-92e1-5c44-b07d-bf80f9e20cdd",
      "id": "CVE-2026-2652",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2652 affects version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2b2d51f-c3f3-5275-ac2b-f5948a72cb65",
      "id": "CVE-2026-2734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2734 affects version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24ea4c41-943e-5ffd-97f2-023ef2c7fb02",
      "id": "CVE-2026-3198",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-3198 does not affect version 2.9.1.post2+tuxcare of mlflow. not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-3198. The vulnerability describes missing authorization checks for Gateway API list endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in MLflow 3.9.0's basic-auth integrated server. Version 2.9.1 has a fundamentally different architecture: the Gateway runs as a separate FastAPI application with no integration to the Fl..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de62c523-84a3-5948-bc3f-2ed23f2c3f47",
      "id": "CVE-2026-33865",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33865 affects version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:043e6311-bc49-5013-8689-a7f85879e2a2",
      "id": "CVE-2026-33866",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33866 affects version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:478161a4-4490-5ee6-9b13-02e2ab63d4b4",
      "id": "CVE-2026-4035",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-4035 affects version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e230294-b896-57c3-aa5f-9c9d1643992a",
      "id": "CVE-2026-4137",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-4137 affects version 2.9.1.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00b4dfd4-1f17-51f5-ab76-0670c140b5f0",
      "id": "CVE-2024-37059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37059 affects version 2.22.4.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf71a990-4ca1-569e-9f86-17d69adedcf5",
      "id": "CVE-2025-10279",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-10279 is fixed in version 2.22.4.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53872e1c-4e45-5bee-a5e4-1c86c09deb79",
      "id": "CVE-2025-14279",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-14279 is fixed in version 2.22.4.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e91aa31-5d82-56f1-9294-85ee5f1b328f",
      "id": "CVE-2025-14287",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-14287 is fixed in version 2.22.4.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3895ea6c-22e3-5514-90b0-893a6667acaa",
      "id": "CVE-2025-15031",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-15031 is fixed in version 2.22.4.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4dbc74e-8e50-511c-b56a-21b07d5d7542",
      "id": "CVE-2025-15036",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-15036 does not affect version 2.22.4.post2+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bce7935-bd30-50d6-bf65-be15ebf84484",
      "id": "CVE-2025-15379",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-15379 affects version 2.22.4.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a03c0d8-4911-57d5-bc9f-c9fa669e7f31",
      "id": "CVE-2025-15381",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-15381 affects version 2.22.4.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ea63302-b4a8-5846-b599-3862e92d542e",
      "id": "CVE-2026-0545",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-0545 does not affect version 2.22.4.post2+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb4bae97-d300-551e-a59c-2e9eb50ed0f3",
      "id": "CVE-2026-0596",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-0596 affects version 2.22.4.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01a442ae-b646-55ea-ac2f-e1416be7d2ce",
      "id": "CVE-2026-10803",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10803 affects version 2.22.4.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cad29fb1-86fa-560e-842c-4d05c6a59382",
      "id": "CVE-2026-2033",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-2033 is fixed in version 2.22.4.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e52e27f3-9849-52ff-8a98-a4047009e12a",
      "id": "CVE-2026-2393",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-2393 does not affect version 2.22.4.post2+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68edfe6a-45a9-5497-b4d4-7b019f332b89",
      "id": "CVE-2026-2614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2614 affects version 2.22.4.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61b967d1-baff-5f99-bc70-27c694104180",
      "id": "CVE-2026-2635",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-2635 is fixed in version 2.22.4.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e58cb79d-570c-5d5d-81d5-c7acb4f76927",
      "id": "CVE-2026-2651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2651 affects version 2.22.4.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6738ffe1-64c3-574d-b71d-b1fe66275224",
      "id": "CVE-2026-2652",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-2652 does not affect version 2.22.4.post2+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b017e6be-bbf4-560a-a5d4-35a8a7a8a664",
      "id": "CVE-2026-2734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2734 affects version 2.22.4.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a922ace0-a806-5e31-a9b4-93fef8699edc",
      "id": "CVE-2026-3198",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-3198 does not affect version 2.22.4.post2+tuxcare of mlflow. not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:245f1105-e7aa-5c35-b6ce-064c50c88403",
      "id": "CVE-2026-33865",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33865 affects version 2.22.4.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c81ab4a-d243-5b18-8c59-c12bdaff3e62",
      "id": "CVE-2026-33866",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33866 does not affect version 2.22.4.post2+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ddd81d3b-d71a-51e5-adb0-e3203947a67e",
      "id": "CVE-2026-4035",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-4035 affects version 2.22.4.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4220ce91-adfa-56ca-9338-4bb4c7430a28",
      "id": "CVE-2026-4137",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-4137 affects version 2.22.4.post2+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9835d892-af97-510b-bf25-8dd9d75300e4",
      "id": "CVE-2022-29217",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29217 is fixed in version 1.7.1.post2+tuxcare of pyjwt."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3501b429-afaf-53f3-9893-3049a3cfcb9c",
      "id": "CVE-2026-32597",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32597 is fixed in version 1.7.1.post2+tuxcare of pyjwt."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:587bfc7d-d8d0-53c5-9723-e1b747eca35b",
      "id": "CVE-2026-48522",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-48522 does not affect version 1.7.1.post2+tuxcare of pyjwt. not_affected \u2014 Version 1.7.1 is not affected by CVE-2026-48522. The vulnerability concerns PyJWKClient accepting non-HTTP(S) URL schemes (file://, ftp://, data:) without validation, enabling local file read and SSRF. However, PyJWKClient class does not exist in version 1.7.1 - it was introduced in later versions (tested vulnerable in 2.11.0 and 2.12.1). The affected component and its entire remote JWKS fetchi..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d7fab7b-a3fc-52ff-bf93-ec8672d81f28",
      "id": "CVE-2026-48524",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-48524 does not affect version 1.7.1.post2+tuxcare of pyjwt. not_affected \u2014 PyJWT version 1.7.1 is not affected by CVE-2026-48524. The vulnerability concerns PyJWKClient.fetch_data() clearing the JWKS cache on fetch errors, enabling unlimited HTTP requests. PyJWKClient was introduced in PyJWT 2.0.0 (2021), and this target version 1.7.1 (2018) predates that feature entirely. No JWKS fetching capability, no cache mechanism, and no code path exists for the vulnerability p..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d4c75ea-db41-54f4-a198-1181c1515023",
      "id": "CVE-2026-48525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48525 affects version 1.7.1.post2+tuxcare of pyjwt."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71d4e9ee-1031-516c-af96-321dc094fa39",
      "id": "CVE-2026-48526",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48526 affects version 1.7.1.post2+tuxcare of pyjwt."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2bb7ead-e76d-5f67-ae3b-1c34bde15fe9",
      "id": "CVE-2022-40897",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-40897 is fixed in version 59.8.0.post1+tuxcare of setuptools."
      },
      "affects": [
        {
          "ref": "pkg:pypi/setuptools@59.8.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d524d9cc-2fb8-5333-a418-0db136e2da69",
      "id": "CVE-2024-6345",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6345 affects version 59.8.0.post1+tuxcare of setuptools."
      },
      "affects": [
        {
          "ref": "pkg:pypi/setuptools@59.8.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15cb6fe8-57aa-599f-9e13-ad9927eff777",
      "id": "CVE-2025-47273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-47273 affects version 59.8.0.post1+tuxcare of setuptools."
      },
      "affects": [
        {
          "ref": "pkg:pypi/setuptools@59.8.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0a3a6d5-0ef0-5106-85cd-04b595ed5cd7",
      "id": "CVE-2026-59890",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59890 affects version 59.8.0.post1+tuxcare of setuptools."
      },
      "affects": [
        {
          "ref": "pkg:pypi/setuptools@59.8.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3aae28cc-cc98-5610-9b02-90fd6e059dae",
      "id": "CVE-2026-25990",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25990 is fixed in version 11.3.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01685bc6-4dad-5df7-aafe-f40c8eca88c4",
      "id": "CVE-2026-40192",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40192 affects version 11.3.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:733ac214-b8d0-5e1e-962f-7996b82d8ad9",
      "id": "CVE-2026-42308",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42308 affects version 11.3.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8c3c875-51be-5eb6-a7e4-2be2871cc699",
      "id": "CVE-2026-42309",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42309 affects version 11.3.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b47a89d3-07b5-5d9b-88d6-2f7dadbff0bc",
      "id": "CVE-2026-42310",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42310 affects version 11.3.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5a41ab3-f46e-51af-8874-17ca3d7ca1ce",
      "id": "CVE-2026-54058",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54058 affects version 11.3.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c69a0ff-c614-5df2-8123-a7761e631b91",
      "id": "CVE-2026-54059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54059 affects version 11.3.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8cea215f-e1e6-5174-a0df-7e72734eda38",
      "id": "CVE-2026-54060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54060 affects version 11.3.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2302ae8-5160-5495-af37-0731d78a4c3b",
      "id": "CVE-2026-55379",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55379 affects version 11.3.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:493689b7-dd81-55bf-b213-cc6db3427aaf",
      "id": "CVE-2026-55380",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55380 affects version 11.3.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1443eb34-47de-5b6a-bc2a-2f3c7af6b39a",
      "id": "CVE-2026-55798",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55798 affects version 11.3.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab977522-6157-5310-8928-316aa2c9dddd",
      "id": "CVE-2026-59197",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59197 affects version 11.3.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a706c54d-e03a-5b3c-bb38-a60516d418b1",
      "id": "CVE-2026-59198",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59198 affects version 11.3.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc8a15c2-6ea0-5296-8272-bddf046ecc46",
      "id": "CVE-2026-59199",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59199 affects version 11.3.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58c9d11b-3ce6-5d28-845f-bbab42605451",
      "id": "CVE-2026-59200",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59200 affects version 11.3.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e6254ed-9da5-52c8-9a1f-bed59310cf1a",
      "id": "CVE-2026-59204",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59204 affects version 11.3.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f767638d-7cf2-522e-8d01-806cfe1be327",
      "id": "CVE-2026-59205",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59205 affects version 11.3.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33974420-36d9-5c39-aa04-e24bd98ae986",
      "id": "CVE-2026-25990",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25990 is fixed in version 10.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:693fa577-7cfe-5b42-b7e2-9d6f51a39585",
      "id": "CVE-2026-40192",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40192 affects version 10.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc40836f-f6bf-59f5-bbac-019972dce8c0",
      "id": "CVE-2026-42308",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42308 affects version 10.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e3c5b30-ad27-5f68-9658-a2a1eec2bede",
      "id": "CVE-2026-42310",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42310 affects version 10.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b07eaa7-e207-59ad-b77f-d634a8483287",
      "id": "CVE-2026-42311",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42311 affects version 10.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a53977c-0049-56e7-a7f3-3e9621b61965",
      "id": "CVE-2026-54058",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54058 affects version 10.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cea8b0a6-4cd6-51fd-aada-0e5e1654e001",
      "id": "CVE-2026-54059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54059 affects version 10.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7374639-1fd9-5cb7-a8d4-5e586d074299",
      "id": "CVE-2026-54060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54060 affects version 10.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a785a0a4-5e93-5d76-9889-181cd5c37fc0",
      "id": "CVE-2026-55379",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55379 affects version 10.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d07aa962-cbf1-57de-b99c-469447847ad2",
      "id": "CVE-2026-55380",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55380 affects version 10.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c2febdf-2bb9-54c3-9632-5ab26e8b98b2",
      "id": "CVE-2026-55798",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55798 affects version 10.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f61406e-e152-5e29-8815-9611f743e312",
      "id": "CVE-2026-59197",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59197 affects version 10.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef07ff22-b0fc-50f4-9164-6235c881ccf3",
      "id": "CVE-2026-59198",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59198 affects version 10.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a395791f-0f50-55b6-bcda-90abf76d701b",
      "id": "CVE-2026-59199",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59199 affects version 10.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9213ea92-f4e0-58bf-bb59-b9e78e90abcb",
      "id": "CVE-2026-59200",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59200 affects version 10.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7cb9751-4c67-5acb-bb35-7bd747120fbb",
      "id": "CVE-2026-59204",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59204 affects version 10.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:546769ff-302d-555b-a46d-3205e3a026ff",
      "id": "CVE-2026-59205",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59205 affects version 10.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@10.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb143f14-3e54-5593-85ca-4aa5f9207e9d",
      "id": "CVE-2023-28370",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-28370 affects version 5.1.1.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@5.1.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64bd3436-6451-59df-92c6-af718487d0cc",
      "id": "CVE-2024-52804",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52804 is fixed in version 5.1.1.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@5.1.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1371938-2610-5779-b515-0d8bcb5e248d",
      "id": "CVE-2025-47287",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-47287 is fixed in version 5.1.1.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@5.1.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a88baa2a-700f-545a-843a-322e5da841df",
      "id": "CVE-2025-67724",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67724 affects version 5.1.1.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@5.1.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2eac92af-41a6-50e1-982a-1034b63efe8b",
      "id": "CVE-2025-67725",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67725 affects version 5.1.1.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@5.1.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbd13e49-b77f-572b-9e65-6efd1d58fb73",
      "id": "CVE-2025-67726",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67726 affects version 5.1.1.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@5.1.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c990d2c2-a461-5903-8d01-af95dd327895",
      "id": "CVE-2026-31958",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-31958 affects version 5.1.1.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@5.1.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7486ea5e-18eb-5403-a2a0-74bb047de18a",
      "id": "CVE-2026-35536",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-35536 affects version 5.1.1.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@5.1.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0417e586-948a-50f7-8505-04a4b5a3580d",
      "id": "CVE-2026-49853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49853 affects version 5.1.1.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@5.1.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85a5d5da-5b50-58d5-86ca-907639ae363f",
      "id": "CVE-2026-49854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49854 affects version 5.1.1.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@5.1.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d617a165-a653-5a2c-ac82-f835120faa13",
      "id": "CVE-2026-49855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49855 affects version 5.1.1.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@5.1.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fda29a58-5099-5b86-a7f9-2121317d2ade",
      "id": "GHSA-753j-mpmx-qq6g",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-753j-mpmx-qq6g affects version 5.1.1.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@5.1.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87f43455-223b-5aad-ace4-bd73706d2382",
      "id": "GHSA-78cv-mqj4-43f7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-78cv-mqj4-43f7 affects version 5.1.1.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@5.1.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61fa7cff-5e4d-5dc6-a0d6-68b16d613cd1",
      "id": "GHSA-pw6j-qg29-8w7f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-pw6j-qg29-8w7f affects version 5.1.1.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@5.1.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c002d7a7-95e1-51ba-ad53-f5e15a8ba110",
      "id": "GHSA-qppv-j76h-2rpx",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-qppv-j76h-2rpx affects version 5.1.1.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@5.1.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0932e92-fc2f-5ff2-ba60-60ee4dbe112d",
      "id": "GHSA-w235-7p84-xx57",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-w235-7p84-xx57 affects version 5.1.1.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@5.1.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86fdae9d-7116-5cbe-afdb-768ec02a299d",
      "id": "CVE-2023-6709",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-6709 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f963ef2a-13b2-53e4-9716-ac5fb749050a",
      "id": "CVE-2023-6753",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-6753 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eeb844b0-1644-545d-8d42-ce76e84afffb",
      "id": "CVE-2023-6831",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-6831 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0cc9e07c-8638-5ad4-b3b4-a24c10bd1e0f",
      "id": "CVE-2023-6909",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-6909 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e956304-2dbb-5baf-a277-3cb00e9d1d8e",
      "id": "CVE-2023-6940",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-6940 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82ff20b1-a9e3-5e0f-983a-93e616c3f726",
      "id": "CVE-2023-6974",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-6974 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b676db1f-5764-5d4b-918a-35b2f730dfe9",
      "id": "CVE-2023-6975",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-6975 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f1460b3-3d9d-5c46-b415-6a42ed23f965",
      "id": "CVE-2023-6976",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-6976 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4865ba62-7fb9-50cd-a9ae-88005958137f",
      "id": "CVE-2023-6977",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-6977 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cab4b20f-2504-5aed-97ee-ca879f807df8",
      "id": "CVE-2024-1483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-1483 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db1beb54-d3ad-51ed-80d7-f01ad05ddd9e",
      "id": "CVE-2024-1558",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-1558 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ed95bc4-5818-5d8a-af12-8076aeed4564",
      "id": "CVE-2024-1560",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-1560 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9832c23-ad76-5afc-9072-51117a1f8e58",
      "id": "CVE-2024-1593",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-1593 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d025a803-93c4-5e7d-921f-d56ebe9a8d38",
      "id": "CVE-2024-1594",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-1594 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c38609c4-afcb-5c8e-8915-382b5ea34be6",
      "id": "CVE-2024-27132",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27132 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad905843-e6ce-5819-976d-7f840914952e",
      "id": "CVE-2024-27133",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27133 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:535ea9f5-cf0d-5003-96b1-4d3f7ad4119c",
      "id": "CVE-2024-27134",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27134 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e29b012b-3880-5845-a12e-14c9730af004",
      "id": "CVE-2024-2928",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-2928 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:176e3275-379c-5d67-a46b-18abde15c23d",
      "id": "CVE-2024-3099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-3099 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be0dc1fd-757f-599f-af0e-f92f55f80fab",
      "id": "CVE-2024-3573",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-3573 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a34718d0-b3e0-5927-9887-fe3b521c2c33",
      "id": "CVE-2024-37052",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-37052 does not affect version 2.9.1.post1+tuxcare of mlflow. already_fixed \u2014 The target MLflow 2.9.1 codebase contains the fix for CVE-2024-37052 (unsafe pickle deserialization in scikit-learn model loading). The MLFLOW_ALLOW_PICKLE_DESERIALIZATION environment variable check was added in prior TuxCare backports (commits d58ee98ca for initial guard, 98a32847a for CVE-2024-37056, cf8bc9c26 for CVE-2024-37053). However, the defense defaults to True (allowing deserializatio..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:adae0806-6dc9-5b11-b86b-ab0731040367",
      "id": "CVE-2024-37053",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37053 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36e37eec-6cf9-5733-8ccb-18e306910203",
      "id": "CVE-2024-37054",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37054 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5221006-5341-55c5-ac7d-0760fe6adf41",
      "id": "CVE-2024-37055",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37055 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2085c463-f8d6-5909-9622-941e1115af4a",
      "id": "CVE-2024-37056",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37056 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c02fbf68-1c2d-5b4a-872e-15816e7ae9e4",
      "id": "CVE-2024-37057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37057 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24919a98-2437-51fc-8c17-19705b26696d",
      "id": "CVE-2024-37058",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37058 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bbfb393-ef29-561f-8ab1-32307ea3259f",
      "id": "CVE-2024-37059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37059 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e15cef90-bf2d-50d1-857c-34e5df982da9",
      "id": "CVE-2024-37060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37060 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d9d6149-68a3-5296-87d6-edeb02240d70",
      "id": "CVE-2024-37061",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37061 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf0ff4cd-7e5c-5919-8055-61401fe4f17a",
      "id": "CVE-2024-4263",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-4263 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ade96a25-4b70-53b3-b5e9-560af300067e",
      "id": "CVE-2024-6838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6838 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:832b755c-c17d-5e6d-979d-6c813e954f48",
      "id": "CVE-2024-8859",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-8859 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f801a2e-4c02-5431-9e8c-40e6c74b93b9",
      "id": "CVE-2025-0453",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-0453 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ee0fb07-d39d-53c9-8152-7787695f9a5f",
      "id": "CVE-2025-10279",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-10279 is fixed in version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c36fd2f-0bc5-58c6-9f3f-981cb26f58d7",
      "id": "CVE-2025-11200",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11200 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4bf7454-69c8-57a2-a8c3-6a3b8c9eb777",
      "id": "CVE-2025-11201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-11201 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ed6ab93-51ec-5857-8f7e-453bca6250fb",
      "id": "CVE-2025-14279",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-14279 is fixed in version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb2479d4-f473-577b-9b65-b5809f83bcff",
      "id": "CVE-2025-14287",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-14287 is fixed in version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b547e4f-babd-59c4-9a78-2ff5012e9263",
      "id": "CVE-2025-1474",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-1474 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d803e22-3037-5443-8d45-fedc4fcf1f6a",
      "id": "CVE-2025-15031",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-15031 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19393f2d-45a6-5faf-bec6-d04a6489cb35",
      "id": "CVE-2025-15036",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-15036 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0018cfe-4432-5404-8a7c-4a92738395e4",
      "id": "CVE-2025-15379",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-15379 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f1e5fbb-7824-507d-aa5c-b68933dd7eec",
      "id": "CVE-2025-15381",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-15381 does not affect version 2.9.1.post1+tuxcare of mlflow. not_affected \u2014 MLflow version 2.9.1 does not contain tracing and assessment features. These features appear to have been introduced in a later version of mlflow. The vulnerability pattern described in CVE-2025-15381 (missing permission validators on tracing and assessment endpoints when basic-auth is enabled) cannot exist in a version that does not have these endpoints."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93f07282-5f92-5549-bdfb-b6219ac8a82c",
      "id": "CVE-2025-52967",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52967 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3fb4dfb6-a812-5f3c-ab62-3e40dc11acb4",
      "id": "CVE-2026-0545",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-0545 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b3ccbc2-2210-5613-a24e-04e887096a73",
      "id": "CVE-2026-0596",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-0596 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2e3d0cd-8e14-5f8d-8ac0-a79d1da52a52",
      "id": "CVE-2026-10803",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10803 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90b76fac-be43-540d-af44-c88b1fc71c3e",
      "id": "CVE-2026-2033",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-2033 is fixed in version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b3457d9-08ce-513a-88d9-e89be1ef175d",
      "id": "CVE-2026-2393",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2393 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1285808e-3e9f-5f8c-9dde-cad1853a7c62",
      "id": "CVE-2026-2614",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-2614 does not affect version 2.9.1.post1+tuxcare of mlflow. Version 2.9.1 is not vulnerable. Summary: The target repository (MLflow v2.9.1.post4+tuxcare) does not contain the vulnerable code pattern described in CVE-2026-2614. The vulnerability was introduced in version 3.5.0 (September 2025) when prompt registry support was added to webhooks. The target version predates the introduction of the vulnerable feature by approximately 21 months."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2bb10c9-2436-5853-aad3-7ddd760c8beb",
      "id": "CVE-2026-2635",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-2635 is fixed in version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bd1a48c-4f45-54d1-86db-79e472d26bee",
      "id": "CVE-2026-2651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2651 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b652d51-3b0a-50c9-be4c-f74b2acc9826",
      "id": "CVE-2026-2652",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2652 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df317a29-237d-5226-9903-51fa60b4b3d6",
      "id": "CVE-2026-2734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2734 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aeb400c5-f521-58ca-a68d-d7fbc1b5819d",
      "id": "CVE-2026-3198",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-3198 does not affect version 2.9.1.post1+tuxcare of mlflow. not_affected \u2014 MLflow 2.9.1 is not affected by CVE-2026-3198. The vulnerability describes missing authorization checks for Gateway API list endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in MLflow 3.9.0's basic-auth integrated server. Version 2.9.1 has a fundamentally different architecture: the Gateway runs as a separate FastAPI application with no integration to the Fl..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ebec1d0-e13f-5894-8d87-5d3e8682e645",
      "id": "CVE-2026-33865",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33865 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc2f9b96-ce82-5614-bf62-61f02d9ea465",
      "id": "CVE-2026-33866",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33866 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f0547f6-84ad-5cc0-bc55-914c9510b601",
      "id": "CVE-2026-4035",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-4035 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48201d91-e25d-59fb-9ee6-25f08491d06c",
      "id": "CVE-2026-4137",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-4137 affects version 2.9.1.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f7291e9-5a42-5bb5-b61b-a692ff83f459",
      "id": "AIKIDO-2026-10318",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2026-10318 is fixed in version 2.14.5.post1+tuxcare of fastmcp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/fastmcp@2.14.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ebc62b3-f4b0-589e-a21a-bf8115679113",
      "id": "CVE-2025-64340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64340 affects version 2.14.5.post1+tuxcare of fastmcp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/fastmcp@2.14.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76201204-1dae-564e-9768-90eef9fa6dc2",
      "id": "CVE-2026-27124",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27124 affects version 2.14.5.post1+tuxcare of fastmcp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/fastmcp@2.14.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e619b1f3-40e5-5369-b77b-305a31423343",
      "id": "CVE-2026-32871",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32871 affects version 2.14.5.post1+tuxcare of fastmcp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/fastmcp@2.14.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a895ab59-60d7-56a0-bdb3-ee6b278fbef6",
      "id": "CVE-2024-12797",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-12797 is fixed in version 43.0.3.post2+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@43.0.3.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea645efe-ea59-51d0-befa-abdb6c8b92ea",
      "id": "CVE-2026-26007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-26007 is fixed in version 43.0.3.post2+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@43.0.3.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40133b1a-f000-5877-bb2f-c2c6c38b178e",
      "id": "CVE-2026-34073",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34073 affects version 43.0.3.post2+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@43.0.3.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7d84737-47a9-56a8-8cec-a061133b7a9e",
      "id": "GHSA-537c-gmf6-5ccf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-537c-gmf6-5ccf affects version 43.0.3.post2+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@43.0.3.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b48a99b-0e5f-5eb8-ada0-6bf9315b2c04",
      "id": "CVE-2026-26007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-26007 is fixed in version 44.0.3.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@44.0.3.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b683a38f-2379-59c1-94a6-dfddce1890b2",
      "id": "CVE-2026-34073",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34073 affects version 44.0.3.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@44.0.3.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ba5a757-68d5-5749-ab8a-91f367b260d1",
      "id": "GHSA-537c-gmf6-5ccf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-537c-gmf6-5ccf affects version 44.0.3.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@44.0.3.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d373907-e59a-5c7d-8eeb-f3450b0cc4de",
      "id": "CVE-2023-50782",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-50782 is fixed in version 41.0.7.post2+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@41.0.7.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:226231db-1538-53ef-aaf1-c496934960fa",
      "id": "CVE-2024-0727",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-0727 is fixed in version 41.0.7.post2+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@41.0.7.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71f7c5b1-04a6-5131-a928-d4edf85ce40d",
      "id": "CVE-2024-26130",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-26130 is fixed in version 41.0.7.post2+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@41.0.7.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ba6c2a9-a897-5b62-ab33-d7ada145e713",
      "id": "CVE-2026-26007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-26007 is fixed in version 41.0.7.post2+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@41.0.7.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73b536af-b664-5cc2-9833-5531e9b5bfc1",
      "id": "CVE-2026-34073",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34073 affects version 41.0.7.post2+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@41.0.7.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48ca8f5d-c1d7-5ccf-8b71-5e4b959b6586",
      "id": "GHSA-537c-gmf6-5ccf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-537c-gmf6-5ccf affects version 41.0.7.post2+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@41.0.7.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08700069-9f7d-504b-b9d1-415eaf2e1726",
      "id": "GHSA-h4gh-qq45-vh27",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-h4gh-qq45-vh27 affects version 41.0.7.post2+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@41.0.7.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9636c205-29d0-5b82-8aeb-51da6b6da56a",
      "id": "CVE-2024-12797",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-12797 is a false positive for cryptography 45.0.7.post1+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@45.0.7.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8885e6b-4abd-5e30-b801-8d7d0cb24662",
      "id": "CVE-2026-26007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-26007 is fixed in version 45.0.7.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@45.0.7.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f705f87a-a8a7-5c1a-91d4-7b2ddf186942",
      "id": "CVE-2026-34073",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34073 affects version 45.0.7.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@45.0.7.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a715697-2024-560e-bde2-326a06c12144",
      "id": "CVE-2026-39892",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-39892 affects version 45.0.7.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@45.0.7.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a589f412-c837-5114-b8af-ebaa68fa8cc7",
      "id": "GHSA-537c-gmf6-5ccf",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-537c-gmf6-5ccf does not affect version 45.0.7.post1+tuxcare of cryptography. not_affected \u2014 The source repository does not contain OpenSSL source code. The vulnerability (GHSA-537c-gmf6-5ccf) affects OpenSSL bundled in binary wheels distributed on PyPI, not the cryptography source code itself. OpenSSL is downloaded and compiled during the wheel build process via build_openssl.sh, not present in the repository."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@45.0.7.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b8655bd-be7c-5771-84e4-513d1aa71602",
      "id": "CVE-2024-12797",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-12797 is fixed in version 42.0.8.post2+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@42.0.8.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f5ddc71-5be8-542b-8b33-24908b7a24ba",
      "id": "CVE-2026-26007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-26007 is fixed in version 42.0.8.post2+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@42.0.8.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20ac00e8-bebc-589d-ac47-404cb41ada7f",
      "id": "CVE-2026-34073",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34073 affects version 42.0.8.post2+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@42.0.8.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7d6b186-2c51-599f-9d32-aac52c92da08",
      "id": "GHSA-537c-gmf6-5ccf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-537c-gmf6-5ccf affects version 42.0.8.post2+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@42.0.8.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e27e036b-0dbc-505c-ac4e-9dfe059116d4",
      "id": "GHSA-h4gh-qq45-vh27",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-h4gh-qq45-vh27 is fixed in version 42.0.8.post2+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@42.0.8.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efe1c1ef-d7a5-5eee-b4d7-2fc696e8d414",
      "id": "CVE-2022-33124",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-33124 is a false positive for aiohttp 3.8.1.post7+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5fa5600-b371-521d-95bb-215421a4af62",
      "id": "CVE-2023-37276",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-37276 is fixed in version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d6d54d9-429b-5298-a308-bb30100fb3e9",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49081 is fixed in version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1120dea-3025-5eeb-8b76-ebc3a8e9cfee",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49082 is fixed in version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d9ff890-5780-5b4d-8920-242062fc3532",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23334 is fixed in version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:447be8c5-dfa5-50ec-8a6c-518bcd082290",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23829 is fixed in version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29f84cac-7980-57b0-812b-6c5604870fb8",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-27306 is fixed in version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6d34b5f-183a-5fdb-abe5-76aa121ce7c3",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-30251 is fixed in version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac8f0870-2e8a-515c-88e5-baf69ccb46f9",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52304 is fixed in version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9c4b35d-eef1-5d99-b8dc-94af3feca52b",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53643 is fixed in version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:067940de-f835-5029-bcb2-e8c71a9971da",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bcd3f6e6-827a-5250-ae4a-293292eafa13",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a21c0f35-9973-5ab3-b01e-593f9e5721da",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:420890f9-377a-5f2b-9890-d0506f883404",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d28568b-9b78-5593-84fc-09435702f6fd",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb95dda7-0a74-5aaf-b9f6-d6ebec9d92c3",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6acb94e-fa45-5e97-b38e-144cb2ae7316",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b67b708-0921-5e0c-916a-960ecf2f6115",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b12a02ce-280b-564a-b038-19dfcfa6e436",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22815 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e574bf43-9499-5d4b-9506-c40256b0da93",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34513 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df168562-233e-54df-860c-c2dfffcdeb20",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34514 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef1ce006-f63f-5be9-98c8-2b97cf29b4ed",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd6da254-c879-519a-bb98-0efcf7130fcb",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34516 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e03cae1d-c402-54bb-9e39-9f4853883490",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34517 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d74c2028-baee-56dc-8136-0826373b2e5b",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34518 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13fabdb0-39de-528c-adac-4bc253204cc0",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34519 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca580f76-5a39-5659-855f-e137634732d0",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34520 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6353b66e-2985-54ac-a8ad-84173c3ce5f9",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34525 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:305de710-f182-5671-9fd1-72ea94c15f6f",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4442ea4-7225-511a-a106-f1181d706130",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8aadce3f-1698-52cb-8de0-af34dd99b57f",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37778db4-c922-56df-9f1c-c4c372fecc59",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eab5e0fa-93c2-548b-9e8a-37cd3ad29cf6",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd3ab937-5b75-5051-aeb4-47175553e8b9",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.1.post7+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac5d40a7-787d-51ca-8c44-d26f7d9d52de",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.1.post7+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cab7e913-4d54-5d16-8a70-113b6f4a10d9",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32d9aa49-a8c4-54c9-87fb-73a57d9d74d7",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0e438c1-fb51-596e-9174-ee37634bb60b",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d578f3b8-59f4-52d2-a9ce-f2425eb17e96",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.1.post7+tuxcare of aiohttp. CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe"
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85374b67-b2cd-5bbd-9237-0ccc37d41774",
      "id": "GHSA-pjjw-qhg8-p2p9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-pjjw-qhg8-p2p9 is fixed in version 3.8.1.post7+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae80360f-a35a-5162-9322-19aab595bd5e",
      "id": "AIKIDO-2024-10085",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2024-10085 is fixed in version 2.2.3.post4+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@2.2.3.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6455dd58-d26a-5e3a-a495-a225d908fe30",
      "id": "AIKIDO-2024-10410",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2024-10410 is fixed in version 2.2.3.post4+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@2.2.3.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5806cb0-9305-5570-85de-d8d4745343f4",
      "id": "CVE-2023-46136",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-46136 is fixed in version 2.2.3.post4+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@2.2.3.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42864c40-7357-5531-94b3-dc184aad7d7f",
      "id": "CVE-2024-34069",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34069 affects version 2.2.3.post4+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@2.2.3.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f459436e-4331-53f5-98b0-9682872f0ec7",
      "id": "CVE-2024-49766",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-49766 is fixed in version 2.2.3.post4+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@2.2.3.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9308980a-790d-5ec2-b347-b750b30a023c",
      "id": "CVE-2024-49767",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-49767 is fixed in version 2.2.3.post4+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@2.2.3.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3450eb6-dab6-5e60-b74b-db943d9c759b",
      "id": "CVE-2025-66221",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66221 affects version 2.2.3.post4+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@2.2.3.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b181581-002f-56b4-a22e-057ca5a88ec3",
      "id": "CVE-2026-21860",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-21860 affects version 2.2.3.post4+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@2.2.3.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8875830e-4abb-5a67-aabf-9d5678f27723",
      "id": "CVE-2026-27199",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27199 affects version 2.2.3.post4+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@2.2.3.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54ee7961-ee78-569f-a089-32f09c49298b",
      "id": "AIKIDO-2024-10085",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2024-10085 is fixed in version 1.0.1.post4+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6015c90-6efc-5429-b8cc-58754d74d093",
      "id": "AIKIDO-2024-10410",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2024-10410 is fixed in version 1.0.1.post4+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7dc3cc10-21e2-54b8-87d0-54b5e7d84024",
      "id": "CVE-2023-23934",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-23934 is fixed in version 1.0.1.post4+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:735f09f9-26d6-5549-872f-28fa83eb1f99",
      "id": "CVE-2023-25577",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-25577 is fixed in version 1.0.1.post4+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ec3c687-7ef3-5d16-a398-88d3dcefd238",
      "id": "CVE-2023-46136",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-46136 is fixed in version 1.0.1.post4+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eefe6edf-a94b-51e7-b17b-21a5ce1ab18b",
      "id": "CVE-2024-34069",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34069 is fixed in version 1.0.1.post4+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18bde190-ea3c-5a8e-9f93-8f5a103f6b7f",
      "id": "CVE-2024-49766",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-49766 is fixed in version 1.0.1.post4+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a01306d8-06a3-592a-abe5-422c269218b6",
      "id": "CVE-2024-49767",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-49767 is fixed in version 1.0.1.post4+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68908140-9567-51c7-92b3-5cdaa1662014",
      "id": "CVE-2025-66221",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66221 affects version 1.0.1.post4+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4acd8ff3-935b-59d1-88d3-f85c5ab93ccb",
      "id": "CVE-2026-21860",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-21860 affects version 1.0.1.post4+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b59cd60-b20f-5a10-9f64-18566c9ebf80",
      "id": "CVE-2026-27199",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27199 affects version 1.0.1.post4+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec220fc3-2011-5034-b7e9-f7b6632d2eea",
      "id": "CVE-2022-33124",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-33124 is a false positive for aiohttp 3.8.1.post6+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e2b212c-d910-5208-99ca-4551d5ca48de",
      "id": "CVE-2023-37276",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-37276 is fixed in version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1718bab2-14c1-55d1-a241-665ddfc3c192",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49081 is fixed in version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbd8c8dc-4c41-54ca-bec7-2a586536c0e8",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49082 is fixed in version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb6177f9-5170-549c-9368-5941ea99517d",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23334 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60818faa-61a1-5a1f-9d86-f5313c72bd67",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23829 is fixed in version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef2fc72d-3136-5745-818a-d0f01caee328",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-27306 is fixed in version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:989e9734-004a-59d4-a3a6-250c692f5928",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-30251 is fixed in version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:041ae525-0355-57ac-b71a-d4a4e313bf3b",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52304 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7de3a6db-cad4-5ed7-9dad-c9bee09013ca",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53643 is fixed in version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2b895d1-afcd-50c0-9aa0-ad5c1a22c193",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50dab4f4-6a77-5346-b529-d5129f2ebec2",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1ccde4c-3524-53a0-a257-2d224e7e3182",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a78c338-6939-5b98-9433-92c477cfc7a5",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c48731d1-64f0-561c-942a-79d6d3455127",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8178fdb8-b504-542c-80a0-9773f81ba401",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cca8b0d5-d9e0-5d60-83ca-d9c9a7279b35",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:409ee904-b7fa-5780-8ad3-7e4b70b751d9",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d98008b7-32bd-5d4a-b0fa-3279426bdd61",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22815 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:789a1f86-d9c4-558f-9b47-6809593f0a44",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34513 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0c7379a-fafd-5ed3-83aa-d5276a8c0c33",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34514 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ded7465-c6cc-5880-9d2a-dc8221addbb3",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e85940f3-aaf0-53b8-8d95-5647ae40eebd",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34516 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbc66457-953e-5d11-8495-726aacb966e9",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34517 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c303fe70-b0df-594b-be70-24339a9812bb",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34518 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8849470f-c753-5b02-9ecc-bdea0bb8fb77",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34519 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4991d4b-017e-599a-81af-9e04e9b8835a",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34520 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24ae41e0-469e-5de1-bb02-4242b1ad0711",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34525 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42f7426b-1c1a-51b5-b1fe-19fad9b484f0",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99baf69f-e981-5657-bb9c-d442c98dfbcf",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ccf2a614-a329-5b53-a584-36e6ed35e866",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:baae7c48-7654-5629-82a4-5650fd2be391",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6a274bb-c1fb-5fae-bf71-724aaa2c9408",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc9858c3-09af-5060-bd05-9f1270a29749",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.1.post6+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05bf5d42-802a-5591-9b94-82971736b70d",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.1.post6+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c9fc676-becc-58f6-9aec-06b3355d5bdb",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56949f9e-8b6c-5a84-a24b-d9eb92cc14f5",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45553d25-2a3c-54f8-80ff-5c74830045b4",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79135d11-1a3f-519d-8e8e-4c077faace4a",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.1.post6+tuxcare of aiohttp. CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe"
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57039b05-a6a2-5280-bedb-031ba9e2257d",
      "id": "GHSA-pjjw-qhg8-p2p9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.1.post6+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f698476-eb6a-5256-9bb9-34e1131c8fab",
      "id": "CVE-2022-33124",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-33124 is a false positive for aiohttp 3.8.1.post5+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12eaf67b-74f4-50ca-b277-6ed1522c41fc",
      "id": "CVE-2023-37276",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-37276 is fixed in version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da985fd4-4ae0-5444-b5bb-658a38f695d2",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49081 is fixed in version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ece88f6-2707-5bd3-8456-b597240ff2ae",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-49082 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b4deb8a-7ed7-5f70-af97-6bdeba5d8bdb",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23334 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d00b5611-ff5c-57d2-bcc9-4e03b0734db3",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23829 is fixed in version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9984b3c3-03e0-548b-951e-97dfd4d683b9",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27306 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:565a822d-ed8d-5252-92e6-f7e786bba97d",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-30251 is fixed in version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4672bfb9-0d8f-5722-a05b-1b31186e8c83",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52304 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc1b03d7-9dc4-52c5-91dd-021877fb0ba3",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53643 is fixed in version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b1f2dd8-24b9-54e3-a87e-d2e32f38ba89",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1cb237a-c9de-529f-97bd-65b5eb7cd8ed",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb8fa4a5-3b3e-5081-a1df-4ba151c8b97a",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5da47dad-f5f6-5378-b393-e70ba3119b4f",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71750835-0eac-51dc-bb02-b14596a201c3",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2530eb8a-6634-508b-a85b-442b0d777367",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00a65e7a-79a5-568f-bfb9-0347524e90dd",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27018dcd-9128-557a-a78f-f407edc7d534",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f3e924a-57c5-53ce-aff1-5ccacdf130d2",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22815 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8379eb63-5a58-575e-828d-d8f11a5d4a57",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34513 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:544dd432-8f62-53cd-bca8-f04251ef9602",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34514 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9196eb2-8adb-5d66-9f27-78ebca0086bd",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b379ba2-4f7f-5423-bfda-9dae55b72977",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34516 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee6516d7-e91b-5909-914e-9e1455da5bc0",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34517 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f29098e1-af62-5a7e-aa81-62478e7ce6d9",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34518 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:282c94e9-4bbd-5c59-bbb9-1a8e492dbed5",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34519 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a434e67-c40d-5608-a03f-e1e51ee2728c",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34520 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75c2d644-f4e6-5264-9cab-85a09ec0dd4c",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34525 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:136da239-e060-5060-87c4-0b9b8be78943",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80e11318-9389-5e89-9ca6-463c42cf43d3",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a00a4afa-e271-5615-840f-a65929bc4388",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac499b89-7082-5697-925c-03b6102657b1",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ddb46bb-ffa1-54db-b632-5a568da1b94c",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0120527e-1f2c-5aae-b0d9-d10b99b13833",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.1.post5+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d753af1c-579d-52ec-a4d4-61fb75a9509c",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.1.post5+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c91ed0ea-8bb6-54a2-a531-d9b0f24f7138",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74015640-9100-551a-80df-f0de2afb46c1",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f34584f1-bb41-547f-97d1-37870e0a352a",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d32c1ce-015c-55aa-9c13-00fa16b187be",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.1.post5+tuxcare of aiohttp. CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe"
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2da9bbda-40ed-516c-b4d2-2b1b3fea89ad",
      "id": "GHSA-pjjw-qhg8-p2p9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.1.post5+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58a6ae57-bc1e-51ab-b0d2-26c4e126fce2",
      "id": "CVE-2019-20916",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-20916 is fixed in version 9.0.post1+tuxcare of pip."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pip@9.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5144efd9-a6a3-5e6d-b4a1-05ffef895fa4",
      "id": "CVE-2024-34069",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34069 affects version 2.3.8.post1+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@2.3.8.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96d751ab-0887-597c-b942-7a52f72ec186",
      "id": "CVE-2024-49766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-49766 affects version 2.3.8.post1+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@2.3.8.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:937b82cf-1521-5da6-9264-f7e63a13d2e4",
      "id": "CVE-2024-49767",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-49767 affects version 2.3.8.post1+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@2.3.8.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a90bebde-6a57-525f-85da-fa9585f0515b",
      "id": "CVE-2025-66221",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66221 is fixed in version 2.3.8.post1+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@2.3.8.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d9f7f70-2baf-5498-92f7-52f098a22901",
      "id": "CVE-2026-21860",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-21860 affects version 2.3.8.post1+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@2.3.8.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b77f6a8-55be-5427-857a-b2d1c1e15c40",
      "id": "CVE-2026-27199",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27199 affects version 2.3.8.post1+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@2.3.8.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94f677b1-9ecc-51d8-8237-7c0a0e000f58",
      "id": "CVE-2023-37920",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-37920 is fixed in version 2022.12.7.post2+tuxcare of certifi."
      },
      "affects": [
        {
          "ref": "pkg:pypi/certifi@2022.12.7.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93a562ec-29e2-5f91-9748-b43a46a31a4e",
      "id": "CVE-2024-39689",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-39689 is fixed in version 2022.12.7.post2+tuxcare of certifi."
      },
      "affects": [
        {
          "ref": "pkg:pypi/certifi@2022.12.7.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c8a7fd6-3061-53f6-9b6a-dc339469b792",
      "id": "CVE-2023-44271",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44271 is fixed in version 9.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:695e1bd8-da63-578c-b759-75cc63984378",
      "id": "CVE-2023-4863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-4863 is fixed in version 9.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0862a20b-99cc-5fb6-9a8c-3831be4d2dd4",
      "id": "CVE-2023-50447",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-50447 is fixed in version 9.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09d18547-37cc-50a2-9276-a088f65cba93",
      "id": "CVE-2024-28219",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-28219 is fixed in version 9.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0ed2fdf-1e10-5374-b2ec-64fd933dc289",
      "id": "CVE-2026-42308",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42308 affects version 9.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf73ff11-8703-5470-85af-f4f0016b9510",
      "id": "CVE-2026-42310",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42310 affects version 9.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f05bba2-4379-5c88-b604-97d8b8a71342",
      "id": "CVE-2026-54058",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54058 affects version 9.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a5c1a0b-38be-5057-a423-834752254f95",
      "id": "CVE-2026-54059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54059 affects version 9.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6ca487d-07cc-53a4-aa65-14dad569f62c",
      "id": "CVE-2026-54060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54060 affects version 9.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6307da06-9668-5e0f-a79e-afe4999fa122",
      "id": "CVE-2026-55379",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55379 affects version 9.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b386795-cca2-5c07-a0d3-f189830f1f3f",
      "id": "CVE-2026-55380",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55380 affects version 9.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f9b8740-cff0-5784-8f6a-ebf9fb70d1c4",
      "id": "CVE-2026-55798",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55798 affects version 9.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f30aefa0-71ce-5a96-b440-5523b7a217ca",
      "id": "CVE-2026-59197",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59197 affects version 9.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfab8405-65e8-5bbf-ab7f-342588cc6994",
      "id": "CVE-2026-59198",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59198 affects version 9.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a9ecbbb-ddc3-56e7-9618-acc9a57e8cf4",
      "id": "CVE-2026-59199",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59199 affects version 9.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc6d0f8b-4515-5629-8d79-53011dc99b75",
      "id": "CVE-2026-59200",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59200 affects version 9.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7478569e-0e66-5bf1-ae34-7f1bd2f496dd",
      "id": "CVE-2026-59204",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59204 affects version 9.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fec0d205-3505-5889-aae0-571fce6c765d",
      "id": "CVE-2026-59205",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59205 affects version 9.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d88ae911-ff68-5885-9c87-7b26aaaceed3",
      "id": "GHSA-56pw-mpj4-fxww",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-56pw-mpj4-fxww is fixed in version 9.4.0.post3+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e65005a1-4a05-5a4f-8e80-1e7473ebc594",
      "id": "CVE-2022-23491",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23491 is fixed in version 2021.10.8.post2+tuxcare of certifi."
      },
      "affects": [
        {
          "ref": "pkg:pypi/certifi@2021.10.8.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c71683c-ba27-5b04-852d-7bbe21aa9786",
      "id": "CVE-2023-37920",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-37920 is fixed in version 2021.10.8.post2+tuxcare of certifi."
      },
      "affects": [
        {
          "ref": "pkg:pypi/certifi@2021.10.8.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2c183d5-9304-540c-99fe-ef7b39d77aee",
      "id": "AIKIDO-2024-10085",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2024-10085 is fixed in version 2.2.3.post3+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@2.2.3.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a0ecade-e5d7-5c54-8ee7-2caf6713be78",
      "id": "AIKIDO-2024-10410",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2024-10410 is fixed in version 2.2.3.post3+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@2.2.3.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a839c66d-da70-56a8-a29b-c85de245baa6",
      "id": "CVE-2023-46136",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46136 affects version 2.2.3.post3+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@2.2.3.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c2bf8f7-ae61-5a6d-8704-e08c1bc9ce50",
      "id": "CVE-2024-34069",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34069 affects version 2.2.3.post3+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@2.2.3.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbb702be-fcf4-5442-97a9-810ed321937f",
      "id": "CVE-2024-49766",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-49766 is fixed in version 2.2.3.post3+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@2.2.3.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc4b0f11-4358-5025-b3fa-f681b354d55f",
      "id": "CVE-2024-49767",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-49767 is fixed in version 2.2.3.post3+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@2.2.3.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afe95436-ed9d-5629-aed8-07ccab55e41e",
      "id": "CVE-2025-66221",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66221 affects version 2.2.3.post3+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@2.2.3.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:590ad52b-9f87-5b9d-9a5e-3dc156459ab5",
      "id": "CVE-2026-21860",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-21860 affects version 2.2.3.post3+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@2.2.3.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:419691ca-e212-5b53-b054-11f94c527842",
      "id": "CVE-2026-27199",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27199 affects version 2.2.3.post3+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@2.2.3.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88426ad7-b48a-505e-aab5-0ba9a83ff659",
      "id": "AIKIDO-2024-10216",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2024-10216 is fixed in version 20.1.0.post1+tuxcare of gunicorn."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gunicorn@20.1.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:614a8af8-1dcd-5a75-95ff-0b0afff1ac6e",
      "id": "AIKIDO-2026-10742",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability AIKIDO-2026-10742 affects version 20.1.0.post1+tuxcare of gunicorn."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gunicorn@20.1.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b20ab63-ffea-58d8-9c2c-9fdf060c41ce",
      "id": "CVE-2024-1135",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-1135 is fixed in version 20.1.0.post1+tuxcare of gunicorn."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gunicorn@20.1.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb7ee655-21d5-5496-8c3c-cb86ea81f218",
      "id": "CVE-2024-6827",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6827 is fixed in version 20.1.0.post1+tuxcare of gunicorn."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gunicorn@20.1.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45eb0a7a-c600-5f01-95ac-5c0269cb1ed3",
      "id": "CVE-2024-7923",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-7923 affects version 20.1.0.post1+tuxcare of gunicorn."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gunicorn@20.1.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0bb3da92-6b98-51b0-a4b4-29d38040436c",
      "id": "CVE-2024-6827",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6827 is fixed in version 20.0.4.post2+tuxcare of gunicorn."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gunicorn@20.0.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:041c0549-ed82-515a-afdc-9e859bd16d5a",
      "id": "CVE-2024-47081",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47081 is fixed in version 2.32.3.post1+tuxcare of requests."
      },
      "affects": [
        {
          "ref": "pkg:pypi/requests@2.32.3.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6db37ea1-9be8-542a-96b4-c892e99a9839",
      "id": "CVE-2026-25645",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25645 affects version 2.32.3.post1+tuxcare of requests."
      },
      "affects": [
        {
          "ref": "pkg:pypi/requests@2.32.3.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0176c58-7fae-56ce-96a3-247321ba49bd",
      "id": "AIKIDO-2024-10216",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2024-10216 is fixed in version 21.2.0.post2+tuxcare of gunicorn."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gunicorn@21.2.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e44690c2-5f9a-512b-aa07-20e4236436a1",
      "id": "CVE-2024-1135",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-1135 is fixed in version 21.2.0.post2+tuxcare of gunicorn."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gunicorn@21.2.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9559a63c-0c89-5b45-8a0b-ce8351baeca5",
      "id": "CVE-2024-6827",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6827 is fixed in version 21.2.0.post2+tuxcare of gunicorn."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gunicorn@21.2.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2bed95d-b123-5501-8b00-bb862cbdae1c",
      "id": "CVE-2024-7923",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-7923 affects version 21.2.0.post2+tuxcare of gunicorn."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gunicorn@21.2.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ae0fc29-a4cc-5bb2-b216-a6abbdbe5b84",
      "id": "AIKIDO-2025-10170",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2025-10170 is fixed in version 3.7.1.post1+tuxcare of anyio."
      },
      "affects": [
        {
          "ref": "pkg:pypi/anyio@3.7.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00bdaa73-e21e-57fa-aca8-6c4447e0704b",
      "id": "AIKIDO-2024-10216",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2024-10216 is fixed in version 21.2.0.post3+tuxcare of gunicorn."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gunicorn@21.2.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:729a40d1-c206-5cfa-bbb5-67b85ce242cb",
      "id": "CVE-2024-1135",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-1135 is fixed in version 21.2.0.post3+tuxcare of gunicorn."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gunicorn@21.2.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8a69400-2892-5c5c-a79b-85b6275282c3",
      "id": "CVE-2024-6827",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6827 is fixed in version 21.2.0.post3+tuxcare of gunicorn."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gunicorn@21.2.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:927fc771-97f0-59d3-a837-3dcf5522a66b",
      "id": "CVE-2024-7923",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-7923 is fixed in version 21.2.0.post3+tuxcare of gunicorn."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gunicorn@21.2.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0824e7e-f9c7-5cc2-96ab-e7abce8014b1",
      "id": "CVE-2023-32681",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-32681 is fixed in version 2.25.1.post1+tuxcare of requests."
      },
      "affects": [
        {
          "ref": "pkg:pypi/requests@2.25.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4bb1055-887b-5ad4-9d49-af8dc25684b7",
      "id": "CVE-2024-35195",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-35195 is fixed in version 2.25.1.post1+tuxcare of requests."
      },
      "affects": [
        {
          "ref": "pkg:pypi/requests@2.25.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e916983-c9c4-5b9d-a57f-cac22f3fece9",
      "id": "CVE-2024-47081",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47081 is fixed in version 2.25.1.post1+tuxcare of requests."
      },
      "affects": [
        {
          "ref": "pkg:pypi/requests@2.25.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1128eda6-029b-5d16-a7d2-f3cde4244e35",
      "id": "CVE-2026-25645",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25645 affects version 2.25.1.post1+tuxcare of requests."
      },
      "affects": [
        {
          "ref": "pkg:pypi/requests@2.25.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f66c25f-c3d8-52ac-a72f-cac6788fa4b7",
      "id": "CVE-2024-35195",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-35195 is fixed in version 2.31.0.post1+tuxcare of requests."
      },
      "affects": [
        {
          "ref": "pkg:pypi/requests@2.31.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df360fdb-198e-5ffe-9548-99b2d9f8ecc0",
      "id": "CVE-2024-47081",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47081 is fixed in version 2.31.0.post1+tuxcare of requests."
      },
      "affects": [
        {
          "ref": "pkg:pypi/requests@2.31.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4cef691c-e502-5fc3-b143-27c0d1377df7",
      "id": "CVE-2026-25645",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25645 affects version 2.31.0.post1+tuxcare of requests."
      },
      "affects": [
        {
          "ref": "pkg:pypi/requests@2.31.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2af280b-4d6e-5475-8d37-d0ef145e8bda",
      "id": "CVE-2023-32681",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-32681 is fixed in version 2.30.0.post1+tuxcare of requests."
      },
      "affects": [
        {
          "ref": "pkg:pypi/requests@2.30.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8374edf-8a13-5538-a63b-5ba7d55be91f",
      "id": "CVE-2024-35195",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-35195 is fixed in version 2.30.0.post1+tuxcare of requests."
      },
      "affects": [
        {
          "ref": "pkg:pypi/requests@2.30.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef61b328-0172-5a47-ac81-334f6cc04d39",
      "id": "CVE-2024-47081",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47081 is fixed in version 2.30.0.post1+tuxcare of requests."
      },
      "affects": [
        {
          "ref": "pkg:pypi/requests@2.30.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7903c3ca-21f5-560c-a833-62669503ee6c",
      "id": "CVE-2026-25645",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25645 affects version 2.30.0.post1+tuxcare of requests."
      },
      "affects": [
        {
          "ref": "pkg:pypi/requests@2.30.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:509a3cba-379b-5345-a321-25d487ca5e34",
      "id": "AIKIDO-2024-10216",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2024-10216 is fixed in version 20.1.0.post2+tuxcare of gunicorn."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gunicorn@20.1.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e826fd9e-298e-56a8-922b-3c818da74551",
      "id": "AIKIDO-2026-10742",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability AIKIDO-2026-10742 affects version 20.1.0.post2+tuxcare of gunicorn."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gunicorn@20.1.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee40c5ad-aa9b-562d-9504-15a2d5a0e426",
      "id": "CVE-2024-1135",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-1135 is fixed in version 20.1.0.post2+tuxcare of gunicorn."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gunicorn@20.1.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15a63a87-a98c-5d5b-b337-83bbdcd02b5c",
      "id": "CVE-2024-6827",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6827 is fixed in version 20.1.0.post2+tuxcare of gunicorn."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gunicorn@20.1.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa13667c-605f-5119-8138-5457e1020bb1",
      "id": "CVE-2024-7923",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-7923 is fixed in version 20.1.0.post2+tuxcare of gunicorn."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gunicorn@20.1.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b67012b0-2fb5-57d9-a6c8-e37086517b9d",
      "id": "AIKIDO-2024-10216",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2024-10216 is fixed in version 22.0.0.post1+tuxcare of gunicorn."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gunicorn@22.0.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc53509d-b355-5613-b4d1-15a25ff13204",
      "id": "CVE-2024-6827",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6827 is fixed in version 22.0.0.post1+tuxcare of gunicorn."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gunicorn@22.0.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db05dccc-b31b-54c9-9dcc-7d6974a336fc",
      "id": "CVE-2023-28370",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-28370 affects version 6.1.0.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70ba4bd3-f043-54b9-9a92-6409d10aef7b",
      "id": "CVE-2024-52804",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52804 is fixed in version 6.1.0.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb478015-02cc-5daa-b2f1-813373cbfd01",
      "id": "CVE-2025-47287",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-47287 is fixed in version 6.1.0.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77d3943e-c449-5d25-9233-07111af67f5b",
      "id": "CVE-2025-67724",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67724 affects version 6.1.0.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc3bd027-a303-5caa-8786-fc95bce8c55b",
      "id": "CVE-2025-67725",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67725 affects version 6.1.0.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:473cdc79-ef3b-58ef-93e0-fc222ec238f3",
      "id": "CVE-2026-31958",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-31958 affects version 6.1.0.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c50ee4a-ca7d-576a-8341-94a463ea5832",
      "id": "CVE-2026-35536",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-35536 affects version 6.1.0.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f2914ab-2da6-5202-9337-b1e510d8b527",
      "id": "CVE-2026-49853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49853 affects version 6.1.0.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2532ecc-2f3d-570e-8362-1e134ab7a70f",
      "id": "CVE-2026-49854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49854 affects version 6.1.0.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66af16e3-fe44-5fcb-9bdb-b1b204e5ad3a",
      "id": "CVE-2026-49855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49855 affects version 6.1.0.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8215998-1211-50b3-b46e-b1d45c8ac773",
      "id": "GHSA-753j-mpmx-qq6g",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-753j-mpmx-qq6g affects version 6.1.0.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29273111-564b-5a58-bad8-84566f9f59d4",
      "id": "GHSA-78cv-mqj4-43f7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-78cv-mqj4-43f7 affects version 6.1.0.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f2cbb63-09d1-5c8c-b91a-a2ad3276ef15",
      "id": "GHSA-pw6j-qg29-8w7f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-pw6j-qg29-8w7f affects version 6.1.0.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:446fe487-6f6c-5a50-9ac4-868158b5f2f1",
      "id": "GHSA-qppv-j76h-2rpx",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-qppv-j76h-2rpx affects version 6.1.0.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d99109be-a0e2-54b1-b6ab-0cf985e370c2",
      "id": "GHSA-w235-7p84-xx57",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-w235-7p84-xx57 affects version 6.1.0.post1+tuxcare of tornado."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8511f8bf-1ccd-5584-bc78-9b255d39acf0",
      "id": "CVE-2024-5629",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-5629 is fixed in version 3.13.0.post1+tuxcare of pymongo."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pymongo@3.13.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b56e852-1a63-5b2f-a8b1-afba5d3490bd",
      "id": "GHSA-cr6f-gf5w-vhrc",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-cr6f-gf5w-vhrc is a false positive for pymongo 3.13.0.post1+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pymongo@3.13.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fb5382a-8765-5c76-b137-5dc9a0364bab",
      "id": "CVE-2022-25765",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-25765 affects version 0.6.1.post1+tuxcare of pdfkit."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pdfkit@0.6.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ee09e5a-870a-5321-9a1d-002e58605740",
      "id": "CVE-2025-26240",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-26240 is fixed in version 0.6.1.post1+tuxcare of pdfkit."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pdfkit@0.6.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5c3a641-022d-562f-a072-5d3d0ca0fab6",
      "id": "CVE-2026-23949",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-23949 is fixed in version 5.3.0.post1+tuxcare of jaraco-context."
      },
      "affects": [
        {
          "ref": "pkg:pypi/jaraco-context@5.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23c97463-3c44-5fae-85f5-c1ad630cbab4",
      "id": "CVE-2023-44271",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44271 is fixed in version 9.5.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61ce48ea-891b-57f6-bb76-7341d814e221",
      "id": "CVE-2023-4863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-4863 is fixed in version 9.5.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4cd5ebc9-8481-5a39-84a0-bdecdbfc9333",
      "id": "CVE-2023-50447",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-50447 is fixed in version 9.5.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4c50c8e-bb4e-5013-b6a5-a75bf4c84f13",
      "id": "CVE-2024-28219",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-28219 is fixed in version 9.5.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ce9d4f7-b3a6-5ac2-81ca-620a376abc5e",
      "id": "CVE-2026-42308",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42308 affects version 9.5.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad443bdd-4ce5-57df-966d-78031c0624b1",
      "id": "CVE-2026-42310",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42310 affects version 9.5.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d4c08a7-11b8-561f-957d-4b8c6f11995e",
      "id": "CVE-2026-54058",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54058 affects version 9.5.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff124b81-8112-5403-a299-1589c01b8551",
      "id": "CVE-2026-54059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54059 affects version 9.5.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e85f6a3a-dc21-5bae-803a-eb26a594d07a",
      "id": "CVE-2026-54060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54060 affects version 9.5.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be7d5894-4e64-5558-8cb7-ce3d70feab72",
      "id": "CVE-2026-55379",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55379 affects version 9.5.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:143dbd24-14db-5f15-a874-b45621231260",
      "id": "CVE-2026-55380",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55380 affects version 9.5.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0cc10a48-ef7a-5287-93d4-f0358d7cb867",
      "id": "CVE-2026-55798",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55798 affects version 9.5.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1012f8e8-f0bb-5f66-b296-aa232179ee55",
      "id": "CVE-2026-59197",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59197 affects version 9.5.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35e60e46-3153-5483-bceb-af25f8472ff9",
      "id": "CVE-2026-59198",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59198 affects version 9.5.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fdfdf46a-c8a4-512a-9fd0-be573fb818f4",
      "id": "CVE-2026-59199",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59199 affects version 9.5.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:875a7144-6aa1-5d89-ae6b-affe01f3f32c",
      "id": "CVE-2026-59200",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59200 affects version 9.5.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1fd85e06-0820-5710-a7be-ca4400f5f0c8",
      "id": "CVE-2026-59204",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59204 affects version 9.5.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54f9be52-509e-5270-8b57-10e0ce9d80ca",
      "id": "CVE-2026-59205",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59205 affects version 9.5.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94b8f831-697e-5771-8c5c-c33ec204ce3c",
      "id": "GHSA-56pw-mpj4-fxww",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-56pw-mpj4-fxww is a false positive for pillow 9.5.0.post2+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75893991-33a2-5b33-b2d2-9fb043bbb044",
      "id": "AIKIDO-2024-10086",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2024-10086 is fixed in version 2.11.3.post1+tuxcare of jinja2."
      },
      "affects": [
        {
          "ref": "pkg:pypi/jinja2@2.11.3.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e3def21-64b2-54e5-91e6-f101be86d7b6",
      "id": "AIKIDO-2024-10560",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2024-10560 is fixed in version 2.11.3.post1+tuxcare of jinja2."
      },
      "affects": [
        {
          "ref": "pkg:pypi/jinja2@2.11.3.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53b13faa-002c-5882-8b64-2850921f8a68",
      "id": "CVE-2024-22195",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22195 is fixed in version 2.11.3.post1+tuxcare of jinja2."
      },
      "affects": [
        {
          "ref": "pkg:pypi/jinja2@2.11.3.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3dcb8d05-16e6-5622-b82f-5339fa7295be",
      "id": "CVE-2024-34064",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34064 is fixed in version 2.11.3.post1+tuxcare of jinja2."
      },
      "affects": [
        {
          "ref": "pkg:pypi/jinja2@2.11.3.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6a813ac-7ae5-5e9b-b2d2-bd1fd9934d13",
      "id": "CVE-2024-56201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56201 affects version 2.11.3.post1+tuxcare of jinja2."
      },
      "affects": [
        {
          "ref": "pkg:pypi/jinja2@2.11.3.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15bf12ff-7677-5d9a-b97d-bb7586df1975",
      "id": "CVE-2024-56326",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56326 affects version 2.11.3.post1+tuxcare of jinja2."
      },
      "affects": [
        {
          "ref": "pkg:pypi/jinja2@2.11.3.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35d14ff4-915c-5ad0-80c6-eb52d323fbd0",
      "id": "CVE-2025-27516",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27516 affects version 2.11.3.post1+tuxcare of jinja2."
      },
      "affects": [
        {
          "ref": "pkg:pypi/jinja2@2.11.3.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7468ef14-2a6d-52c3-b542-644f24be21bb",
      "id": "CVE-2024-22195",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22195 is fixed in version 3.0.3.post1+tuxcare of jinja2."
      },
      "affects": [
        {
          "ref": "pkg:pypi/jinja2@3.0.3.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d9ec788-7265-54ee-8a55-6ac184e9a954",
      "id": "CVE-2024-34064",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34064 is fixed in version 3.0.3.post1+tuxcare of jinja2."
      },
      "affects": [
        {
          "ref": "pkg:pypi/jinja2@3.0.3.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0db577c-3980-519d-bc58-20e4bb09b052",
      "id": "CVE-2024-56201",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56201 is fixed in version 3.0.3.post1+tuxcare of jinja2."
      },
      "affects": [
        {
          "ref": "pkg:pypi/jinja2@3.0.3.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ed992d1-37f3-5b3d-b822-9cde873979dc",
      "id": "CVE-2024-56326",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56326 is fixed in version 3.0.3.post1+tuxcare of jinja2."
      },
      "affects": [
        {
          "ref": "pkg:pypi/jinja2@3.0.3.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:050ea8aa-b618-5819-b3a7-1a453e4c439c",
      "id": "CVE-2025-27516",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27516 is fixed in version 3.0.3.post1+tuxcare of jinja2."
      },
      "affects": [
        {
          "ref": "pkg:pypi/jinja2@3.0.3.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92908f34-a3f3-5717-b60c-046d36bea3a2",
      "id": "CVE-2022-22815",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22815 affects version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:befe2515-6518-5539-b3ff-9242604368b3",
      "id": "CVE-2022-22816",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22816 affects version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02fc3747-ffe2-5351-945c-8616f4484286",
      "id": "CVE-2022-22817",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22817 is fixed in version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32cd5989-11f3-5ec4-9b35-caf24120fa41",
      "id": "CVE-2022-24303",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24303 is fixed in version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f55e886b-3928-54fc-ad50-4e9a6f3e9698",
      "id": "CVE-2022-45198",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45198 is fixed in version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb68f813-e194-5b43-be35-17dbd19e01e9",
      "id": "CVE-2023-44271",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44271 affects version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6581a77b-9231-5669-9a45-fcd422fb4b22",
      "id": "CVE-2023-4863",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-4863 does not affect version 8.4.0.post1+tuxcare of pillow. not_affected \u2014 CVE-2023-4863 is a heap buffer overflow vulnerability in libwebp's huffman_utils.c (BuildHuffmanTable function). Pillow 8.4.0 does not contain libwebp source code - it only has build scripts (install_webp.sh) that specify libwebp-1.2.1 as an external dependency to download and link. The vulnerable code lives in the separate libwebp repository, not in Pillow's codebase. Per the DOC-ONLY PATCH ru..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:910961a1-79ca-5ddf-9ebf-795448781100",
      "id": "CVE-2023-50447",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-50447 is fixed in version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2852f914-56d9-52fa-90da-ac507480d164",
      "id": "CVE-2024-21272",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-21272 is fixed in version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1d293af-f807-5c8a-a710-98e9a79705cc",
      "id": "CVE-2024-28219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-28219 affects version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b02c4f1b-b447-5b41-8ed2-e20b7b6d9740",
      "id": "CVE-2026-42308",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42308 affects version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa3d8978-8800-57af-8d46-8b8b584df553",
      "id": "CVE-2026-42310",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42310 affects version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28734b65-d743-5802-98ae-72fd13fdd3e9",
      "id": "CVE-2026-54058",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54058 affects version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c608551-17cf-5068-86c3-f46b37bec26c",
      "id": "CVE-2026-54059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54059 affects version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52673c1d-88ff-55cc-bc6f-441ecff4490b",
      "id": "CVE-2026-54060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54060 affects version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1cedf34-9fd7-5e4a-b0ec-f4ee78d3ac49",
      "id": "CVE-2026-55379",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55379 affects version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9c3a2da-5fb4-5d1a-8894-835fbf2009cd",
      "id": "CVE-2026-55380",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55380 affects version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec649a35-da48-5492-bae2-c2173676023b",
      "id": "CVE-2026-55798",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55798 affects version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:569b0536-ad84-5b2a-a7b5-9252de43ebe6",
      "id": "CVE-2026-59197",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59197 affects version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8b594be-7817-54c6-9099-079c0ba04d27",
      "id": "CVE-2026-59198",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59198 affects version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76c562f0-f89f-535e-86e4-758e37291dc3",
      "id": "CVE-2026-59199",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59199 affects version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d7567d8-5f2a-595a-b370-d34ee0ad3fab",
      "id": "CVE-2026-59200",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59200 affects version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4e0938b-c880-5915-8c3e-1536ac749250",
      "id": "CVE-2026-59204",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59204 affects version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f4f30ec-b2b2-53e1-9310-faba832d7a39",
      "id": "CVE-2026-59205",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59205 affects version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e131fa3b-b47d-5e27-855e-49363b960f67",
      "id": "GHSA-4fx9-vc88-q2xc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-4fx9-vc88-q2xc affects version 8.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40ad517f-203f-52ae-8f67-ca79e3c964f6",
      "id": "GHSA-56pw-mpj4-fxww",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-56pw-mpj4-fxww is a false positive for pillow 8.4.0.post1+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14814704-2e4b-5743-bb5b-adaf73d9e4e9",
      "id": "AIKIDO-2024-10086",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2024-10086 is fixed in version 2.11.3.post2+tuxcare of jinja2."
      },
      "affects": [
        {
          "ref": "pkg:pypi/jinja2@2.11.3.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c35e2fe9-d3c1-5835-90f7-fc9961ba5a11",
      "id": "AIKIDO-2024-10560",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2024-10560 is fixed in version 2.11.3.post2+tuxcare of jinja2."
      },
      "affects": [
        {
          "ref": "pkg:pypi/jinja2@2.11.3.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54cc07c3-a767-5072-84e4-019d73ad257a",
      "id": "CVE-2024-22195",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22195 is fixed in version 2.11.3.post2+tuxcare of jinja2."
      },
      "affects": [
        {
          "ref": "pkg:pypi/jinja2@2.11.3.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9488e9d0-0333-594f-9629-9e6c4f9c98ba",
      "id": "CVE-2024-34064",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34064 is fixed in version 2.11.3.post2+tuxcare of jinja2."
      },
      "affects": [
        {
          "ref": "pkg:pypi/jinja2@2.11.3.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77327400-31fc-594b-bdfc-0f2c076cf375",
      "id": "CVE-2024-56201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56201 affects version 2.11.3.post2+tuxcare of jinja2."
      },
      "affects": [
        {
          "ref": "pkg:pypi/jinja2@2.11.3.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1ec5857-1c33-598c-b085-b0fb567ae9d5",
      "id": "CVE-2024-56326",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56326 is fixed in version 2.11.3.post2+tuxcare of jinja2."
      },
      "affects": [
        {
          "ref": "pkg:pypi/jinja2@2.11.3.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5753022e-6a49-5d16-93c6-55ab145b73a9",
      "id": "CVE-2025-27516",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27516 is fixed in version 2.11.3.post2+tuxcare of jinja2."
      },
      "affects": [
        {
          "ref": "pkg:pypi/jinja2@2.11.3.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:300da17f-69b5-502d-8823-ab1327a37f33",
      "id": "CVE-2023-30861",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-30861 is fixed in version 1.1.4.post1+tuxcare of flask."
      },
      "affects": [
        {
          "ref": "pkg:pypi/flask@1.1.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51d25a6f-0dab-53f5-acef-bd2208fee35c",
      "id": "CVE-2026-27205",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27205 is fixed in version 1.1.4.post1+tuxcare of flask."
      },
      "affects": [
        {
          "ref": "pkg:pypi/flask@1.1.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb559a99-8102-5f2d-9ff3-deebc8ced953",
      "id": "CVE-2023-30861",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-30861 is fixed in version 2.2.1.post1+tuxcare of flask."
      },
      "affects": [
        {
          "ref": "pkg:pypi/flask@2.2.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c128823-0d29-5231-b457-2e5326b0d87d",
      "id": "CVE-2026-27205",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27205 is fixed in version 2.2.1.post1+tuxcare of flask."
      },
      "affects": [
        {
          "ref": "pkg:pypi/flask@2.2.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4c792ec-6a1e-57cf-939c-7b3a581fa754",
      "id": "CVE-2023-44271",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44271 is fixed in version 9.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3040c843-47d7-5fc0-a9f6-96272195329e",
      "id": "CVE-2023-4863",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-4863 affects version 9.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4754a6f-eb5f-5835-83a1-9b24dbf32d44",
      "id": "CVE-2023-50447",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-50447 affects version 9.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03741c0c-e16c-5171-8b4f-66e5ba1ea775",
      "id": "CVE-2024-28219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-28219 affects version 9.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3161a06-95c4-541a-ae9d-0505d795ad86",
      "id": "CVE-2026-42308",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42308 affects version 9.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d539dc7-912e-5f48-b525-18a92d285178",
      "id": "CVE-2026-42310",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42310 affects version 9.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:faf1bcc6-9951-50cc-b62d-d7ae848032a2",
      "id": "CVE-2026-54058",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54058 affects version 9.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76cb8f9a-e5ce-5102-aaaa-b87e113a7e92",
      "id": "CVE-2026-54059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54059 affects version 9.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6525f7ea-d269-526a-9a5e-fa10e8605f61",
      "id": "CVE-2026-54060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54060 affects version 9.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1c8a012-9869-5d02-a49c-62b114f3d177",
      "id": "CVE-2026-55379",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55379 affects version 9.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee0e47d1-1e14-55f2-8db9-59915490517d",
      "id": "CVE-2026-55380",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55380 affects version 9.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4400d100-3592-5dd4-837f-976662a741b7",
      "id": "CVE-2026-55798",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55798 affects version 9.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be1cde53-13b8-5849-a2ff-122ac342cae6",
      "id": "CVE-2026-59197",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59197 affects version 9.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:262ebbd0-b435-58ec-8514-cbe4c9913038",
      "id": "CVE-2026-59198",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59198 affects version 9.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8826175d-a6f4-52d9-9ab0-15b69eb9f475",
      "id": "CVE-2026-59199",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59199 affects version 9.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90395ddd-d57a-50e2-b6a8-bec6463c7954",
      "id": "CVE-2026-59200",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59200 affects version 9.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1b9dec6-df4e-5377-ac84-cb660dc1ff3f",
      "id": "CVE-2026-59204",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59204 affects version 9.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd2c23bb-3c8b-5a85-ae59-967f05eac6a3",
      "id": "CVE-2026-59205",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59205 affects version 9.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ac173e1-d3ae-5cf1-8695-78090db89cd7",
      "id": "GHSA-56pw-mpj4-fxww",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-56pw-mpj4-fxww affects version 9.4.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eca2e9c2-0663-5996-b1c0-f1c9f3504ccb",
      "id": "AIKIDO-2024-10085",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability AIKIDO-2024-10085 affects version 1.0.1.post1+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d538516-96ac-5142-806a-f2f6c16d8392",
      "id": "AIKIDO-2024-10410",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability AIKIDO-2024-10410 affects version 1.0.1.post1+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d318c4ba-e04e-5c40-b5e8-f4b5199e2060",
      "id": "CVE-2023-23934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-23934 affects version 1.0.1.post1+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f011079-8903-541c-8e23-05d9c106dd01",
      "id": "CVE-2023-25577",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-25577 is fixed in version 1.0.1.post1+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:197d5e6d-3403-5227-b32d-9936386c12ad",
      "id": "CVE-2023-46136",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46136 affects version 1.0.1.post1+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aeac038a-0eb0-5a9b-94e3-5e9e3c31942e",
      "id": "CVE-2024-34069",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34069 affects version 1.0.1.post1+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2338dfc-037f-5d24-a87f-78303577ee0d",
      "id": "CVE-2024-49766",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-49766 is fixed in version 1.0.1.post1+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a6c4e5c-0222-5646-9dd9-6d8c8ab9784e",
      "id": "CVE-2024-49767",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-49767 is fixed in version 1.0.1.post1+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22a58f52-9e3b-56c4-9216-791848d9ad7a",
      "id": "CVE-2025-66221",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66221 affects version 1.0.1.post1+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4aca5dca-26e0-5e0f-9e9a-595d6b627bd7",
      "id": "CVE-2026-21860",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-21860 affects version 1.0.1.post1+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa1a10d1-87cb-59b6-80f3-a60c4dd895f3",
      "id": "CVE-2026-27199",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27199 affects version 1.0.1.post1+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a834fe01-f00e-5bcd-80ec-d7ef4abdebea",
      "id": "CVE-2023-44271",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44271 affects version 9.5.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afcbaca3-982d-5225-abc2-0ba967fa73c8",
      "id": "CVE-2023-4863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-4863 is fixed in version 9.5.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b591eab9-6796-539b-b3d8-63f7b09144dd",
      "id": "CVE-2023-50447",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-50447 is fixed in version 9.5.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96b7d033-74fb-5829-adf1-362e20162f48",
      "id": "CVE-2024-28219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-28219 affects version 9.5.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c192be02-ba2d-5026-9d60-109834c58e06",
      "id": "CVE-2026-42308",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42308 affects version 9.5.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b4dab50-c600-5926-a83d-38529dc6314e",
      "id": "CVE-2026-42310",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42310 affects version 9.5.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4dbddb1-4ff4-5813-a04e-1a7241462ec0",
      "id": "CVE-2026-54058",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54058 affects version 9.5.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0523441-4c4a-5ed0-b9fd-5287a42236aa",
      "id": "CVE-2026-54059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54059 affects version 9.5.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc016222-2f92-543e-bb4d-ff029689afbf",
      "id": "CVE-2026-54060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54060 affects version 9.5.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:154f6b7d-0316-5d4f-b2b6-36393c7ba513",
      "id": "CVE-2026-55379",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55379 affects version 9.5.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d3a1e1f-b23c-5335-a935-3a5af0b97a2b",
      "id": "CVE-2026-55380",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55380 affects version 9.5.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aad08abe-51e4-5a0c-b1f7-b9f137379b2f",
      "id": "CVE-2026-55798",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55798 affects version 9.5.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:627654be-8b23-5c35-9fb5-29d197bd6e65",
      "id": "CVE-2026-59197",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59197 affects version 9.5.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95b1caf1-ae6c-580e-86a2-6124b5d840e8",
      "id": "CVE-2026-59198",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59198 affects version 9.5.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b37ad3da-1970-52a3-932d-8d76db4a192a",
      "id": "CVE-2026-59199",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59199 affects version 9.5.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c59056e-83d8-5c3e-a9ca-ec1b17220c31",
      "id": "CVE-2026-59200",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59200 affects version 9.5.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9e2f7e5-8310-54c7-a698-13fda00ee333",
      "id": "CVE-2026-59204",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59204 affects version 9.5.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20b0ddcf-b2de-5064-bb49-c377d1e6ac82",
      "id": "CVE-2026-59205",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59205 affects version 9.5.0.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff4f9886-dac6-56ad-8e86-caeed51897ae",
      "id": "GHSA-56pw-mpj4-fxww",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-56pw-mpj4-fxww is a false positive for pillow 9.5.0.post1+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c73d7a4-fb35-57b4-8e2a-9a0f80ebb1e5",
      "id": "AIKIDO-2024-10085",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2024-10085 is fixed in version 1.0.1.post2+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f843a77-51d7-5548-955e-24dc9e5a3d94",
      "id": "AIKIDO-2024-10410",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability AIKIDO-2024-10410 affects version 1.0.1.post2+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f11c586b-d1cd-58a6-98ef-cc9ae8536137",
      "id": "CVE-2023-23934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-23934 affects version 1.0.1.post2+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a947099a-a9ca-5300-ad3e-0f33f06321b5",
      "id": "CVE-2023-25577",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-25577 is fixed in version 1.0.1.post2+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0bb663f-ebea-55d3-994c-9733799b2565",
      "id": "CVE-2023-46136",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46136 affects version 1.0.1.post2+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae8d10d9-b534-52c2-8a1d-4afe644c8e37",
      "id": "CVE-2024-34069",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34069 is fixed in version 1.0.1.post2+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d99c0611-ddf4-5fd5-8a6c-995e8257cfb4",
      "id": "CVE-2024-49766",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-49766 is fixed in version 1.0.1.post2+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f09974e3-0b22-5934-991a-9006e82cc353",
      "id": "CVE-2024-49767",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-49767 is fixed in version 1.0.1.post2+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:032cfc74-326c-5d04-bed7-fffa67413e80",
      "id": "CVE-2025-66221",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66221 affects version 1.0.1.post2+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5534451d-6139-548f-b609-8bf2df0d1612",
      "id": "CVE-2026-21860",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-21860 affects version 1.0.1.post2+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d088773f-115e-54c5-965e-e1af45d7d331",
      "id": "CVE-2026-27199",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27199 affects version 1.0.1.post2+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:626868b7-1c02-5c32-9b73-e672bc10975a",
      "id": "CVE-2024-6827",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6827 affects version 20.0.4.post1+tuxcare of gunicorn."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gunicorn@20.0.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afc3ab29-399d-54be-bea9-e8fc16b48219",
      "id": "AIKIDO-2024-10085",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2024-10085 is fixed in version 1.0.1.post3+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d78a7d9-7661-5ff2-9b33-d72e0a229b7f",
      "id": "AIKIDO-2024-10410",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2024-10410 is fixed in version 1.0.1.post3+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03185a39-1255-5e19-ab74-82c49cbfd990",
      "id": "CVE-2023-23934",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-23934 is fixed in version 1.0.1.post3+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c78a36a8-11ff-51ac-8565-43eaf42406e5",
      "id": "CVE-2023-25577",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-25577 is fixed in version 1.0.1.post3+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b604961-64ec-5ce3-8646-244817448e8a",
      "id": "CVE-2023-46136",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46136 affects version 1.0.1.post3+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43e48eff-5471-5241-bd6b-aca949fcb32b",
      "id": "CVE-2024-34069",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34069 is fixed in version 1.0.1.post3+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a329446-a6d6-5762-9ec0-c7c9f6557083",
      "id": "CVE-2024-49766",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-49766 is fixed in version 1.0.1.post3+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15a2d16e-3725-554f-a869-642f04181b4d",
      "id": "CVE-2024-49767",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-49767 is fixed in version 1.0.1.post3+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c006506f-f88d-5341-a5de-23d2329af3cd",
      "id": "CVE-2025-66221",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66221 affects version 1.0.1.post3+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:763bb222-ccba-5563-9d67-2c0d0203171f",
      "id": "CVE-2026-21860",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-21860 affects version 1.0.1.post3+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa098489-c466-5ed2-bec9-4129398ad9c9",
      "id": "CVE-2026-27199",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27199 affects version 1.0.1.post3+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@1.0.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:457628e9-076f-5a6b-b439-e545e0628dae",
      "id": "CVE-2023-44271",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44271 is fixed in version 9.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08b8564f-3b2a-56f9-8dec-8d38732fd6c8",
      "id": "CVE-2023-4863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-4863 is fixed in version 9.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c739d734-2537-5112-88c3-f190d61cfbc1",
      "id": "CVE-2023-50447",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-50447 is fixed in version 9.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f135a81c-68d2-534e-9bdb-76390bde877c",
      "id": "CVE-2024-28219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-28219 affects version 9.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1e45fe5-657f-59a7-8177-1241be513a6b",
      "id": "CVE-2026-42308",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42308 affects version 9.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e561dd2f-771c-53b6-8491-80f37f08467b",
      "id": "CVE-2026-42310",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42310 affects version 9.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5bc1723-752b-5884-a7f2-f958cc96c935",
      "id": "CVE-2026-54058",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54058 affects version 9.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ec76b1d-08cb-5c62-af5c-d0804bf8ec71",
      "id": "CVE-2026-54059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54059 affects version 9.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19ca93ef-47d4-59e7-b795-d5bad2b11b8e",
      "id": "CVE-2026-54060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54060 affects version 9.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63eb3397-4fe9-5922-b5f9-fe6100da553f",
      "id": "CVE-2026-55379",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55379 affects version 9.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cba23351-b56d-5506-bced-6924afe613df",
      "id": "CVE-2026-55380",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55380 affects version 9.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95799179-7e09-593e-9d76-7951829c2eb8",
      "id": "CVE-2026-55798",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55798 affects version 9.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:970825fb-426a-5edc-9026-40e750716185",
      "id": "CVE-2026-59197",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59197 affects version 9.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1afbe32-6b56-5b88-bfa3-a464ba1d9d26",
      "id": "CVE-2026-59198",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59198 affects version 9.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa93dba5-ea57-5ec0-ab46-847a29cdb049",
      "id": "CVE-2026-59199",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59199 affects version 9.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61992c96-36fa-5cab-9751-e8ee541e3a9c",
      "id": "CVE-2026-59200",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59200 affects version 9.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96d59174-90b8-56f4-b90f-754d02a7a954",
      "id": "CVE-2026-59204",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59204 affects version 9.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:510b87c4-9cd0-5a3d-ac2d-527e12960335",
      "id": "CVE-2026-59205",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59205 affects version 9.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff0c626b-af93-5608-ac16-592df494d8c0",
      "id": "GHSA-56pw-mpj4-fxww",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-56pw-mpj4-fxww is fixed in version 9.4.0.post2+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8dccfd1-b481-59a8-b993-942c76cf0201",
      "id": "AIKIDO-2024-10085",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2024-10085 is fixed in version 2.2.3.post1+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@2.2.3.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0768eb1-85c5-55ba-abc9-91d7d997d110",
      "id": "AIKIDO-2024-10410",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2024-10410 is fixed in version 2.2.3.post1+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@2.2.3.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9bcdcc7-83b2-5334-99c6-f6f4ca1b6a8c",
      "id": "CVE-2023-46136",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46136 affects version 2.2.3.post1+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@2.2.3.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae596c8b-86db-5066-971d-0d330f5645b1",
      "id": "CVE-2024-34069",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34069 affects version 2.2.3.post1+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@2.2.3.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37131d6e-7f25-518e-b8e9-f0af3a44dde1",
      "id": "CVE-2024-49766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-49766 affects version 2.2.3.post1+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@2.2.3.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:728b5abe-2fdb-5606-a0d3-e75ee7c5c619",
      "id": "CVE-2024-49767",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-49767 affects version 2.2.3.post1+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@2.2.3.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ede225b8-b337-59a0-ae4a-9bb5a6f44cba",
      "id": "CVE-2025-66221",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66221 affects version 2.2.3.post1+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@2.2.3.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1325d157-1f23-5866-8289-3872ad61c7c6",
      "id": "CVE-2026-21860",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-21860 affects version 2.2.3.post1+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@2.2.3.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3e17620-47ae-5f4b-ab34-9bc65bfed4f1",
      "id": "CVE-2026-27199",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27199 affects version 2.2.3.post1+tuxcare of werkzeug."
      },
      "affects": [
        {
          "ref": "pkg:pypi/werkzeug@2.2.3.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3c53104-eb2c-5680-90a0-e046b0d79142",
      "id": "CVE-2025-48379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48379 is fixed in version 11.2.1.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.2.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:199dd2c3-7849-546e-949a-4db0f51a651b",
      "id": "CVE-2026-25990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25990 affects version 11.2.1.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.2.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab61adf3-1ebb-560f-a21a-5408a1ff25dc",
      "id": "CVE-2026-40192",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40192 affects version 11.2.1.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.2.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:545d4a12-76e3-5a63-a804-6234b1a29330",
      "id": "CVE-2026-42308",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42308 affects version 11.2.1.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.2.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c279fda-04e2-54bb-b1df-7ea7bd575e73",
      "id": "CVE-2026-42309",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42309 affects version 11.2.1.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.2.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcc9245f-5c0d-575f-bcc2-b9d412a062f5",
      "id": "CVE-2026-42310",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42310 affects version 11.2.1.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.2.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3dc107a-0c75-5886-831a-6bb2a4ad8eb4",
      "id": "CVE-2026-42311",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42311 affects version 11.2.1.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.2.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a5b6ed9-ef69-50f8-9842-1a0cc7904713",
      "id": "CVE-2026-54058",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54058 affects version 11.2.1.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.2.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1ffe4a4-7449-5e96-bbb5-99be0983d784",
      "id": "CVE-2026-54059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54059 affects version 11.2.1.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.2.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31f2238f-fe6a-50c4-86da-deda435c2baa",
      "id": "CVE-2026-54060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54060 affects version 11.2.1.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.2.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49af05fe-75e4-564c-a74e-a2b1a8f8da31",
      "id": "CVE-2026-55379",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55379 affects version 11.2.1.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.2.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a480e65-1183-541b-9fed-6c58da964ed7",
      "id": "CVE-2026-55380",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55380 affects version 11.2.1.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.2.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04635440-66f5-5bde-b1b0-5cd1d0e24549",
      "id": "CVE-2026-55798",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55798 affects version 11.2.1.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.2.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10491b9f-d7de-5df5-be14-6b115e638ae5",
      "id": "CVE-2026-59197",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59197 affects version 11.2.1.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.2.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf8eb236-6baf-5b62-950e-462219ef7d2a",
      "id": "CVE-2026-59198",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59198 affects version 11.2.1.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.2.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74aa07f2-b27e-5aab-aff8-78a2fff7507d",
      "id": "CVE-2026-59199",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59199 affects version 11.2.1.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.2.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a8739e6-1cb5-5c6c-9260-51c479f492ef",
      "id": "CVE-2026-59200",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59200 affects version 11.2.1.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.2.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6f1afb6-0439-5877-a1de-802dbfac1592",
      "id": "CVE-2026-59204",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59204 affects version 11.2.1.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.2.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:926b9fa2-6864-5870-97ad-e4c073bcf0d7",
      "id": "CVE-2026-59205",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59205 affects version 11.2.1.post1+tuxcare of pillow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pillow@11.2.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50012db9-b8a2-5ab2-80ea-b31c37f1ebf8",
      "id": "CVE-2023-30861",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-30861 is fixed in version 1.1.2.post1+tuxcare of flask."
      },
      "affects": [
        {
          "ref": "pkg:pypi/flask@1.1.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b292012-6377-5cc5-98c4-ed5d1c2ec1c5",
      "id": "CVE-2026-27205",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27205 is fixed in version 1.1.2.post1+tuxcare of flask."
      },
      "affects": [
        {
          "ref": "pkg:pypi/flask@1.1.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31afcd46-ee2b-52fd-8784-a183df42159a",
      "id": "CVE-2019-1010083",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-1010083 is fixed in version 0.12.5.post1+tuxcare of flask."
      },
      "affects": [
        {
          "ref": "pkg:pypi/flask@0.12.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52df410c-1275-50a5-9ffd-8a0d720471e3",
      "id": "CVE-2023-30861",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-30861 is fixed in version 0.12.5.post1+tuxcare of flask."
      },
      "affects": [
        {
          "ref": "pkg:pypi/flask@0.12.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd91f954-5412-5280-9afb-948ae8ea9b25",
      "id": "CVE-2026-27205",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27205 is fixed in version 0.12.5.post1+tuxcare of flask."
      },
      "affects": [
        {
          "ref": "pkg:pypi/flask@0.12.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ded46b0e-aa52-5856-84a3-9049f1da141a",
      "id": "CVE-2023-37920",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-37920 is fixed in version 2022.12.7.post1+tuxcare of certifi."
      },
      "affects": [
        {
          "ref": "pkg:pypi/certifi@2022.12.7.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:385aa4bb-de6e-5476-981f-4775b527d1a1",
      "id": "CVE-2024-39689",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-39689 affects version 2022.12.7.post1+tuxcare of certifi."
      },
      "affects": [
        {
          "ref": "pkg:pypi/certifi@2022.12.7.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a6ec6ed-9856-54e0-bf49-cda3b52cec59",
      "id": "CVE-2023-0286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-0286 is fixed in version 3.4.8.post5+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:edf3a195-0f31-5160-a60f-4e8f45ce5c91",
      "id": "CVE-2023-23931",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-23931 is fixed in version 3.4.8.post5+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97abaf65-3156-5c82-81d9-65c309a9d4b2",
      "id": "CVE-2023-3446",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-3446 is fixed in version 3.4.8.post5+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d480546-9490-5dc4-af80-5b3ad5c983f1",
      "id": "CVE-2023-49083",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49083 is fixed in version 3.4.8.post5+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:faa24ba1-8b20-59d2-b329-01b1d5565508",
      "id": "CVE-2023-50782",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-50782 is fixed in version 3.4.8.post5+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4bf2ef6-4bfc-55d3-b992-f7c6680978a9",
      "id": "CVE-2024-0727",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-0727 affects version 3.4.8.post5+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:235851d9-4a0f-53d9-99d4-3351e2d0699e",
      "id": "CVE-2024-12797",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-12797 is fixed in version 3.4.8.post5+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c545a99-83dd-5e10-8b6e-2109cd16f008",
      "id": "CVE-2026-26007",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-26007 affects version 3.4.8.post5+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8b9a65c-0911-531d-87ac-6e0b8b0086a5",
      "id": "CVE-2026-34073",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34073 affects version 3.4.8.post5+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8e2ca6e-f734-5bcc-a8a4-1b974205cbca",
      "id": "GHSA-537c-gmf6-5ccf",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-537c-gmf6-5ccf does not affect version 3.4.8.post5+tuxcare of cryptography. not_affected \u2014 The CVE concerns vulnerable OpenSSL bundled in pre-built cryptography WHEELS (binary distributions), not the source code. The target repository (version 3.4.8.post5+tuxcare) contains only cryptography's source code and Python bindings to OpenSSL, but does NOT contain OpenSSL source code or binaries. The CVE explicitly states: 'If you are building cryptography source (sdist) then you are respons..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7fbabd96-6cfa-520e-a981-7665e286c91a",
      "id": "GHSA-5cpq-8wj7-hf2v",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-5cpq-8wj7-hf2v affects version 3.4.8.post5+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82a546ad-d9ed-566c-9bf5-7da5ce01ebac",
      "id": "GHSA-jm77-qphf-c4w8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-jm77-qphf-c4w8 affects version 3.4.8.post5+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb364b19-afcb-5949-bf67-2b072c2b45f1",
      "id": "GHSA-v8gr-m533-ghj9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-v8gr-m533-ghj9 affects version 3.4.8.post5+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:257938f1-223d-54f1-ab29-67f0deccbdd4",
      "id": "CVE-2023-0286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-0286 affects version 3.4.8.post4+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41d888da-15d6-51d9-ae8c-209c90494d7f",
      "id": "CVE-2023-23931",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-23931 is fixed in version 3.4.8.post4+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bf96439-84b0-5582-a727-73ad1b90f483",
      "id": "CVE-2023-3446",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-3446 is fixed in version 3.4.8.post4+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e95b257-5a2a-5dae-bf4c-7428057c0f5f",
      "id": "CVE-2023-49083",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49083 is fixed in version 3.4.8.post4+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9ec4376-fa55-544f-ba47-16cfb83527ea",
      "id": "CVE-2023-50782",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-50782 is fixed in version 3.4.8.post4+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb5e93d0-500a-5e6d-81a8-d4a28cf46304",
      "id": "CVE-2024-0727",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-0727 affects version 3.4.8.post4+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebb7a5ce-48d8-53d3-8fa4-4a050f22937e",
      "id": "CVE-2024-12797",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-12797 is fixed in version 3.4.8.post4+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6a8c5f7-994b-599b-a396-0b21367bcf7a",
      "id": "CVE-2026-26007",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-26007 affects version 3.4.8.post4+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfe991cb-4b97-515e-a7b7-df5460303d0e",
      "id": "CVE-2026-34073",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34073 affects version 3.4.8.post4+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e7853a1-8fc4-5732-98fe-21c315599f8d",
      "id": "GHSA-537c-gmf6-5ccf",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-537c-gmf6-5ccf does not affect version 3.4.8.post4+tuxcare of cryptography. not_affected \u2014 The CVE concerns vulnerable OpenSSL bundled in pre-built cryptography WHEELS (binary distributions), not the source code. The target repository (version 3.4.8.post5+tuxcare) contains only cryptography's source code and Python bindings to OpenSSL, but does NOT contain OpenSSL source code or binaries. The CVE explicitly states: 'If you are building cryptography source (sdist) then you are respons..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72f6ffc4-d1e0-5a4c-99f9-4ebfdd0b02da",
      "id": "GHSA-5cpq-8wj7-hf2v",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-5cpq-8wj7-hf2v affects version 3.4.8.post4+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d29508f8-ed4b-590a-bd4c-65a4bc131453",
      "id": "GHSA-jm77-qphf-c4w8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-jm77-qphf-c4w8 affects version 3.4.8.post4+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c53f4398-594c-58e5-ae8e-deaacc8aaeee",
      "id": "GHSA-v8gr-m533-ghj9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-v8gr-m533-ghj9 affects version 3.4.8.post4+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ffdae781-06c0-5b97-83fc-9d6849bbbc75",
      "id": "CVE-2023-0286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-0286 affects version 3.4.8.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a17e22c-d643-592f-b3fc-e6fbe47b215d",
      "id": "CVE-2023-23931",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-23931 is fixed in version 3.4.8.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca80f372-2cd9-5561-b465-2fcbf95b29d9",
      "id": "CVE-2023-3446",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-3446 affects version 3.4.8.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0d98f13-e2e8-59cc-8afc-54b6a6b18bca",
      "id": "CVE-2023-49083",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-49083 affects version 3.4.8.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c336797-2f28-5a9b-9bf1-7a21f6746dd4",
      "id": "CVE-2023-50782",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-50782 is fixed in version 3.4.8.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51dee058-dbd9-5437-88b6-d9ac906bc3cc",
      "id": "CVE-2024-0727",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-0727 affects version 3.4.8.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ad663fa-86af-5ede-8da6-a1907e3f8350",
      "id": "CVE-2024-12797",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-12797 affects version 3.4.8.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b502d77-9d95-5d63-acc0-ae4fd4687d18",
      "id": "CVE-2026-26007",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-26007 affects version 3.4.8.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26e52cde-51da-539d-b267-b9f6e2f65ea8",
      "id": "CVE-2026-34073",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34073 affects version 3.4.8.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f184f16-5efa-5aff-9798-688bddf03300",
      "id": "GHSA-537c-gmf6-5ccf",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-537c-gmf6-5ccf does not affect version 3.4.8.post1+tuxcare of cryptography. not_affected \u2014 The CVE concerns vulnerable OpenSSL bundled in pre-built cryptography WHEELS (binary distributions), not the source code. The target repository (version 3.4.8.post5+tuxcare) contains only cryptography's source code and Python bindings to OpenSSL, but does NOT contain OpenSSL source code or binaries. The CVE explicitly states: 'If you are building cryptography source (sdist) then you are respons..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8af2ced2-6c6d-5d69-82d2-26d306169c96",
      "id": "GHSA-5cpq-8wj7-hf2v",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-5cpq-8wj7-hf2v affects version 3.4.8.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7320d22-9689-5987-aadc-eca1ba253bea",
      "id": "GHSA-jm77-qphf-c4w8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-jm77-qphf-c4w8 affects version 3.4.8.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a24b89da-3111-52de-8e6c-e0f466587c13",
      "id": "GHSA-v8gr-m533-ghj9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-v8gr-m533-ghj9 affects version 3.4.8.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0ea0599-85ca-5ba5-ae3f-a1c1de8d447c",
      "id": "CVE-2023-0286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-0286 affects version 3.4.8.post3+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f472615f-1937-5ead-b931-afd8984bda76",
      "id": "CVE-2023-23931",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-23931 is fixed in version 3.4.8.post3+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1ed6e88-d80c-57d9-bc79-4149423dc5bf",
      "id": "CVE-2023-3446",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-3446 is fixed in version 3.4.8.post3+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abf68550-1dcf-53da-9a62-93f44d7ddadf",
      "id": "CVE-2023-49083",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-49083 affects version 3.4.8.post3+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f60fe94-bf3b-5124-9b13-c7687f3504e1",
      "id": "CVE-2023-50782",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-50782 is fixed in version 3.4.8.post3+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9561a35-9479-532c-8916-694c7a98ab99",
      "id": "CVE-2024-0727",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-0727 affects version 3.4.8.post3+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe6f8ddb-e720-50bd-8063-fa7efcf20eb9",
      "id": "CVE-2024-12797",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-12797 is fixed in version 3.4.8.post3+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c394a16-e5af-5138-a08b-4f6f40c93e27",
      "id": "CVE-2026-26007",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-26007 affects version 3.4.8.post3+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41eaba33-900f-54f2-b0ad-00f1ca70a986",
      "id": "CVE-2026-34073",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34073 affects version 3.4.8.post3+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c575078-336c-5244-8643-bf22e432f9d7",
      "id": "GHSA-537c-gmf6-5ccf",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-537c-gmf6-5ccf does not affect version 3.4.8.post3+tuxcare of cryptography. not_affected \u2014 The CVE concerns vulnerable OpenSSL bundled in pre-built cryptography WHEELS (binary distributions), not the source code. The target repository (version 3.4.8.post5+tuxcare) contains only cryptography's source code and Python bindings to OpenSSL, but does NOT contain OpenSSL source code or binaries. The CVE explicitly states: 'If you are building cryptography source (sdist) then you are respons..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86451073-3664-521e-b3f7-43d16b1ace77",
      "id": "GHSA-5cpq-8wj7-hf2v",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-5cpq-8wj7-hf2v affects version 3.4.8.post3+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6c2c6a5-4586-59c4-8a71-2cc95a641334",
      "id": "GHSA-jm77-qphf-c4w8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-jm77-qphf-c4w8 affects version 3.4.8.post3+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6cc52c8d-9f27-5290-abef-9aff4b00a977",
      "id": "GHSA-v8gr-m533-ghj9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-v8gr-m533-ghj9 affects version 3.4.8.post3+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a93b972-e930-5367-b649-cf0e81b0224a",
      "id": "CVE-2022-23491",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-23491 affects version 2021.10.8.post1+tuxcare of certifi."
      },
      "affects": [
        {
          "ref": "pkg:pypi/certifi@2021.10.8.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3e1311c-a61c-5f87-8411-9cf1baa20927",
      "id": "CVE-2023-37920",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-37920 is fixed in version 2021.10.8.post1+tuxcare of certifi."
      },
      "affects": [
        {
          "ref": "pkg:pypi/certifi@2021.10.8.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:335b5125-20ca-574d-80fe-55ab90c44cdd",
      "id": "CVE-2023-0286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-0286 affects version 3.4.8.post2+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7577c419-e4f7-5d8b-8744-055990de69fc",
      "id": "CVE-2023-23931",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-23931 is fixed in version 3.4.8.post2+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7d4e350-f8f1-5854-b5da-b00e964416cc",
      "id": "CVE-2023-3446",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-3446 is fixed in version 3.4.8.post2+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a64f5641-c2ba-5798-b233-52362181c7f2",
      "id": "CVE-2023-49083",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-49083 affects version 3.4.8.post2+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfbde6d5-f11f-57b6-8056-7d3a5d0cfb21",
      "id": "CVE-2023-50782",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-50782 is fixed in version 3.4.8.post2+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7481279-e662-53f1-82d5-99a024389b33",
      "id": "CVE-2024-0727",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-0727 affects version 3.4.8.post2+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae413bad-7d58-5fa0-93aa-f4dbff0c8429",
      "id": "CVE-2024-12797",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-12797 affects version 3.4.8.post2+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:060eab83-91f2-5aa6-adbb-ff9a899656e9",
      "id": "CVE-2026-26007",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-26007 affects version 3.4.8.post2+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:519150a6-2c2e-5881-bb41-0f918b93c1fe",
      "id": "CVE-2026-34073",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34073 affects version 3.4.8.post2+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85059b36-e583-5ab2-a512-e2ec13514905",
      "id": "GHSA-537c-gmf6-5ccf",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-537c-gmf6-5ccf does not affect version 3.4.8.post2+tuxcare of cryptography. not_affected \u2014 The CVE concerns vulnerable OpenSSL bundled in pre-built cryptography WHEELS (binary distributions), not the source code. The target repository (version 3.4.8.post5+tuxcare) contains only cryptography's source code and Python bindings to OpenSSL, but does NOT contain OpenSSL source code or binaries. The CVE explicitly states: 'If you are building cryptography source (sdist) then you are respons..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7af7dbff-cec5-5bfa-a377-b9d460db9d29",
      "id": "GHSA-5cpq-8wj7-hf2v",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-5cpq-8wj7-hf2v affects version 3.4.8.post2+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90ed98cc-c248-5f18-a3a6-ac32cd9089e5",
      "id": "GHSA-jm77-qphf-c4w8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-jm77-qphf-c4w8 affects version 3.4.8.post2+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93442309-bea2-59f1-a1c3-23a4443860ed",
      "id": "GHSA-v8gr-m533-ghj9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-v8gr-m533-ghj9 affects version 3.4.8.post2+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@3.4.8.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b05efc5-67de-5fec-a44b-d4c6643dce3f",
      "id": "CVE-2024-39689",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-39689 is fixed in version 2023.7.22.post1+tuxcare of certifi."
      },
      "affects": [
        {
          "ref": "pkg:pypi/certifi@2023.7.22.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e177253d-e39a-5431-9215-945e4d9fa907",
      "id": "CVE-2022-42969",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42969 is fixed in version 1.11.0.post1+tuxcare of py."
      },
      "affects": [
        {
          "ref": "pkg:pypi/py@1.11.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efaf9d04-2cd0-57ff-ae05-b264c933f8ab",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-49081 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5464dd7-19ef-5cd7-9194-f40df12f72ca",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49082 is fixed in version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:998c9055-f854-5ec9-9940-c1a0ef8f11f2",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23334 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c373221-049a-51dc-a357-db90bf17627c",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23829 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:124e8c57-e1f2-53a4-80f5-b28765723ef5",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27306 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2515c524-455d-54e0-9e17-82dffe70e6c9",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-30251 is fixed in version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:893a8794-8c81-577c-ad4f-fcf667a95df0",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52304 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a026e511-4918-5255-b464-c685501f38d5",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-53643 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50883f7e-4ea8-5b07-8a77-ae3e6c7b044a",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41d4625c-a0e2-5365-a64d-ef12b91b4621",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f10b9db4-d9e9-55bc-a587-27c84c1050ff",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bda846b-223e-5ad1-82de-ebbac3a2810c",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49270a6e-4bc5-5285-83a6-94501a21b552",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f4eeedd-7f30-5a1c-98dc-062e07a83293",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0039f55d-f42b-524e-859b-8552ea72c1f9",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8cbe4fbd-5483-5804-b86e-0144c0182e57",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0db9a52-6153-5e5e-8e7d-a3dfc7c5ddb0",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22815 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f9e6f8a-c38c-5245-8b56-53418f1ea23e",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34513 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b84f9c5b-5281-5738-aa46-834a6f2754d1",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34514 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ffcd3e9-0416-5efa-aed2-543e557cb515",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f60abfac-251f-5abf-8ad3-c608195b3b3a",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34516 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f81b3cb7-bf0a-55d7-89f1-6f868128c5e5",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34517 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:573d0b7a-2595-5e1c-8aed-f9291ef6855a",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34518 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df773947-5365-5ae7-ab7e-d0af15300e39",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34519 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bee851e-fccd-52dc-bcee-1f4c43157df1",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34520 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8ac9bd2-1b91-54b0-b7c8-0e255f0c7b19",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34525 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:070c0945-eab1-56ed-98fc-544261e91ec0",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8dca71f-1747-50be-bee6-fbb074d52df8",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:acfc7ded-f1a2-5f63-82f3-0cbfaac25518",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:233ec697-f7e3-53ef-9ed7-14c65fa6c6e1",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3822cba-fcb9-5d33-84e3-c16a344bb6aa",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ea6d090-6537-5be6-b2af-671f83fb393a",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.6.post2+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a34bb32-93f3-573a-a4b9-e9dccdb9ef0a",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.6.post2+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f926a6d-c440-561a-b727-b7441a56c0eb",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8ef79d0-205f-55a0-81b9-6ad74c6047b5",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2abd8b1d-2053-5c45-b2dd-751696ccbee5",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.6.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95b0bbd7-8055-515a-8f91-226b87aeefe6",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.6.post2+tuxcare of aiohttp. Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20e2237b-3aa6-5e2c-9492-73b9be46bd85",
      "id": "CVE-2024-37059",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37059 affects version 2.22.4.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:419510a5-afb4-50bd-955b-10a7754f08a6",
      "id": "CVE-2025-10279",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-10279 is fixed in version 2.22.4.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5409e297-a53a-5818-9adf-50c43010cdb1",
      "id": "CVE-2025-14279",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-14279 is fixed in version 2.22.4.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69a4e35c-7dc2-555c-9cc4-557029897ee3",
      "id": "CVE-2025-14287",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-14287 affects version 2.22.4.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e589ce92-c9f0-5e9b-af63-7c36d8abe373",
      "id": "CVE-2025-15031",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-15031 affects version 2.22.4.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b29b0d0-b302-55af-95f5-4fc4913f6d6d",
      "id": "CVE-2025-15036",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-15036 does not affect version 2.22.4.post1+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post1+tuxcare) is NOT VULNERABLE to CVE-2025-15036. While the vulnerable code pattern (tarfile.extractall in extract_archive_to_dir) exists, the security fix has been backported from upstream v3.9.0. The check_tarfile_security function is properly implemented and called before tar extraction, preventing path traversal attacks. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e86796c-809c-57c0-943d-7dfa43fc3d94",
      "id": "CVE-2025-15379",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-15379 affects version 2.22.4.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84bb6ffe-d961-554a-9086-eb00fdbdd21e",
      "id": "CVE-2025-15381",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-15381 affects version 2.22.4.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7fb9c439-c8c3-54ca-b272-3146823f4c73",
      "id": "CVE-2026-0545",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-0545 does not affect version 2.22.4.post1+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (MLflow v2.22.4.post2+tuxcare) is NOT vulnerable to CVE-2026-0545. The vulnerable feature (FastAPI job execution endpoints under /ajax-api/3.0/jobs/*) was introduced in MLflow v3.5.0 (September 2025), which is significantly later than the target version v2.22.4. The target repository does not contain the vulnerable code, job execution infrastructure, or FastAPI authentication middleware. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:045246b3-4656-5a1d-8234-07facbc46977",
      "id": "CVE-2026-0596",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-0596 affects version 2.22.4.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61fea005-2df2-52f0-9a2c-15a6acf89938",
      "id": "CVE-2026-10803",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-10803 affects version 2.22.4.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96813212-24a7-5e0f-9940-1cdf74498f0f",
      "id": "CVE-2026-2033",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2033 affects version 2.22.4.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79f08762-d62c-5f25-b2f6-2c3cb65bb418",
      "id": "CVE-2026-2393",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-2393 does not affect version 2.22.4.post1+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: Target repository version 2.22.4 does not contain the vulnerable webhook feature. Webhooks were introduced in MLflow v3.3.0 (commit 3094ab608b, August 2025), which is significantly after the target version. The vulnerable code pattern described in CVE-2026-2393 never existed in this version of the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09bf4398-d1db-53c8-9de9-9b5ed80d2133",
      "id": "CVE-2026-2614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2614 affects version 2.22.4.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afb178d0-2841-5947-afff-b9084365de80",
      "id": "CVE-2026-2635",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2635 affects version 2.22.4.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5c9f989-01e1-58f6-94fc-5f48f67ab39a",
      "id": "CVE-2026-2651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2651 affects version 2.22.4.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8ba263e-e08d-5d35-9164-529ccfce174e",
      "id": "CVE-2026-2652",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-2652 does not affect version 2.22.4.post1+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target repository (mlflow version 2.22.4) is NOT vulnerable to CVE-2026-2652. The vulnerable FastAPI authentication middleware code was introduced in version 3.9.0, which is significantly newer than the target version. In version 2.22.4, all routes are handled by Flask via WSGI middleware, eliminating the architectural mismatch between Flask and FastAPI authentication that causes this vulnerability. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b8f18da-0cf9-59a5-bff9-bbccc7ee5a03",
      "id": "CVE-2026-2734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-2734 affects version 2.22.4.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65f4ec10-9449-5ad2-8b84-e379c08464b9",
      "id": "CVE-2026-3198",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-3198 does not affect version 2.22.4.post1+tuxcare of mlflow. not_affected \u2014 MLflow version 2.22.4 is not affected by CVE-2026-3198. The vulnerability describes missing authorization handlers for Gateway API protobuf endpoints (ListGatewaySecretInfos, ListGatewayEndpoints, ListGatewayModelDefinitions) in the BEFORE_REQUEST_HANDLERS dictionary when using basic-auth. However, version 2.22.4 uses a fundamentally different Gateway architecture - a separate FastAPI-based ser..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67b40b2e-391f-522b-b871-0ca27152031a",
      "id": "CVE-2026-33865",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33865 affects version 2.22.4.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b24ce4ca-86f8-52da-9152-7a633ce61dbb",
      "id": "CVE-2026-33866",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33866 does not affect version 2.22.4.post1+tuxcare of mlflow. Version 2.22.4 is not vulnerable. Summary: The target MLflow repository (version 2.22.4) does not contain the vulnerable 'Logged Models' feature described in CVE-2026-33866. This feature was introduced in MLflow 3.x, significantly after this version. The vulnerable AJAX artifact download endpoint and associated functionality do not exist in the codebase. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e8b271f-fe8e-50d0-9775-d0e933c80f4c",
      "id": "CVE-2026-4035",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-4035 affects version 2.22.4.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab288d5d-ffeb-52f5-9b47-3880e11d263c",
      "id": "CVE-2026-4137",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-4137 affects version 2.22.4.post1+tuxcare of mlflow."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b10347c-7267-5fa7-8ac5-47c2eb66116d",
      "id": "CVE-2025-50181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-50181 is fixed in version 1.26.20.post3+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.20.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d92bfed-c86b-5d14-8bde-6d0135f7083d",
      "id": "CVE-2025-66418",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66418 is fixed in version 1.26.20.post3+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.20.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89daa1e6-928f-5a49-85b6-3e907ddca224",
      "id": "CVE-2025-66471",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66471 is fixed in version 1.26.20.post3+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.20.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38683a8f-2c53-5541-a161-eef2f5b990a1",
      "id": "CVE-2026-21441",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-21441 is fixed in version 1.26.20.post3+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.20.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51562774-a817-5dc1-abd5-9d063954905a",
      "id": "CVE-2026-44431",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44431 affects version 1.26.20.post3+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.20.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb329e26-f095-5397-a402-fecb4478f8ed",
      "id": "CVE-2021-23727",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-23727 is fixed in version 4.4.7.post1+tuxcare of celery."
      },
      "affects": [
        {
          "ref": "pkg:pypi/celery@4.4.7.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59b9e9cb-eec0-5f51-9aa1-943493d84066",
      "id": "CVE-2022-33124",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-33124 is a false positive for aiohttp 3.8.1.post4+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:057244f0-107f-5d80-997d-e914a51b128d",
      "id": "CVE-2023-37276",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-37276 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31857bf4-ce71-5e31-af9e-1f0b80dc4515",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49081 is fixed in version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7ab5a53-f09e-56ee-8a36-14c8dfc36f73",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-49082 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da88e611-dd5e-5d47-9675-b4f4f370d672",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23334 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27ab1439-1a14-598c-8969-eab48dba7d75",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23829 is fixed in version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:347f170b-2a6b-57a1-990d-9f932dfda2ce",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27306 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6bfaf253-3a4e-5e31-9d54-8fade7763da5",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-30251 is fixed in version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21475896-a29d-53f5-b306-1284f915a09e",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52304 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f24d557-2944-5006-8a5e-e25c1988099c",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-53643 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37ef5429-d867-57a4-bb6b-add261ef7cc0",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7160a1c-3887-50d7-b8d0-0c6aada34cb4",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b5689d9-94c7-5103-a870-1c6499d0d185",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5029fbf-e60f-5e9b-8ce6-a57444c3bd5a",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a9bbbb4-9bd0-58b2-b078-f0be68feb6c5",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:563b1f17-f9ea-5f8c-9707-0017051b20ff",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8343628c-94ea-577d-b7e9-61c83337592f",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2257f034-39cf-538f-86d6-ead8644c52e7",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8aa1bba3-a456-5fde-a89a-372fae38fb26",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22815 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c6692f7-b840-5a02-8496-ef151f90e2ae",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34513 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b951a269-8a38-5bf1-81f2-3c7115141d3e",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34514 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9a245aa-85d8-50a6-9db1-d8f22e9de46f",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78aabf7d-011c-5a96-a009-1cd3532c83f8",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34516 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de9ab509-5c2e-5b7d-8684-1730bbe29d69",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34517 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1151938-2797-5d9f-a3af-d3088a62abc1",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34518 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9c91e22-c224-594a-bf4b-81cdf389d89a",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34519 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a9a8d40-cfac-5688-8b47-40a9c5350f92",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34520 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d763b6d-7cc6-50b1-ba9e-cd3a0f512984",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34525 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2809847d-cdb2-5b9c-af0b-b30db2268827",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ad6e65b-c2ae-5c11-98f6-c2561715b5e9",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83589a36-eef8-5031-a46e-9342578f1419",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0649a3e7-ce02-5e80-b8a6-063ddc28a2c8",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c567e9a9-19a4-558d-85cb-35b9f3bc6455",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62a2caee-9d74-589b-91ac-8876885e99c0",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.1.post4+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1be3ab43-1577-5860-b3db-77a63de099d9",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.1.post4+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c936f9c-f26a-5490-8fdd-0f514805a1ef",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7cb931a6-55a4-53a2-a971-bea429a8aec3",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14fc76a0-35f9-54f6-8d26-815d0d00f93c",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04d56068-45fe-57d2-941a-ca9c95f9dd57",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.1.post4+tuxcare of aiohttp. CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe"
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aec19409-ad29-5d9b-aad8-9cbabca306ab",
      "id": "GHSA-pjjw-qhg8-p2p9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.1.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78a7cbf9-109b-5048-b5f2-3b55fd4eccd3",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-49081 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab93bbf2-1d45-5ce6-ab89-384424989615",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-49082 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86b21d71-c518-563e-b01d-2238958664d8",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23334 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3215a656-af25-576a-afd8-9639cc76f810",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23829 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d53ac28-aaf1-52de-9ee1-73e36d453b54",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27306 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c804fd2-653e-5a69-83ba-61eb40e3014c",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-30251 is fixed in version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b325dff3-4785-550d-a07e-417c1a401bfc",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52304 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8122a549-1d67-5522-9061-877ced349b38",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-53643 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e90d3e53-4990-556e-9f02-919d214fd164",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:262f1ff1-c191-5ba1-a82a-596227a6a76c",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90f5f698-c47c-5dfd-a96a-4eb8498568aa",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aeed7e82-9def-592d-b535-175559328952",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45b14c58-b46d-52ce-b237-be0fdb39d950",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f16ba94-17f5-5eb3-bd45-b85216d054e4",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e928b027-3e7a-5a9b-b711-321bcfbec957",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff606ea8-c3b3-5da7-93db-ad202845e936",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30c32613-4514-5917-a0b8-0bacfadad88c",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22815 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c943e838-a869-53e6-9be8-04ca363ad0d1",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34513 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c22970b2-5e94-5f6d-bcf4-23dcc52c31c6",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34514 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:427e8b25-40b2-52cf-851c-6fc214db1ab3",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f3e43f6-dbb0-541c-a369-7e5a6ce22b6d",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34516 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a519b20a-0922-58d7-8b0d-db474f4ff0eb",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34517 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27e7fa4f-32ec-5338-8098-3b68877a2614",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34518 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b2e2075-bc32-5d09-9cf3-1b263f5e16f9",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34519 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:feb78044-2c07-5316-ac9b-bf7d83118bb3",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34520 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ef06b6f-f5bb-531d-987c-3e066c21e801",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34525 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c604611-70f4-5e6b-a7b3-affe0f3a36f3",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03e40610-fb89-5fa0-95db-2687f8571d66",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f570dcd6-e2bf-5f4d-b644-260c961706f1",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ebca4a4-b801-56fb-bc87-df21e61de033",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fac5eddf-da48-5e2c-bdc2-f17b118e3c29",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64c4f4c7-0493-5c73-9eeb-53e0c1f1b48f",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.6.post1+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d68a4390-ebec-599b-86bc-c429c971daae",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.6.post1+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e7bb516-e0ce-5081-be61-1310a009f11e",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f42cd5b2-7bc3-5901-8d46-01e844bc5db9",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99e1e6ed-ad65-564c-831f-bd95a8c9406b",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.6.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3571b3f0-f4c0-5e75-92c2-672fe4a214fd",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.6.post1+tuxcare of aiohttp. Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:023f03f0-398a-5c33-acca-969233bca60c",
      "id": "CVE-2022-1941",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-1941 is fixed in version 3.17.0.post1+tuxcare of protobuf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/protobuf@3.17.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85c695ef-f1f7-5efd-aace-e9bf84b2eec9",
      "id": "CVE-2025-4565",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-4565 affects version 3.17.0.post1+tuxcare of protobuf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/protobuf@3.17.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d063e96-79cc-599f-b1e3-4e0eda3c219a",
      "id": "CVE-2026-0994",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-0994 affects version 3.17.0.post1+tuxcare of protobuf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/protobuf@3.17.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ef19fce-92b5-5c41-8804-50f3e53fc376",
      "id": "CVE-2024-29370",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-29370 is a false positive for python-jose 3.3.0.post2+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-jose@3.3.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fc76878-5d89-5d01-8ceb-6ee4448034cc",
      "id": "CVE-2024-33663",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-33663 is fixed in version 3.3.0.post2+tuxcare of python-jose."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-jose@3.3.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4345e3da-cfc0-51c4-90b0-0889e4f3cfbf",
      "id": "CVE-2024-33664",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-33664 is fixed in version 3.3.0.post2+tuxcare of python-jose."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-jose@3.3.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7b1307a-cfa9-5558-954a-104c987bbba0",
      "id": "CVE-2021-33503",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-33503 is fixed in version 1.25.11.post4+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fc468bc-32ce-51b5-987a-516da9c75a4b",
      "id": "CVE-2023-43804",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-43804 is fixed in version 1.25.11.post4+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a584a5a2-9b5e-5c9c-b583-b3ffd91e1a04",
      "id": "CVE-2023-45803",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45803 is fixed in version 1.25.11.post4+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73abab17-7631-50f2-baf9-316ce4938b8a",
      "id": "CVE-2024-37891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37891 affects version 1.25.11.post4+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:541ee6e8-9d41-5613-9639-215d995affe9",
      "id": "CVE-2025-50181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-50181 is fixed in version 1.25.11.post4+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e0cd3ca-2d0b-5e86-9e4c-02675a777a87",
      "id": "CVE-2025-66418",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66418 is fixed in version 1.25.11.post4+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63837716-ae92-569a-aa83-e6cf4ae46b5c",
      "id": "CVE-2025-66471",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66471 is fixed in version 1.25.11.post4+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3871cc3-fc76-51f3-9610-a8e1ea0123c5",
      "id": "CVE-2026-21441",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-21441 affects version 1.25.11.post4+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ea74369-36f4-594b-986b-d760bbbba73b",
      "id": "CVE-2026-44431",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44431 affects version 1.25.11.post4+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45909f25-a03e-51c7-bccb-fc73666ef2cc",
      "id": "CVE-2024-24762",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-24762 is fixed in version 0.0.6.post2+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5cf11aad-1902-5618-8251-6b0e23084023",
      "id": "CVE-2024-53981",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-53981 is fixed in version 0.0.6.post2+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebc8b6a3-9ead-5a98-8107-4e1d104c842f",
      "id": "CVE-2026-24486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24486 affects version 0.0.6.post2+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f2b3c20-898a-534a-9d69-de4d36ee0ecf",
      "id": "CVE-2026-40347",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40347 affects version 0.0.6.post2+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a06c474-0415-5440-91dd-34647404bf91",
      "id": "CVE-2026-42561",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42561 affects version 0.0.6.post2+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9ac8979-cd98-597f-969f-28bf63280a96",
      "id": "CVE-2026-53537",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53537 affects version 0.0.6.post2+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de0b02ce-bb47-5ed0-b7f5-ffb161c77da7",
      "id": "CVE-2026-53538",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53538 affects version 0.0.6.post2+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95a258ba-16e0-5fd2-9314-6314ed56b3dd",
      "id": "CVE-2026-53539",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53539 affects version 0.0.6.post2+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c27a0b3-9e61-52fa-a129-b01a7b1afddd",
      "id": "CVE-2026-53540",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53540 affects version 0.0.6.post2+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db937299-9ba5-5e3e-a354-99562d6d7c9a",
      "id": "CVE-2021-33503",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-33503 is fixed in version 1.26.4.post4+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:528a879d-604c-5d13-8766-60d09c5b4924",
      "id": "CVE-2023-43804",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-43804 affects version 1.26.4.post4+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b00635a8-3f8f-5c1c-ab8b-c2922ce6c937",
      "id": "CVE-2023-45803",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45803 is fixed in version 1.26.4.post4+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a4557de-6fe0-5923-85bf-8781a0a94c6b",
      "id": "CVE-2024-37891",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-37891 is fixed in version 1.26.4.post4+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff42c389-95a0-5e98-8926-822725592e2b",
      "id": "CVE-2025-50181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-50181 is fixed in version 1.26.4.post4+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d87ec456-17d8-5d00-92f2-9aad80b70d60",
      "id": "CVE-2025-66418",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66418 is fixed in version 1.26.4.post4+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da6f68ea-5e63-5f2e-9a11-b9c017ee297d",
      "id": "CVE-2025-66471",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66471 is fixed in version 1.26.4.post4+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b44b4e8-87bc-5250-9189-942ae9e9d8e2",
      "id": "CVE-2026-21441",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-21441 affects version 1.26.4.post4+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61b934ef-db93-5ff3-ad9d-777055ef957f",
      "id": "CVE-2026-44431",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44431 affects version 1.26.4.post4+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e85f770-b3f5-54fa-80f3-a8d65958fa89",
      "id": "CVE-2023-47627",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-47627 is fixed in version 3.8.5.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8828f43e-19a6-59a7-a640-5345e7b41e02",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49081 is fixed in version 3.8.5.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5944319b-bbbd-5f5c-8c2c-846988c1759a",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49082 is fixed in version 3.8.5.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1a6d4f0-aa7f-5769-9848-558fcf3e5c26",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23334 is fixed in version 3.8.5.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6056e84-ca01-5a50-a0f4-c03e703d54d3",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23829 is fixed in version 3.8.5.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbfd743f-e81a-5090-bad8-69101bf12330",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27306 affects version 3.8.5.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49eb8baf-90cb-517e-a83a-450531edd020",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-30251 affects version 3.8.5.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8e82f63-e109-5de3-ae66-fefeccae9d4b",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52304 is fixed in version 3.8.5.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff573b26-0a92-51b0-a3a0-07229cd26cc6",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-53643 affects version 3.8.5.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a455d401-ce55-52e8-8627-bd5ea86a5f22",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.5.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12d38c8e-d1af-5695-a7c4-a69f88152fa8",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.5.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9954672a-0bbe-5927-a92a-94b5118d06e0",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.5.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a830ae30-0837-500e-953a-1d2d65d0f828",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.5.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e598792f-6bbe-5439-8822-1b4c4a043f09",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.5.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e390d49-212e-54e3-901c-56202f44c702",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.5.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9abaa3a0-bc5f-5912-a8f3-02444ed6aafa",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.5.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2207b4b7-a313-570b-845c-ff4fc5050b4c",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.5.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:235240a2-d106-5ca6-95cc-4f6eb0d45923",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22815 affects version 3.8.5.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08af31e2-edb4-5a9f-a48c-66255cda3783",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34513 affects version 3.8.5.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7af12ecc-141f-5d8a-b33c-56f066a69f72",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34514 affects version 3.8.5.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ec9d6c4-f123-526a-9bf8-7b5bb49b78c2",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.5.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a3d0a89-d0cf-5e21-b8e6-4b586c2877bc",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34516 affects version 3.8.5.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2eca0511-74f7-5c1c-9aa5-5d137ccc5a2e",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34517 affects version 3.8.5.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c64de79b-8961-501c-a5cb-be58adb0bda2",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34518 affects version 3.8.5.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c622cc2-0243-54c6-927e-e7742a9ee8c1",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34519 affects version 3.8.5.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7426e7c0-514c-5b99-946b-e54783e4e1b0",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34520 affects version 3.8.5.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bffc5545-52f5-533b-acf6-ef39729e9ccc",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34525 affects version 3.8.5.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74dec20e-4058-51db-92fd-8b4b0adcdc8d",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.5.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65e66d68-d3d2-5d43-afe4-590105114e95",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.5.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2668ad2-54b2-5cec-af70-1c08a2001462",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.5.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59780526-bc08-5916-9ceb-83c80925ff00",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.5.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4cf89d1d-a62d-5f5a-a1a4-4feb6f914cc8",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.5.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d766797d-100c-5c34-a982-254e4fbd3c15",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.5.post4+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab3a56d6-600e-57b5-a8e8-b30efdd9562d",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.5.post4+tuxcare of aiohttp. not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15d745b1-5346-5437-af3c-daccfb28a091",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.5.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f77df54-96fb-5753-8462-5ad4ca4e4bbc",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.5.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc943059-663a-5b7d-9eca-8e357de4f21f",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.5.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6ffff44-f3e9-586f-8a3c-b8fdbb9ff74c",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.5.post4+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5595886-8be0-516c-9e16-2bd860e5f8e6",
      "id": "GHSA-pjjw-qhg8-p2p9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.5.post4+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71c2fa91-4729-5e72-a52f-d51b56cff20a",
      "id": "CVE-2023-29159",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-29159 is fixed in version 0.13.6.post2+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.13.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:745fecb6-7ad0-550b-a08a-86cf382a37eb",
      "id": "CVE-2023-30798",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-30798 is fixed in version 0.13.6.post2+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.13.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d98ca65e-b550-568b-9575-9cae32bf78f2",
      "id": "CVE-2024-47874",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47874 is fixed in version 0.13.6.post2+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.13.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05e08d8a-5a6e-5fb7-af80-67492541b053",
      "id": "CVE-2025-54121",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-54121 is fixed in version 0.13.6.post2+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.13.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ace7401-4e94-5368-a00f-2261f5f12e3a",
      "id": "CVE-2025-62727",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-62727 affects version 0.13.6.post2+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.13.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44d09cd9-2cc3-5f39-8eed-0c70817976a1",
      "id": "CVE-2026-48710",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48710 affects version 0.13.6.post2+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.13.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bbadba4-bc1a-5c57-be50-b89fd9d8a475",
      "id": "CVE-2026-48817",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48817 affects version 0.13.6.post2+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.13.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff234c9c-2b68-53ce-9dab-6817015d826d",
      "id": "CVE-2026-48818",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48818 affects version 0.13.6.post2+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.13.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9594a6cf-77bd-5c4a-ba38-200cb8a88e74",
      "id": "CVE-2026-54282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54282 affects version 0.13.6.post2+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.13.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ae27f65-2020-51f5-84fe-2370faf213cf",
      "id": "CVE-2026-54283",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54283 affects version 0.13.6.post2+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.13.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc972555-5aac-5958-b5d8-d6512b621cb0",
      "id": "GHSA-3qj8-93xh-pwh2",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-3qj8-93xh-pwh2 is a false positive for starlette 0.13.6.post2+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.13.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43fe7a1b-aaeb-5f1a-9036-8beb9df5efa4",
      "id": "GHSA-93gm-qmq6-w238",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-93gm-qmq6-w238 affects version 0.13.6.post2+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.13.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64456812-8aca-5cc4-995a-f097de76d8ed",
      "id": "GHSA-qj8w-rv5x-2v9h",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-qj8w-rv5x-2v9h is a false positive for starlette 0.13.6.post2+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.13.6.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fb09a73-a189-59cb-8f7e-96196da4cfb5",
      "id": "CVE-2024-36039",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-36039 is fixed in version 0.10.1.post1+tuxcare of pymysql."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pymysql@0.10.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f561711f-cffd-511d-8e85-193a2c2c3458",
      "id": "CVE-2022-33124",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-33124 is a false positive for aiohttp 3.8.1.post3+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f27f48b-e34e-5fe9-af6f-b9ce927a6d1b",
      "id": "CVE-2023-37276",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-37276 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5566c92e-0217-51bc-848f-b2cf1cbf0143",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49081 is fixed in version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd21f0c3-4aea-5994-beec-b719ecf919fd",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-49082 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c41c94ed-f2d7-5a7d-afa3-4a43ed19eb61",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23334 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f48496e0-8199-55fb-8e1f-f16b11cea9b0",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23829 is fixed in version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79b9b3c5-4d21-5320-ba95-0914aef791f7",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27306 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4376f3c2-813d-5141-8575-b70e9ed3956d",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-30251 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9af1bc88-9396-5c1f-8258-8fedeeedc9b5",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52304 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97f30527-f2c9-5cfd-af79-e62b5e29ef88",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-53643 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c9e36f3-7432-51d4-ba3b-fd51dd9c3ac6",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12223501-79fa-5573-826c-e5d965778731",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6cb52fc4-3e95-50ef-abf2-9450a4885f4f",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a222ba27-7161-5155-a1d8-1e19ce531f55",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73b54f12-833b-5e14-a264-2cc786aaea2c",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30a51f83-a348-58a3-9cff-dfa083afaa9d",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc29a11b-08dd-5ddf-b68b-fc42fc4f0261",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0af739b-a06b-5cc2-bc9b-a65578fcd0a9",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89b9c61a-3822-5bb4-b202-0594e6e8ebd7",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22815 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e889c1a-b78b-5c36-9c63-f5858595dfd3",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34513 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:073c16ba-318b-57f1-80af-a82dfabd6033",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34514 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44bf6f39-0104-5c9a-b207-c4ea32010f32",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d295fa7-a486-5d2b-9098-b61ff9871c4a",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34516 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86e1a292-07ae-560a-8fd7-7b6f0cc83082",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34517 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb1b6a15-f93a-56ae-8724-3736c30793df",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34518 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56ced25a-756b-5c1d-a6b7-6304e7356e7a",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34519 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d701cbf-8646-5c40-b220-021223992bb0",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34520 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34c3421a-c5da-5567-8acb-b15f5116b5cf",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34525 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67b0619b-f376-5f34-9003-9af108c1a616",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04e18713-c5b5-5950-9a9f-9c78e743018d",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:700bfe3e-c16d-5225-862d-6d19aa49114e",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b01e683e-b094-5695-8075-642961450132",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4cc08478-9e01-5bf6-8937-ea876ed6c706",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b4190cd-68bd-5f5a-80e3-6864246a9556",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.1.post3+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f9ccc90-75fc-52ea-b414-6a96260ad36a",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.1.post3+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02a9921e-9e08-523e-a3cd-711fca0d5812",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9dfb0767-39c9-5853-8866-2682029fee81",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96166790-d8da-5c7b-9db7-203fb1c02375",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f68bd78-bd5d-58a8-9327-bc9d5200c09a",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.1.post3+tuxcare of aiohttp. CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe"
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89a9fe06-1e4d-5ab7-af40-43293624c872",
      "id": "GHSA-pjjw-qhg8-p2p9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1358b016-b27b-5096-a0ef-8ef131d3d7bb",
      "id": "CVE-2024-45231",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-45231 affects version 3.2.25.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@3.2.25.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f081456-1904-5ecb-a74a-1827a06dfb9e",
      "id": "CVE-2025-48432",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48432 affects version 3.2.25.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@3.2.25.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0adcb824-12ed-5800-b656-bc44917bb23d",
      "id": "CVE-2025-57833",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-57833 is fixed in version 3.2.25.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@3.2.25.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ba10790-e2cd-58d4-aa32-dd6c42a541cf",
      "id": "CVE-2025-64458",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64458 is fixed in version 3.2.25.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@3.2.25.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:baab3aaa-d48f-53a6-a153-2014fe265553",
      "id": "CVE-2025-64459",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64459 is fixed in version 3.2.25.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@3.2.25.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b3bdbf3-d68e-59c3-90f8-79a4a5b17897",
      "id": "CVE-2021-33503",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-33503 affects version 1.26.4.post3+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4a2004a-1be7-5309-a398-8b3fcb78f01d",
      "id": "CVE-2023-43804",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-43804 affects version 1.26.4.post3+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e84320d1-172a-5612-84af-94dce3762535",
      "id": "CVE-2023-45803",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45803 is fixed in version 1.26.4.post3+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3bdcdfb4-03e2-51fa-ac85-c87ba1a8c456",
      "id": "CVE-2024-37891",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-37891 is fixed in version 1.26.4.post3+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbd38a82-b731-59e7-b734-2e1dd48eeffe",
      "id": "CVE-2025-50181",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-50181 affects version 1.26.4.post3+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95712d8a-38f4-5d49-8a6f-33271ec21e83",
      "id": "CVE-2025-66418",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66418 is fixed in version 1.26.4.post3+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7af9f02-899c-5985-9184-0813b7ca67f7",
      "id": "CVE-2025-66471",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66471 is fixed in version 1.26.4.post3+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1dc955bc-d8f6-5f2b-a033-fbb9b124f13b",
      "id": "CVE-2026-21441",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-21441 affects version 1.26.4.post3+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d27ce78-ab29-5df3-ab20-c030cd620a54",
      "id": "CVE-2026-44431",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44431 affects version 1.26.4.post3+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8f3a4d2-4a6d-5673-b37d-9feb67f0594c",
      "id": "CVE-2021-33503",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-33503 is fixed in version 1.25.11.post3+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32bb4fa5-8e86-5c8d-851d-a67376e20ff5",
      "id": "CVE-2023-43804",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-43804 affects version 1.25.11.post3+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e3ecceb-83e7-5d48-a652-5001f0de143b",
      "id": "CVE-2023-45803",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45803 is fixed in version 1.25.11.post3+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7da81628-8ef6-5d66-bc86-7d11494813b0",
      "id": "CVE-2024-37891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37891 affects version 1.25.11.post3+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78347219-49aa-5ba9-bd9c-8af1b50768ff",
      "id": "CVE-2025-50181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-50181 is fixed in version 1.25.11.post3+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7937e169-651d-51b6-a227-dcad15f3211c",
      "id": "CVE-2025-66418",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66418 is fixed in version 1.25.11.post3+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2c08a4d-0b57-5158-bd04-6514026f198f",
      "id": "CVE-2025-66471",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66471 is fixed in version 1.25.11.post3+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd4d1771-ff87-5da2-baf7-4bc486f28749",
      "id": "CVE-2026-21441",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-21441 affects version 1.25.11.post3+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78900dbb-17f4-538c-8926-41c7ecff0df9",
      "id": "CVE-2026-44431",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44431 affects version 1.25.11.post3+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:308e7e9f-f05e-5e4b-b075-68b081426253",
      "id": "CVE-2022-33124",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-33124 is a false positive for aiohttp 3.8.1.post2+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff15f441-6c0e-5749-a6f0-17723f858a71",
      "id": "CVE-2023-37276",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-37276 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90fc8532-e193-51e9-87f5-5554964ac743",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49081 is fixed in version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5123f454-7426-59c6-b6c7-ab3dc8849c3a",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-49082 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be66cc7f-b157-592e-8d09-6f0e1a7f92ba",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23334 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f45d647-50c6-5990-8385-11e793229281",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23829 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56d008e0-4778-57ad-afc2-87bbb00bb806",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27306 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcdbe26f-8be5-5468-888a-a17894be8afe",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-30251 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f03a4fb6-768d-5034-b0d4-9f4eb1ba36b7",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52304 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50ceef91-c2be-59c3-a4bd-c1c35669580b",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-53643 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a35ed9f3-3753-592d-b0b3-a0fe2b775f34",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9863194b-fe97-5bde-94e9-2cbe2a5e6196",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b5ed928-c014-5a9d-be0a-54445e819589",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3e5d6dd-9fab-5b63-822d-40a111da7b91",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd66abee-42fc-59d1-8353-8d22d484e741",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70424e44-785b-5e38-88a9-7749c28b5ca2",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f02f7fa-4cd0-5e84-9f8b-99257cbedbd2",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcf7c713-dd9d-5fc4-93ad-9900b3a95f8c",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87021d5f-2714-5726-8547-5a462fd7c331",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22815 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98c994ef-6558-5938-a129-a7f7a99ce4fe",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34513 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:542a41f3-6cfb-5372-acd5-dc4622b96dc3",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34514 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4834e793-cdbc-52ab-b7c5-19ce3e072fce",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6e31bf4-76fb-5f62-a398-3d0eee15f2d9",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34516 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff088aab-99e4-591e-98ba-8b5823af0ec4",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34517 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:740b0491-30a6-5c06-b1a9-827a059645dd",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34518 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8e04697-935e-590f-88ec-1e0621ec5ed2",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34519 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2d14588-46ad-5536-8762-d3a53eabcaa1",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34520 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:acf644b8-effb-54ac-a0ec-d80dfb36a5a5",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34525 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:baef910d-6a09-5265-b399-a9b6da351351",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:113d1182-cd8f-5da2-ba8b-db6181308d03",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6dbbc972-247c-50de-b969-9c0096f26f91",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5ad0c5a-473a-5093-8030-c209cf94165f",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0495ca15-7731-5a97-9827-8009a91fa9d6",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa842b9f-3745-5635-93f5-870295b664f9",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.1.post2+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20952625-f5b5-5f73-acfa-ee5e3271ffd5",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.1.post2+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:411e5b7c-cc0d-5d44-9dfd-310dbb97e813",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d97bfb72-676f-50c3-92a7-31dde056b192",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58c6a208-563b-56a9-8110-996865469e47",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15e4ec42-5410-53bc-a04a-59fa3c64d644",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.1.post2+tuxcare of aiohttp. CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe"
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd84c1bf-13ef-596d-a33b-cc417dfe155f",
      "id": "GHSA-pjjw-qhg8-p2p9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.1.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be532d5d-20a4-5a4a-a12a-46dd5e0b8d71",
      "id": "CVE-2024-5206",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-5206 is fixed in version 1.0.2.post1+tuxcare of scikit-learn."
      },
      "affects": [
        {
          "ref": "pkg:pypi/scikit-learn@1.0.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9746ac92-dc63-5a45-b5b9-26803b83027d",
      "id": "CVE-2025-50181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-50181 is fixed in version 1.26.20.post2+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.20.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9334ddd8-94a2-51fa-8f86-779456eb217e",
      "id": "CVE-2025-66418",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66418 is fixed in version 1.26.20.post2+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.20.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98267c2c-6c3e-58c2-b7cc-9d24f4493a91",
      "id": "CVE-2025-66471",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66471 is fixed in version 1.26.20.post2+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.20.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcadf6e2-bb81-5e0d-b11e-376bb8a64638",
      "id": "CVE-2026-21441",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-21441 affects version 1.26.20.post2+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.20.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a9569a2-53b7-53e6-99e6-81ac58b6d510",
      "id": "CVE-2026-44431",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44431 affects version 1.26.20.post2+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.20.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:720eb03d-950d-5441-9099-c7c7a90c20de",
      "id": "CVE-2023-47627",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-47627 is fixed in version 3.8.5.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:784ce8bb-1119-54f4-8875-e3f3c5e68aa4",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-49081 affects version 3.8.5.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38a9f501-ad45-5aba-a717-85c27f64f4ce",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49082 is fixed in version 3.8.5.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:600b9d9d-a47c-50de-9e24-97cc7218f870",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23334 is fixed in version 3.8.5.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5504bf6-ef98-5ac8-b09f-a3f482338ab5",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23829 is fixed in version 3.8.5.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67580b8e-bd24-5bbc-8bc9-09e71226b362",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27306 affects version 3.8.5.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0c5cc2d-a891-5ed4-9f33-267b30b6024e",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-30251 affects version 3.8.5.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5151875-b4a2-534f-8c15-e0ce50f752ea",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52304 is fixed in version 3.8.5.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:def8e4bd-e44c-5dc4-927d-52ad29fc6738",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-53643 affects version 3.8.5.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e84838a-fd54-51f7-8a18-e677b0c3f8d2",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.5.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0dc4818e-0da8-5ece-b208-d4b29f97367f",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.5.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ad34ce7-477a-5b6f-b80e-968feffdb77e",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.5.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32cf8a23-b1b6-5332-be23-5e0cfe21592a",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.5.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7da04cab-8631-511e-af2c-105cb316c556",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.5.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b06668b8-62fb-5366-86c6-265c11506743",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.5.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2470ba15-d638-54a3-bb9b-0c5cff1219d0",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.5.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e758c56-0895-5ce3-9603-0fb27029a9a2",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.5.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0eba9fd-2398-5afb-ad53-ce401882e8cd",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22815 affects version 3.8.5.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4640fc3d-5eeb-5cfd-b74e-23e225a49f70",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34513 affects version 3.8.5.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63dc956a-85a3-5e41-8843-4ddda09825bf",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34514 affects version 3.8.5.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d886ab1-4855-50ff-97f0-55b0deb0ab6b",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.5.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e737e23-326c-5d2f-b813-463bb6e967e2",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34516 affects version 3.8.5.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d368569-0577-5126-9043-7c5fe5eb4bd4",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34517 affects version 3.8.5.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a33394ae-3719-5b5b-b6dd-07054cb8e24f",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34518 affects version 3.8.5.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bdfad62-32a7-5eaa-b426-3f208afc67a5",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34519 affects version 3.8.5.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07ac3ab6-3944-50be-9e58-539b8d0b0cc6",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34520 affects version 3.8.5.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81283544-fce7-54be-82f7-4bca279c95f2",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34525 affects version 3.8.5.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:220382cd-2146-5865-b7e1-6b0e07b1020c",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.5.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb7ba6a5-7f2d-5dec-880f-3b72cfea28ec",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.5.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:458e8bc4-2646-5c0d-a2a3-609e989bbdd2",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.5.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1994f7c3-67f1-5df4-a3c1-a4894e0194df",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.5.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1012d36f-c3ee-532f-890f-888c80da1cc0",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.5.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54a00b31-a8dc-5ddd-bc68-1a8ec6418960",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.5.post3+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14a12ddd-b894-5c49-b56a-ff17c311c293",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.5.post3+tuxcare of aiohttp. not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd31dc80-2f7b-5cde-a058-b053ffcb47df",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.5.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2571d0b3-1e7f-546b-aecc-4c576eccf431",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.5.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd2144bd-e770-51c1-872a-ef51dad55bd4",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.5.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9481ea8-743b-5adc-84ba-178cddf9b3f8",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.5.post3+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c549f1b4-54c7-5fda-a88e-ca0aee486dc3",
      "id": "GHSA-pjjw-qhg8-p2p9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.5.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eecc83db-adbe-55dc-aa72-1ef7eee0a394",
      "id": "CVE-2025-43859",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-43859 is fixed in version 0.9.0.post1+tuxcare of h11."
      },
      "affects": [
        {
          "ref": "pkg:pypi/h11@0.9.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38b676a7-6e84-5f6d-88a5-35b7c24e42af",
      "id": "CVE-2024-37891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37891 affects version 2.0.7.post1+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@2.0.7.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ae1dadb-0b0d-5bfe-b64e-421a823d504b",
      "id": "CVE-2025-50181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-50181 is fixed in version 2.0.7.post1+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@2.0.7.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e95c9535-f705-57bd-a04b-a57c527086ea",
      "id": "CVE-2025-66418",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66418 affects version 2.0.7.post1+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@2.0.7.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b638504e-656f-5101-998d-49ba1cd9243f",
      "id": "CVE-2025-66471",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66471 affects version 2.0.7.post1+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@2.0.7.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35f239bd-e1ef-51e8-97d8-c018c1b7f100",
      "id": "CVE-2026-21441",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-21441 affects version 2.0.7.post1+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@2.0.7.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:434748f2-334b-57ac-83a3-a24db0e44fd1",
      "id": "CVE-2026-44431",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44431 affects version 2.0.7.post1+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@2.0.7.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b76c67c1-ae15-5c3c-8f78-46a06953d67d",
      "id": "CVE-2019-6446",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-6446 is fixed in version 1.16.0.post2+tuxcare of numpy."
      },
      "affects": [
        {
          "ref": "pkg:pypi/numpy@1.16.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03e9a900-a23c-56e3-b896-d80e95bf7ea6",
      "id": "CVE-2021-33430",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-33430 affects version 1.16.0.post2+tuxcare of numpy."
      },
      "affects": [
        {
          "ref": "pkg:pypi/numpy@1.16.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54444040-7f7e-5f93-ae4a-11832e1792bd",
      "id": "CVE-2021-34141",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34141 affects version 1.16.0.post2+tuxcare of numpy."
      },
      "affects": [
        {
          "ref": "pkg:pypi/numpy@1.16.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:308201a1-6fd9-52d0-8532-80fc32e8ecb6",
      "id": "CVE-2021-41495",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41495 affects version 1.16.0.post2+tuxcare of numpy."
      },
      "affects": [
        {
          "ref": "pkg:pypi/numpy@1.16.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c47189fb-5403-5166-b0eb-6c0ca0216c5a",
      "id": "CVE-2021-41496",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-41496 is fixed in version 1.16.0.post2+tuxcare of numpy."
      },
      "affects": [
        {
          "ref": "pkg:pypi/numpy@1.16.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec68fa48-14ee-5cae-b04a-06dd5379310d",
      "id": "CVE-2025-55197",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55197 is fixed in version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5650a7e-1ae8-5dc1-8b14-4da721d84944",
      "id": "CVE-2025-62707",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-62707 is fixed in version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58f103c2-184f-53c2-998c-8a6c812e778d",
      "id": "CVE-2025-62708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-62708 is fixed in version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbaaecda-f855-509d-9b8d-76f79c5a9377",
      "id": "CVE-2025-66019",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66019 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca626369-d5b4-5e67-bc59-1d02a2bdb3f3",
      "id": "CVE-2026-22690",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22690 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7d17593-675b-5ecc-b3fa-3843ed83a8f2",
      "id": "CVE-2026-22691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22691 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ef45a19-97d7-540f-9eef-5b98145fbd3e",
      "id": "CVE-2026-24688",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24688 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc63fe09-1358-5de2-8e95-839ce32c7fc0",
      "id": "CVE-2026-27024",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27024 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dca30031-7074-517a-8d4c-640b7ff94197",
      "id": "CVE-2026-27025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27025 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fde69527-c36b-575c-a479-8478611d6c8f",
      "id": "CVE-2026-27026",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27026 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82a0bc37-11c9-5e49-bb4c-d3eb23531cc6",
      "id": "CVE-2026-27628",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27628 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:486d76ad-71f4-592f-8f0b-c07dc93c1644",
      "id": "CVE-2026-27888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27888 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4d0290e-a144-5179-9051-d6a9a69a69a5",
      "id": "CVE-2026-28351",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-28351 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ace374b-cf4c-5099-b1cc-9b37d1be7747",
      "id": "CVE-2026-28804",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-28804 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1341f2da-2c9b-531a-be16-888d2ae92b44",
      "id": "CVE-2026-31826",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-31826 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4e2b8ce-6193-5f53-8307-aaea5ac937a1",
      "id": "CVE-2026-33123",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33123 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32e9ba15-11c4-5c65-9209-4985544211e4",
      "id": "CVE-2026-33699",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33699 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea928941-f0ba-5ebb-81ec-38e857c0f740",
      "id": "CVE-2026-40260",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40260 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e11297dc-2613-5f56-8e54-97ad4fe47908",
      "id": "CVE-2026-41168",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41168 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:084b1f7e-9d50-591e-9b43-a33b8ff789b0",
      "id": "CVE-2026-41312",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41312 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb01faf7-bd75-5693-b979-9f77da5ff8a8",
      "id": "CVE-2026-41313",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41313 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5f3ba5b-653a-50b1-90d2-d8ceabe7cdb6",
      "id": "CVE-2026-41314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41314 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66bd27d8-349c-592f-9ebe-fa6684a35308",
      "id": "CVE-2026-48155",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48155 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b081c9e-9a03-55b0-9ca9-ef8390339ed8",
      "id": "CVE-2026-48156",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48156 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5752a9ad-1b3b-588c-9051-ae2f27fff56e",
      "id": "CVE-2026-48735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48735 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb950a37-8d3a-5f37-bec4-9a398a714436",
      "id": "CVE-2026-49460",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49460 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7618faee-ff86-5ac5-99b6-997270007304",
      "id": "CVE-2026-49461",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49461 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ee81747-f104-5bfc-b6df-1008e360e26c",
      "id": "CVE-2026-54530",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54530 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83513cd2-1d8d-5bea-b32e-912fea23dfd5",
      "id": "CVE-2026-54531",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54531 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:077b226e-f716-59fa-9fca-10a0f313cfdb",
      "id": "CVE-2026-54651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54651 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d955b3f9-ba36-5fa1-b28c-1b020cd8ea65",
      "id": "CVE-2026-59935",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59935 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f89506dd-60fc-50c8-ba36-d7413c46e673",
      "id": "CVE-2026-59936",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59936 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34c8f516-35eb-5c48-9ca6-21984cffa506",
      "id": "CVE-2026-59937",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59937 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d5af52d-5de2-5b50-8b94-988e9f31e51e",
      "id": "CVE-2026-59938",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59938 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2c3f964-09b6-5df8-bf55-baee19c68db3",
      "id": "GHSA-4pxv-j86v-mhcw",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:692e2e55-429f-58c4-b53b-1448b6fb7e49",
      "id": "GHSA-7gw9-cf7v-778f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1535f64-8bc1-5ef7-ac63-3a560e0a6146",
      "id": "GHSA-9m86-7pmv-2852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58c8d490-011c-5cc2-b423-7efcb185b893",
      "id": "GHSA-jj6c-8h6c-hppx",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2103984e-5e6f-5db8-9d5d-ec1fc6747b20",
      "id": "GHSA-jm82-fx9c-mx94",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-jm82-fx9c-mx94 affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f04991e-f313-569c-a623-7b1c5104fa4e",
      "id": "GHSA-x284-j5p8-9c5p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-x284-j5p8-9c5p affects version 5.9.0.post3+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e5171c6-90f8-590e-b66e-85c79cb1e559",
      "id": "CVE-2017-18342",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2017-18342 is fixed in version 3.13.post1+tuxcare of pyyaml."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyyaml@3.13.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0c95004-38c7-5e32-a530-83a075c0ea19",
      "id": "CVE-2020-14343",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-14343 is fixed in version 3.13.post1+tuxcare of pyyaml."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyyaml@3.13.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b0783b2-5c66-58f5-936e-48ba0f9fb127",
      "id": "AIKIDO-2024-10370",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2024-10370 is fixed in version 2.7.0.post1+tuxcare of sentence-transformers."
      },
      "affects": [
        {
          "ref": "pkg:pypi/sentence-transformers@2.7.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6148a11a-9fde-5bff-9ab9-748d6b1ec940",
      "id": "CVE-2022-22817",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22817 is fixed in version 8.4.0.post1+tuxcare of mysql-connector-python."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mysql-connector-python@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f537103-ff4e-5541-ba95-d9e0a13966b3",
      "id": "CVE-2022-24303",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-24303 is fixed in version 8.4.0.post1+tuxcare of mysql-connector-python."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mysql-connector-python@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:239972d6-99df-567b-b750-b0b706064c85",
      "id": "CVE-2022-45198",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45198 is fixed in version 8.4.0.post1+tuxcare of mysql-connector-python."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mysql-connector-python@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7ec2150-c037-513a-bfbc-fa08544596db",
      "id": "CVE-2023-50447",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-50447 is fixed in version 8.4.0.post1+tuxcare of mysql-connector-python."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mysql-connector-python@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:968136ff-9126-5d02-9dbe-4313cf265b16",
      "id": "CVE-2024-21272",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-21272 is fixed in version 8.4.0.post1+tuxcare of mysql-connector-python."
      },
      "affects": [
        {
          "ref": "pkg:pypi/mysql-connector-python@8.4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a92ab1f5-7224-57fc-b1be-0f025c98afbb",
      "id": "CVE-2022-29217",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29217 is fixed in version 1.7.1.post1+tuxcare of pyjwt."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@1.7.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d5ad0b7-3d53-54e8-966a-cb3eeede041e",
      "id": "CVE-2026-32597",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32597 affects version 1.7.1.post1+tuxcare of pyjwt."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@1.7.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76b05c85-6faa-5772-b82a-9b08334c5c6e",
      "id": "CVE-2026-48522",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-48522 does not affect version 1.7.1.post1+tuxcare of pyjwt. not_affected \u2014 Version 1.7.1 is not affected by CVE-2026-48522. The vulnerability concerns PyJWKClient accepting non-HTTP(S) URL schemes (file://, ftp://, data:) without validation, enabling local file read and SSRF. However, PyJWKClient class does not exist in version 1.7.1 - it was introduced in later versions (tested vulnerable in 2.11.0 and 2.12.1). The affected component and its entire remote JWKS fetchi..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@1.7.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ad33ba7-0ad4-552d-b970-b8462c39075d",
      "id": "CVE-2026-48524",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-48524 does not affect version 1.7.1.post1+tuxcare of pyjwt. not_affected \u2014 PyJWT version 1.7.1 is not affected by CVE-2026-48524. The vulnerability concerns PyJWKClient.fetch_data() clearing the JWKS cache on fetch errors, enabling unlimited HTTP requests. PyJWKClient was introduced in PyJWT 2.0.0 (2021), and this target version 1.7.1 (2018) predates that feature entirely. No JWKS fetching capability, no cache mechanism, and no code path exists for the vulnerability p..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@1.7.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48f1f0c5-f545-5376-a4ee-c57b7609c29d",
      "id": "CVE-2026-48525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48525 affects version 1.7.1.post1+tuxcare of pyjwt."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@1.7.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c430602-4395-5e76-bb0f-f22303f0a766",
      "id": "CVE-2026-48526",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48526 affects version 1.7.1.post1+tuxcare of pyjwt."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@1.7.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbc09aaa-d622-52b3-9d17-faefa341de7d",
      "id": "CVE-2025-55197",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55197 is fixed in version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5223778b-c91a-5d00-a3ed-02341ff8db08",
      "id": "CVE-2025-62707",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-62707 is fixed in version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4aef023-1fdc-5356-942a-03ede0445b26",
      "id": "CVE-2025-62708",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-62708 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a90b8e40-6426-506c-a852-e74ad5b430d6",
      "id": "CVE-2025-66019",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66019 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1c26ff8-4902-507e-a46e-d791399376a9",
      "id": "CVE-2026-22690",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22690 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13631f30-da95-594c-92ed-adb44fade09b",
      "id": "CVE-2026-22691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22691 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:285582ab-9537-5bfe-92f9-379da24a3611",
      "id": "CVE-2026-24688",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24688 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7a65dd1-fd78-5e7e-acfd-83e4337c2fee",
      "id": "CVE-2026-27024",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27024 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1322d25-0c6b-549b-b1c3-85a7b0482229",
      "id": "CVE-2026-27025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27025 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a657ec0-8eff-5ac0-a5dd-fdd1e8ae81bd",
      "id": "CVE-2026-27026",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27026 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3a86814-ac0c-5ba8-b2ac-2a92ea3205b9",
      "id": "CVE-2026-27628",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27628 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e33b2984-7c66-54c3-9646-2c7e9ad3d7b8",
      "id": "CVE-2026-27888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27888 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3aca3b7b-a58f-58ad-9069-c2b10aa315f8",
      "id": "CVE-2026-28351",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-28351 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b12c9bd7-ba14-536c-8f82-6e71b19df3f6",
      "id": "CVE-2026-28804",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-28804 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6719b708-52fc-5b05-b210-283fb6335a66",
      "id": "CVE-2026-31826",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-31826 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea663bf1-fbd1-5871-8951-5f3254903a33",
      "id": "CVE-2026-33123",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33123 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:771b343e-1c38-5689-af8c-b6702404702a",
      "id": "CVE-2026-33699",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33699 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6cf0734b-8134-5fc4-b95b-22b7d8bad280",
      "id": "CVE-2026-40260",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40260 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66aed09a-1c91-55cd-8323-b527cfc6f2ca",
      "id": "CVE-2026-41168",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41168 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57085391-a59a-5d8d-ac55-96ce810d0e20",
      "id": "CVE-2026-41312",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41312 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77748d78-1a22-584f-8508-52bf6533c0fa",
      "id": "CVE-2026-41313",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41313 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea6157af-72e9-5ede-9cea-5d8e2deb8016",
      "id": "CVE-2026-41314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41314 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df38fb41-52b9-52f8-8d0d-4e968fded98d",
      "id": "CVE-2026-48155",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48155 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a98dacd-a1e8-55b7-a172-a575fc4e2daf",
      "id": "CVE-2026-48156",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48156 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab3bcb28-5600-5877-ab2c-74bd02b49f39",
      "id": "CVE-2026-48735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48735 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdcafc89-9aa0-5f00-95df-88d9f29be8da",
      "id": "CVE-2026-49460",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49460 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:607bffe6-b136-5dc6-8ec3-c271ab282cfe",
      "id": "CVE-2026-49461",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49461 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b45288cc-25b9-5852-93ce-6c605b1906e5",
      "id": "CVE-2026-54530",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54530 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad96fc7c-c28f-5e9b-a4bd-9c398b48087d",
      "id": "CVE-2026-54531",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54531 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:083dacdd-3cfd-5db2-98f4-529548a4ba93",
      "id": "CVE-2026-54651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54651 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9055e24-19b6-5946-a634-27306c8e80dc",
      "id": "CVE-2026-59935",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59935 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37754617-b42c-5a37-a83f-e67f1ce763ba",
      "id": "CVE-2026-59936",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59936 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d744651f-2e8c-5cf9-b3d4-abdbef4817ed",
      "id": "CVE-2026-59937",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59937 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab93f720-8a2b-53bf-9acd-8448ef77f25e",
      "id": "CVE-2026-59938",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59938 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d43c71e0-c997-5949-bba5-690651823f6f",
      "id": "GHSA-4pxv-j86v-mhcw",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c7426d9-e8ac-57c9-b704-5d7b3c9ae15f",
      "id": "GHSA-7gw9-cf7v-778f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e011c833-4f08-5515-adba-17802e43e993",
      "id": "GHSA-9m86-7pmv-2852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aada6d10-9ab2-5919-b159-7c21b5f2b493",
      "id": "GHSA-jj6c-8h6c-hppx",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca13d0b7-cc5e-5d70-b1cc-b4aa39844596",
      "id": "GHSA-jm82-fx9c-mx94",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-jm82-fx9c-mx94 affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5169f07a-5e7c-5824-94b0-1da8b7fe2c61",
      "id": "GHSA-x284-j5p8-9c5p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-x284-j5p8-9c5p affects version 5.9.0.post2+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0ed95b2-d5da-51db-826c-ed33408f627a",
      "id": "CVE-2023-29159",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-29159 affects version 0.13.6.post1+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.13.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c41694aa-d7a6-586d-b8b6-d40f72e2771c",
      "id": "CVE-2023-30798",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-30798 affects version 0.13.6.post1+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.13.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf39cc41-bb66-559c-b679-ff1d8cf6745f",
      "id": "CVE-2024-47874",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-47874 affects version 0.13.6.post1+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.13.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd53f96f-e2f2-5f39-8410-600cf1f3f001",
      "id": "CVE-2025-54121",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-54121 is fixed in version 0.13.6.post1+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.13.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11cf1efa-317b-5e6b-a5f6-3272fbc04fcd",
      "id": "CVE-2025-62727",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-62727 affects version 0.13.6.post1+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.13.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5ba710f-9159-5710-85b9-9e9a5f551314",
      "id": "CVE-2026-48710",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48710 affects version 0.13.6.post1+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.13.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d29e4779-5f21-5619-93cf-53e54b4d6898",
      "id": "CVE-2026-48817",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48817 affects version 0.13.6.post1+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.13.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04cccc80-2212-5463-873c-782ab7106ed3",
      "id": "CVE-2026-48818",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48818 affects version 0.13.6.post1+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.13.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a6e1010-693b-536d-bcd6-4c921b31da28",
      "id": "CVE-2026-54282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54282 affects version 0.13.6.post1+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.13.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2caca229-8bef-52af-819a-49be0827ec47",
      "id": "CVE-2026-54283",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54283 affects version 0.13.6.post1+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.13.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4126c298-21f7-57d3-84a6-631afdd09a6a",
      "id": "GHSA-3qj8-93xh-pwh2",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-3qj8-93xh-pwh2 is a false positive for starlette 0.13.6.post1+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.13.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc61b878-4799-5729-9593-2cf99cc6724f",
      "id": "GHSA-93gm-qmq6-w238",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-93gm-qmq6-w238 affects version 0.13.6.post1+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.13.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2d41b9b-0261-5c75-9d6a-e5846826a829",
      "id": "GHSA-qj8w-rv5x-2v9h",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-qj8w-rv5x-2v9h is a false positive for starlette 0.13.6.post1+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.13.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:384740fa-3b1c-5d41-b126-cfa0ba59e1d0",
      "id": "CVE-2021-33880",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-33880 is fixed in version 8.1.post1+tuxcare of websockets."
      },
      "affects": [
        {
          "ref": "pkg:pypi/websockets@8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5768009-2d7c-5ed1-96be-a9c3aeda98f7",
      "id": "CVE-2024-47874",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47874 is fixed in version 0.27.0.post2+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f61cacce-035e-5413-b929-c47266f1303d",
      "id": "CVE-2025-54121",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-54121 is fixed in version 0.27.0.post2+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3447de6c-88ca-5bfb-b07a-27e2d981652b",
      "id": "CVE-2025-62727",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-62727 does not affect version 0.27.0.post2+tuxcare of starlette. Version 0.27.0 is not vulnerable. Summary: The target repository (Starlette version 0.27.0) is NOT vulnerable to CVE-2025-62727. The vulnerable Range header parsing logic was introduced in version 0.39.0, and the target version 0.27.0 predates this introduction. The FileResponse class in version 0.27.0 does not implement any Range header parsing or processing functionality. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15f27604-8902-50fe-b96c-912653ab4193",
      "id": "CVE-2026-48710",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48710 affects version 0.27.0.post2+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:889281ee-ea1a-5e43-834a-8537f6d5f7b7",
      "id": "CVE-2026-48817",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48817 affects version 0.27.0.post2+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf02f091-cb27-5022-8571-4266b96a2969",
      "id": "CVE-2026-48818",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48818 affects version 0.27.0.post2+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6f6f010-26e4-50f0-a56e-8563f1a45235",
      "id": "CVE-2026-54282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54282 affects version 0.27.0.post2+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f576d12d-124d-5226-b323-9cb3ce0f6d5e",
      "id": "CVE-2026-54283",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54283 affects version 0.27.0.post2+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2cd6e599-c6e6-56ad-bfd0-e787cf8dca37",
      "id": "GHSA-93gm-qmq6-w238",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-93gm-qmq6-w238 is a false positive for starlette 0.27.0.post2+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d1c0b63-bd82-5a50-93e8-e89b2263cd05",
      "id": "CVE-2021-33503",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-33503 affects version 1.26.4.post2+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ac67388-9e0f-5b4f-a7cb-74cc78de82cf",
      "id": "CVE-2023-43804",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-43804 affects version 1.26.4.post2+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3fed0294-cdd3-5e90-b10d-f9832863570b",
      "id": "CVE-2023-45803",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45803 is fixed in version 1.26.4.post2+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:564d84fb-8c75-5c0d-8e3a-09c23076f717",
      "id": "CVE-2024-37891",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-37891 is fixed in version 1.26.4.post2+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50779d2b-0ec1-58af-b536-dd91a5fec825",
      "id": "CVE-2025-50181",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-50181 affects version 1.26.4.post2+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cdeacf22-5cb1-5271-89fc-76d28173582c",
      "id": "CVE-2025-66418",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66418 affects version 1.26.4.post2+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea13b502-3210-554e-95a5-9fd3619b785e",
      "id": "CVE-2025-66471",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66471 affects version 1.26.4.post2+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9b1c7d3-14de-5ddc-81a9-a34330517540",
      "id": "CVE-2026-21441",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-21441 affects version 1.26.4.post2+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:706fa0c1-5d0a-5c89-a3dd-dcc38750ba85",
      "id": "CVE-2026-44431",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44431 affects version 1.26.4.post2+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ccf807d-0f88-545e-b966-226263e8672a",
      "id": "CVE-2024-3651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-3651 is fixed in version 2.10.post1+tuxcare of idna."
      },
      "affects": [
        {
          "ref": "pkg:pypi/idna@2.10.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3213a83-30f8-5d99-bd12-655ecf5d1827",
      "id": "AIKIDO-2024-10275",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2024-10275 is fixed in version 0.14.5.post1+tuxcare of statsmodels."
      },
      "affects": [
        {
          "ref": "pkg:pypi/statsmodels@0.14.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee5cfb05-7271-57a4-a813-02e340f60b86",
      "id": "CVE-2024-31580",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-31580 is fixed in version 1.13.1.post2+tuxcare of torch."
      },
      "affects": [
        {
          "ref": "pkg:pypi/torch@1.13.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1abcbc7-d7f5-5e48-a9be-1432ee48f0e8",
      "id": "CVE-2024-31583",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-31583 is fixed in version 1.13.1.post2+tuxcare of torch."
      },
      "affects": [
        {
          "ref": "pkg:pypi/torch@1.13.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4a2d8f3-3d90-5629-b7bd-50de33fbed08",
      "id": "CVE-2024-7804",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-7804 is a false positive for torch 1.13.1.post2+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/torch@1.13.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fae0895-b881-5e62-8c26-7a12d07e6407",
      "id": "CVE-2025-2148",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-2148 affects version 1.13.1.post2+tuxcare of torch."
      },
      "affects": [
        {
          "ref": "pkg:pypi/torch@1.13.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:049e5103-dc44-5cc7-b827-d7451118717f",
      "id": "CVE-2025-2149",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-2149 affects version 1.13.1.post2+tuxcare of torch."
      },
      "affects": [
        {
          "ref": "pkg:pypi/torch@1.13.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2720fb3-c37e-5357-ac58-2e8e2fd06c19",
      "id": "CVE-2025-2953",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-2953 affects version 1.13.1.post2+tuxcare of torch."
      },
      "affects": [
        {
          "ref": "pkg:pypi/torch@1.13.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70fb9423-d028-5f05-aa0f-68662ec69c1a",
      "id": "CVE-2025-2998",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-2998 affects version 1.13.1.post2+tuxcare of torch."
      },
      "affects": [
        {
          "ref": "pkg:pypi/torch@1.13.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51cbeb7f-8c89-54da-8d9e-c967d7bdb049",
      "id": "CVE-2025-2999",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-2999 affects version 1.13.1.post2+tuxcare of torch."
      },
      "affects": [
        {
          "ref": "pkg:pypi/torch@1.13.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7d0949b-2ec9-5640-92b2-6dcee40b2d33",
      "id": "CVE-2025-3000",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-3000 affects version 1.13.1.post2+tuxcare of torch."
      },
      "affects": [
        {
          "ref": "pkg:pypi/torch@1.13.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12bd2a4c-6f57-5b21-944b-ec5fad615d9a",
      "id": "CVE-2025-3001",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-3001 affects version 1.13.1.post2+tuxcare of torch."
      },
      "affects": [
        {
          "ref": "pkg:pypi/torch@1.13.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb7f1197-52a9-5924-a4a8-7f11aab9cc39",
      "id": "CVE-2025-32434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-32434 is fixed in version 1.13.1.post2+tuxcare of torch."
      },
      "affects": [
        {
          "ref": "pkg:pypi/torch@1.13.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0c471f7-732c-50c1-971b-59ad2c5ce634",
      "id": "CVE-2025-3730",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-3730 affects version 1.13.1.post2+tuxcare of torch."
      },
      "affects": [
        {
          "ref": "pkg:pypi/torch@1.13.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee0c1905-8007-5de8-8d25-9b28b8ab2de8",
      "id": "CVE-2020-14343",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-14343 is fixed in version 5.3.1.post1+tuxcare of pyyaml."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyyaml@5.3.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bde3fdd5-d69e-5a71-af5d-fb153a61969e",
      "id": "CVE-2022-21712",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-21712 is fixed in version 20.3.0.post4+tuxcare of twisted."
      },
      "affects": [
        {
          "ref": "pkg:pypi/twisted@20.3.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfc5576b-51f3-5fa4-8069-dd4c54d4715a",
      "id": "CVE-2022-24801",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-24801 affects version 20.3.0.post4+tuxcare of twisted."
      },
      "affects": [
        {
          "ref": "pkg:pypi/twisted@20.3.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:177dedfe-29f8-5c0f-9144-022c8d7022be",
      "id": "CVE-2022-39348",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-39348 affects version 20.3.0.post4+tuxcare of twisted."
      },
      "affects": [
        {
          "ref": "pkg:pypi/twisted@20.3.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:119d3c57-801a-5e5e-9b7b-c26730a97523",
      "id": "CVE-2023-46137",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-46137 is fixed in version 20.3.0.post4+tuxcare of twisted."
      },
      "affects": [
        {
          "ref": "pkg:pypi/twisted@20.3.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c393675b-950a-59c0-9235-89b6fc11e0c0",
      "id": "CVE-2024-41671",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-41671 is fixed in version 20.3.0.post4+tuxcare of twisted."
      },
      "affects": [
        {
          "ref": "pkg:pypi/twisted@20.3.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:640f580d-7840-5c45-8eb4-492330efa91d",
      "id": "CVE-2024-41810",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-41810 is fixed in version 20.3.0.post4+tuxcare of twisted."
      },
      "affects": [
        {
          "ref": "pkg:pypi/twisted@20.3.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e22b768a-e02e-592d-b670-6434e9ab1b02",
      "id": "CVE-2026-42304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42304 affects version 20.3.0.post4+tuxcare of twisted."
      },
      "affects": [
        {
          "ref": "pkg:pypi/twisted@20.3.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5b2cf36-15f1-5b52-ab2d-254f17756a3a",
      "id": "CVE-2022-41323",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41323 is fixed in version 5.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9478a453-cf90-58db-905d-e34482aed0c0",
      "id": "CVE-2024-45230",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-45230 is fixed in version 5.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93200afd-decc-5b89-a9f6-215207775354",
      "id": "CVE-2024-45231",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-45231 is fixed in version 5.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cdb3c8dc-3b36-5d00-a29a-4f7fba3cad58",
      "id": "CVE-2024-53907",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-53907 is fixed in version 5.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9369403e-2fb8-5f23-95c5-718f5b4aa6c1",
      "id": "CVE-2024-53908",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-53908 is fixed in version 5.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df985299-6239-543e-8227-e94072213d91",
      "id": "CVE-2024-56374",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56374 affects version 5.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ab06c8c-1075-5fd2-8fc2-4e9a954239f4",
      "id": "CVE-2025-13372",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13372 affects version 5.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:707357fa-320b-5b10-bbd5-97d6ef9c014b",
      "id": "CVE-2025-13473",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13473 affects version 5.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2f45c56-1b81-54a2-add1-7ec92348f393",
      "id": "CVE-2025-14550",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-14550 affects version 5.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31987654-1e81-557d-87b4-7ca807193982",
      "id": "CVE-2025-26699",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-26699 affects version 5.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15776993-5e01-5adb-a2b6-4d498e2844b3",
      "id": "CVE-2025-27556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27556 is fixed in version 5.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab6ff40d-cf1f-542e-93af-8d6d401142b7",
      "id": "CVE-2025-32873",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-32873 affects version 5.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:871f3897-3d94-5cfc-b554-0b441ea7a819",
      "id": "CVE-2025-48432",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48432 affects version 5.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ea5354e-f690-568c-a421-691286b0411f",
      "id": "CVE-2025-57833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57833 affects version 5.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0a251d2-e5e7-5941-9cf1-95760adb4ac3",
      "id": "CVE-2025-59681",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59681 affects version 5.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad2eb092-e415-5eb1-b44c-80890f6ee409",
      "id": "CVE-2025-59682",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59682 affects version 5.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7fbf3be-5622-54bf-8bfa-aecef2c4150d",
      "id": "CVE-2025-64458",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64458 affects version 5.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1cde4519-5b22-5060-a271-8875eea32227",
      "id": "CVE-2025-64459",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64459 affects version 5.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c85ba4b0-2ca5-5615-b685-f35f98df14ff",
      "id": "CVE-2025-64460",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64460 affects version 5.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ecc04fc-c3df-5fcb-befb-5f9e0f9cef56",
      "id": "CVE-2026-1207",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1207 affects version 5.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba3be317-4383-58f5-bb38-18037d2bc004",
      "id": "CVE-2026-1285",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1285 affects version 5.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76044b79-6357-548b-b837-e87d0beec1ec",
      "id": "CVE-2026-1287",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1287 affects version 5.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1af5a6e-0bf0-5ec1-9cca-74e7f05eb1fb",
      "id": "CVE-2026-1312",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1312 affects version 5.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df3a1a4f-59f4-56a8-a480-5733dbea45b5",
      "id": "CVE-2025-4565",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-4565 is fixed in version 4.24.3.post1+tuxcare of protobuf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/protobuf@4.24.3.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4e8790a-d244-5b6e-8e33-44f18e7b8b65",
      "id": "CVE-2026-0994",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-0994 affects version 4.24.3.post1+tuxcare of protobuf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/protobuf@4.24.3.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4d7f48b-d45f-53c1-906b-12f93dcfc3e7",
      "id": "CVE-2025-48432",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48432 is fixed in version 4.2.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1404475-e31e-57ef-b5b0-babae5c905e4",
      "id": "CVE-2021-45115",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-45115 is fixed in version 4.0.post6+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e14dc33-5790-53fd-8c3b-8e51fb2aa11c",
      "id": "CVE-2021-45116",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-45116 is fixed in version 4.0.post6+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f18bd33-62b0-5ffb-b1f6-d79d28500d39",
      "id": "CVE-2021-45452",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-45452 is fixed in version 4.0.post6+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db6d89c4-7cf5-56b7-89a0-42f100c06a94",
      "id": "CVE-2022-22818",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22818 is fixed in version 4.0.post6+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a95d7522-d10a-5eef-a577-fce158313f52",
      "id": "CVE-2022-23833",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23833 is fixed in version 4.0.post6+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80374467-343e-57b2-a4b8-1292263485cb",
      "id": "CVE-2022-28346",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-28346 is fixed in version 4.0.post6+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4671620-b81e-54f3-a300-27aefebb1f59",
      "id": "CVE-2022-28347",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-28347 is fixed in version 4.0.post6+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1350a52-e784-5350-aa69-062dde7b7b54",
      "id": "CVE-2022-34265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-34265 is fixed in version 4.0.post6+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55d6b887-e156-54b3-9fa8-fd2e1b105620",
      "id": "CVE-2022-36359",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-36359 is fixed in version 4.0.post6+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ff062ad-96ca-5908-8b70-0ae0abe2ece9",
      "id": "CVE-2022-41323",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41323 is fixed in version 4.0.post6+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32b46b89-ed27-525c-95e1-41e32055ef65",
      "id": "CVE-2023-23969",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-23969 is fixed in version 4.0.post6+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3aed2f73-0d00-50e1-8d52-78f74fdf8322",
      "id": "CVE-2023-24580",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-24580 is fixed in version 4.0.post6+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c97710e-21c0-5aca-a2c1-f65d723a9082",
      "id": "CVE-2023-31047",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-31047 affects version 4.0.post6+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5cd85cf0-87c7-5a07-bc1a-68aae443fe78",
      "id": "CVE-2023-36053",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36053 affects version 4.0.post6+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7716de4-5937-51a9-88d5-49b5fa5ef4d5",
      "id": "CVE-2023-43665",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-43665 affects version 4.0.post6+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be1b0585-17f1-5bc6-9d37-dfc2f4bf227e",
      "id": "CVE-2023-46695",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46695 affects version 4.0.post6+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd74fd34-90b3-5bfb-9abf-d5552b2e819e",
      "id": "CVE-2024-45231",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-45231 affects version 4.0.post6+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47bba8d3-d5c7-510f-8ca0-ccdd9ab4f86d",
      "id": "CVE-2025-13372",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13372 affects version 4.0.post6+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8eac620-0fdd-5e29-9dc5-8814fbc09044",
      "id": "CVE-2025-13473",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13473 affects version 4.0.post6+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90ba057c-19f6-5ad5-82a0-1792475a7464",
      "id": "CVE-2025-14550",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-14550 affects version 4.0.post6+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1fac234c-1152-5b09-8986-60739ef1caee",
      "id": "CVE-2025-48432",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48432 affects version 4.0.post6+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b388115-29f8-5f9a-b7be-c4b734ddcc87",
      "id": "CVE-2025-57833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57833 affects version 4.0.post6+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3fdcbfc-5760-5a33-8318-7873904630c4",
      "id": "CVE-2025-64458",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64458 affects version 4.0.post6+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4247ae8-2466-5859-9fc9-85197a1cba5d",
      "id": "CVE-2025-64459",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64459 affects version 4.0.post6+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c883a646-36aa-5905-876b-30096f567922",
      "id": "CVE-2025-64460",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64460 affects version 4.0.post6+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b01621cd-7fe9-5a45-a296-1d22ebaa7028",
      "id": "CVE-2026-1207",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1207 affects version 4.0.post6+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e64c0776-4987-5bbe-9a1c-646183468e36",
      "id": "CVE-2026-1285",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1285 affects version 4.0.post6+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d66f3d7-a3fa-5292-ac68-464db5078f0d",
      "id": "CVE-2026-1287",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1287 affects version 4.0.post6+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c9d44aa-bde6-5e22-a581-d14485c4034c",
      "id": "CVE-2026-1312",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1312 affects version 4.0.post6+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post6+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84f91a8e-9e79-5d8d-b680-7a3039b1fa28",
      "id": "CVE-2022-41323",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41323 is fixed in version 5.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6321c66-0a05-5863-aa00-58c0285ba855",
      "id": "CVE-2024-45230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-45230 affects version 5.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72945da6-550c-540f-b23c-4c206affd53d",
      "id": "CVE-2024-45231",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-45231 is fixed in version 5.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0a81b27-52ce-5d17-be1f-f3b450577b86",
      "id": "CVE-2024-53907",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-53907 affects version 5.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ece02c4b-c795-58cf-b8d8-79dd8e457aed",
      "id": "CVE-2024-53908",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-53908 affects version 5.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64abaa72-e28f-5f8e-a105-da34390363ce",
      "id": "CVE-2024-56374",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56374 affects version 5.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58b821bc-1d6c-5b44-9bc6-c4b8d461bf34",
      "id": "CVE-2025-13372",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13372 affects version 5.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02b5c3e5-8488-5ddb-ae33-a34a320a47b3",
      "id": "CVE-2025-13473",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13473 affects version 5.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8091bf8c-137d-512e-8fb7-45b3e2d5585a",
      "id": "CVE-2025-14550",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-14550 affects version 5.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b983bf59-3033-5786-bfbb-1c4cff401554",
      "id": "CVE-2025-26699",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-26699 affects version 5.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f78baaa-574e-5291-8ae4-fd153768e105",
      "id": "CVE-2025-27556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27556 is fixed in version 5.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b0a949d-29b1-592f-9484-1c2ea405be4a",
      "id": "CVE-2025-32873",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-32873 affects version 5.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70153eb6-4c9a-5fdc-b985-0b40fa83bf1f",
      "id": "CVE-2025-48432",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48432 affects version 5.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4523839-9aa5-5468-a587-abf8cc530357",
      "id": "CVE-2025-57833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57833 affects version 5.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6fd7a132-eece-53c3-bc66-81acb047529b",
      "id": "CVE-2025-59681",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59681 affects version 5.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5bcf3abc-1dc4-55c0-86c1-48f96668acea",
      "id": "CVE-2025-59682",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59682 affects version 5.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6da736ca-2aad-578d-a286-0604dffb0ff2",
      "id": "CVE-2025-64458",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64458 affects version 5.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2a5e1b8-f0d2-5719-9080-0bff70915024",
      "id": "CVE-2025-64459",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64459 affects version 5.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b79a4727-7613-5258-becb-f76095cfcc95",
      "id": "CVE-2025-64460",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64460 affects version 5.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50651c10-caa7-5300-9a8e-eacdc4b1ecf1",
      "id": "CVE-2026-1207",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1207 affects version 5.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21bc1a03-9f6d-54ea-83b5-e01a28c09fe2",
      "id": "CVE-2026-1285",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1285 affects version 5.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:648d80aa-6185-5db3-8650-e8b114a09d89",
      "id": "CVE-2026-1287",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1287 affects version 5.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f56f091-feb0-5f8b-8013-9373d0f4a9b6",
      "id": "CVE-2026-1312",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1312 affects version 5.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2f2af2b-b97c-5649-88c3-de0fea716690",
      "id": "CVE-2021-45115",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-45115 is fixed in version 4.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:751c4fa0-bda2-57e6-8189-2f56ccb0bbe3",
      "id": "CVE-2021-45116",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-45116 is fixed in version 4.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dac8eea2-d2c1-50ac-a1e3-2bcad11bfb47",
      "id": "CVE-2021-45452",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-45452 is fixed in version 4.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:635de059-eccb-5567-8dcb-bcf66d50042f",
      "id": "CVE-2022-22818",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22818 is fixed in version 4.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:709ac6c5-8ebd-511c-9fa5-e621e10c7fb9",
      "id": "CVE-2022-23833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-23833 affects version 4.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0946e9d0-cfc3-5403-823d-1e50a205f01c",
      "id": "CVE-2022-28346",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-28346 is fixed in version 4.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bedc5a41-928f-57c3-b326-86fb664a2596",
      "id": "CVE-2022-28347",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-28347 is fixed in version 4.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c46c78c-b70f-5af8-bfd4-160bb6dcd561",
      "id": "CVE-2022-34265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-34265 is fixed in version 4.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03b5e8e4-9c0f-53ba-8e5c-27fe2953fad8",
      "id": "CVE-2022-36359",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-36359 is fixed in version 4.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1de26558-0629-5e00-9208-9b25f3c0422b",
      "id": "CVE-2022-41323",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41323 is fixed in version 4.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed67a51c-9a38-5a87-83ab-389e2d123fe7",
      "id": "CVE-2023-23969",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-23969 is fixed in version 4.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12706750-6d74-584f-822c-ed9c3b81f5ed",
      "id": "CVE-2023-24580",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-24580 is fixed in version 4.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1d8e87c-0ac7-57c5-8e9e-9721112f088b",
      "id": "CVE-2023-31047",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-31047 affects version 4.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8aaff1d-968f-565a-9002-f4b10e1c4c3d",
      "id": "CVE-2023-36053",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36053 affects version 4.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f250baa5-3d4b-59a1-abff-8fd4e2f1aef0",
      "id": "CVE-2023-43665",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-43665 affects version 4.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4fbd092-3ddd-54e6-bb34-b8b83a85d1cd",
      "id": "CVE-2023-46695",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46695 affects version 4.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7cd3676-c152-5ea0-aad7-729663f02858",
      "id": "CVE-2024-45231",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-45231 affects version 4.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e0cc13a-7ed6-596d-b168-612656b5c263",
      "id": "CVE-2025-13372",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13372 affects version 4.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:585da3e4-b440-5f4f-ba4d-18a0be6155c2",
      "id": "CVE-2025-13473",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13473 affects version 4.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc588eb3-3ce3-5eff-a787-5fb54bc7394f",
      "id": "CVE-2025-14550",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-14550 affects version 4.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5009cf9f-4afb-546a-b32d-15e27fc11b8d",
      "id": "CVE-2025-48432",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48432 affects version 4.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6f702d8-21bb-5b88-8b16-9f1138c0c422",
      "id": "CVE-2025-57833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57833 affects version 4.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e48d701b-df29-5a9c-90cf-040c2e06dac6",
      "id": "CVE-2025-64458",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64458 affects version 4.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4ea329f-104b-54ca-9338-978b0f881dab",
      "id": "CVE-2025-64459",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64459 affects version 4.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7028ba83-165c-5ba9-b105-889dbe12f0f4",
      "id": "CVE-2025-64460",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64460 affects version 4.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a6f0b87-5dcc-5c76-b1e4-24a1ac334b3f",
      "id": "CVE-2026-1207",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1207 affects version 4.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36beca3c-383f-5163-993f-4e175d2af20b",
      "id": "CVE-2026-1285",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1285 affects version 4.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74999049-0398-5d7b-a9e7-403528aedacc",
      "id": "CVE-2026-1287",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1287 affects version 4.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa6aa2cc-1ba3-53fe-bbb7-d1fc300be38d",
      "id": "CVE-2026-1312",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1312 affects version 4.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:977359de-8f9e-53ba-ac08-aa6c8d7bfacc",
      "id": "CVE-2021-33503",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-33503 affects version 1.26.4.post1+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4d9a73a-7e1a-5e34-9833-652d004473fb",
      "id": "CVE-2023-43804",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-43804 affects version 1.26.4.post1+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09dad9c5-0d25-5920-b55a-fa66f048cbfe",
      "id": "CVE-2023-45803",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45803 is fixed in version 1.26.4.post1+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ab521a2-8554-5415-b588-e4c344547bd3",
      "id": "CVE-2024-37891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37891 affects version 1.26.4.post1+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e77a844-e89a-5134-a301-2d42e56c866a",
      "id": "CVE-2025-50181",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-50181 affects version 1.26.4.post1+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68cfcab4-ccef-5a79-b15c-b6d035e9c8f7",
      "id": "CVE-2025-66418",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66418 affects version 1.26.4.post1+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f94a7fdc-d7d2-5f82-89ec-3284822fd8a2",
      "id": "CVE-2025-66471",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66471 affects version 1.26.4.post1+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b944941b-ee10-501b-9159-e55b7a526a66",
      "id": "CVE-2026-21441",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-21441 affects version 1.26.4.post1+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2dc7c979-ed0d-5028-94fb-62aecef3c31f",
      "id": "CVE-2026-44431",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44431 affects version 1.26.4.post1+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1fb22c0-6f99-5714-8041-097717b2d2db",
      "id": "CVE-2024-31580",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-31580 is fixed in version 1.13.1.post1+tuxcare of torch."
      },
      "affects": [
        {
          "ref": "pkg:pypi/torch@1.13.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e80d4e4a-97bf-56d0-80fc-7a3c11bf3103",
      "id": "CVE-2024-31583",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-31583 is fixed in version 1.13.1.post1+tuxcare of torch."
      },
      "affects": [
        {
          "ref": "pkg:pypi/torch@1.13.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a88d6a6-e785-52fc-abdc-f014f2ea6b82",
      "id": "CVE-2024-7804",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-7804 is a false positive for torch 1.13.1.post1+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/torch@1.13.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8658c247-7aa8-534d-8062-259cd74b9e5e",
      "id": "CVE-2025-2148",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-2148 affects version 1.13.1.post1+tuxcare of torch."
      },
      "affects": [
        {
          "ref": "pkg:pypi/torch@1.13.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4b657ea-0786-58c7-bfca-de6ea7241d59",
      "id": "CVE-2025-2149",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-2149 affects version 1.13.1.post1+tuxcare of torch."
      },
      "affects": [
        {
          "ref": "pkg:pypi/torch@1.13.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5777924-b187-5c75-9ff0-351384c90699",
      "id": "CVE-2025-2953",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-2953 affects version 1.13.1.post1+tuxcare of torch."
      },
      "affects": [
        {
          "ref": "pkg:pypi/torch@1.13.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9568217-67f6-5fc5-a1e7-78277b99d12e",
      "id": "CVE-2025-2998",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-2998 affects version 1.13.1.post1+tuxcare of torch."
      },
      "affects": [
        {
          "ref": "pkg:pypi/torch@1.13.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6a79257-d262-5dec-8534-c273f3e2df73",
      "id": "CVE-2025-2999",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-2999 affects version 1.13.1.post1+tuxcare of torch."
      },
      "affects": [
        {
          "ref": "pkg:pypi/torch@1.13.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f991b6dd-770d-59e8-8881-ef658f501597",
      "id": "CVE-2025-3000",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-3000 affects version 1.13.1.post1+tuxcare of torch."
      },
      "affects": [
        {
          "ref": "pkg:pypi/torch@1.13.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef76c818-792d-55e4-9f94-f6fcd5779675",
      "id": "CVE-2025-3001",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-3001 affects version 1.13.1.post1+tuxcare of torch."
      },
      "affects": [
        {
          "ref": "pkg:pypi/torch@1.13.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5dc4ddc5-2230-5240-83cf-93f3aba2bab4",
      "id": "CVE-2025-32434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-32434 is fixed in version 1.13.1.post1+tuxcare of torch."
      },
      "affects": [
        {
          "ref": "pkg:pypi/torch@1.13.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48d91ec7-39b0-55e3-92c0-36c0f5cdd508",
      "id": "CVE-2025-3730",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-3730 affects version 1.13.1.post1+tuxcare of torch."
      },
      "affects": [
        {
          "ref": "pkg:pypi/torch@1.13.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e26b394-2f2d-5546-8aad-bd5597fc7a23",
      "id": "CVE-2021-33503",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-33503 is fixed in version 1.25.11.post2+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27ca308f-4e43-53b7-9136-5021e2013ace",
      "id": "CVE-2023-43804",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-43804 affects version 1.25.11.post2+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e58e471f-42ff-593f-bc0e-3733015088f1",
      "id": "CVE-2023-45803",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45803 is fixed in version 1.25.11.post2+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:344b64ff-c1a9-520a-a617-5d953902930c",
      "id": "CVE-2024-37891",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-37891 affects version 1.25.11.post2+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7dd809c-54f3-5e46-bdab-22f94701d04b",
      "id": "CVE-2025-50181",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-50181 affects version 1.25.11.post2+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e755de62-931d-5eb9-b520-5d688c475cb1",
      "id": "CVE-2025-66418",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66418 affects version 1.25.11.post2+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7ed3094-4318-5669-ba6c-671008a11048",
      "id": "CVE-2025-66471",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66471 affects version 1.25.11.post2+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:421a24b1-7b85-5577-bbf4-247c12f117c8",
      "id": "CVE-2026-21441",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-21441 affects version 1.25.11.post2+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13b23e6e-3d5b-5ff2-990d-5b656fbe7f33",
      "id": "CVE-2026-44431",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44431 affects version 1.25.11.post2+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.25.11.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c3627a2-122b-5491-9868-c97aeaa9a8b9",
      "id": "CVE-2019-6446",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-6446 is fixed in version 1.15.4.post2+tuxcare of numpy."
      },
      "affects": [
        {
          "ref": "pkg:pypi/numpy@1.15.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bcd6bf5b-89c2-581e-a4d1-3c8f6e313fc7",
      "id": "CVE-2021-33430",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-33430 affects version 1.15.4.post2+tuxcare of numpy."
      },
      "affects": [
        {
          "ref": "pkg:pypi/numpy@1.15.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b07c4855-4695-5e3b-803c-e6c78da66655",
      "id": "CVE-2021-34141",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-34141 is fixed in version 1.15.4.post2+tuxcare of numpy."
      },
      "affects": [
        {
          "ref": "pkg:pypi/numpy@1.15.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51fb3761-e652-57cb-b1e5-adda9d2f4e36",
      "id": "CVE-2021-41495",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41495 affects version 1.15.4.post2+tuxcare of numpy."
      },
      "affects": [
        {
          "ref": "pkg:pypi/numpy@1.15.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9fa0332-e17e-5848-9ab6-bc976b83d4fb",
      "id": "CVE-2021-41496",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41496 affects version 1.15.4.post2+tuxcare of numpy."
      },
      "affects": [
        {
          "ref": "pkg:pypi/numpy@1.15.4.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51ad2bf4-f1a8-53ca-878c-77bc6de25978",
      "id": "CVE-2024-6345",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6345 is fixed in version 68.0.0.post1+tuxcare of setuptools."
      },
      "affects": [
        {
          "ref": "pkg:pypi/setuptools@68.0.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:224e27e0-26d9-55b3-9cbe-2596b9470b86",
      "id": "CVE-2025-47273",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-47273 is fixed in version 68.0.0.post1+tuxcare of setuptools."
      },
      "affects": [
        {
          "ref": "pkg:pypi/setuptools@68.0.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04b8e31a-17c9-5d0f-8a92-a4b197ad5f2e",
      "id": "CVE-2026-59890",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59890 affects version 68.0.0.post1+tuxcare of setuptools."
      },
      "affects": [
        {
          "ref": "pkg:pypi/setuptools@68.0.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85d8d292-368d-522b-8a22-732cdc74e2bb",
      "id": "CVE-2025-47273",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-47273 is fixed in version 75.0.0.post1+tuxcare of setuptools."
      },
      "affects": [
        {
          "ref": "pkg:pypi/setuptools@75.0.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab393add-0256-5cd2-8d54-d715846a6a2b",
      "id": "CVE-2026-59890",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59890 affects version 75.0.0.post1+tuxcare of setuptools."
      },
      "affects": [
        {
          "ref": "pkg:pypi/setuptools@75.0.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f13c0d2-715c-5d38-893a-1705572ae451",
      "id": "CVE-2025-47273",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-47273 is fixed in version 70.3.0.post1+tuxcare of setuptools."
      },
      "affects": [
        {
          "ref": "pkg:pypi/setuptools@70.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cdde9a09-3d5a-5276-b16c-b60113ad2b9f",
      "id": "CVE-2026-59890",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59890 affects version 70.3.0.post1+tuxcare of setuptools."
      },
      "affects": [
        {
          "ref": "pkg:pypi/setuptools@70.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a80f03a-5fce-5984-acd9-77ff9f430a0a",
      "id": "CVE-2023-50782",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-50782 is fixed in version 41.0.7.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@41.0.7.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6e9156b-c6a4-592d-8ce4-781809c72340",
      "id": "CVE-2024-0727",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-0727 affects version 41.0.7.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@41.0.7.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e33662f7-0062-519a-8ca6-24237633fb9e",
      "id": "CVE-2024-26130",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-26130 is fixed in version 41.0.7.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@41.0.7.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e0eb505-1d43-5496-8065-f95ed20af2c4",
      "id": "CVE-2026-26007",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-26007 affects version 41.0.7.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@41.0.7.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23c9577f-ddb8-53de-90e4-9ca6c282eb43",
      "id": "CVE-2026-34073",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34073 affects version 41.0.7.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@41.0.7.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99f004b1-6c55-5097-afbd-4d02cd07e09d",
      "id": "GHSA-537c-gmf6-5ccf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-537c-gmf6-5ccf affects version 41.0.7.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@41.0.7.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76395333-512d-5815-adac-360cf5ed6d90",
      "id": "GHSA-h4gh-qq45-vh27",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-h4gh-qq45-vh27 affects version 41.0.7.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@41.0.7.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70ba38ac-2c8b-594b-a824-7b9cdecd4ee7",
      "id": "CVE-2025-55197",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55197 is fixed in version 5.9.0.post1+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92516b9a-85c7-559e-9408-bda48b286c6b",
      "id": "CVE-2025-62707",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-62707 affects version 5.9.0.post1+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f413c160-6991-5cfd-9f07-f5e4ece6ec6a",
      "id": "CVE-2025-62708",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-62708 affects version 5.9.0.post1+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36e5e54f-334e-5051-bc20-59a3c52f09c5",
      "id": "CVE-2025-66019",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66019 affects version 5.9.0.post1+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ab99c16-2293-5498-98c3-d9fa4d23fd08",
      "id": "CVE-2026-22690",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22690 affects version 5.9.0.post1+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:088228e4-40e8-58db-aa24-12ae5f33be29",
      "id": "CVE-2026-22691",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22691 affects version 5.9.0.post1+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c1a9104-992c-590e-8832-bc661fa019c7",
      "id": "CVE-2026-24688",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24688 affects version 5.9.0.post1+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b08b7257-508c-514e-bc79-fc211cee99e1",
      "id": "CVE-2026-27024",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27024 affects version 5.9.0.post1+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbbd1740-3e70-5c7e-976b-6f1b5b4a3d5d",
      "id": "CVE-2026-27025",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27025 affects version 5.9.0.post1+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5d8a9c8-3a65-5a3d-8e05-aa011030eef4",
      "id": "CVE-2026-27026",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27026 affects version 5.9.0.post1+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:caa8e353-585c-5a6b-8fb9-12465877ac8d",
      "id": "CVE-2026-27628",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27628 affects version 5.9.0.post1+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01b09fe0-5e84-5a2a-8c57-ffd019e097db",
      "id": "CVE-2026-27888",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27888 affects version 5.9.0.post1+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f025382-2cb9-5a7d-b9f4-01817e5ba092",
      "id": "CVE-2026-28351",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-28351 affects version 5.9.0.post1+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6cd2d13d-c80b-5752-94ac-244b6f0bc023",
      "id": "CVE-2026-28804",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-28804 affects version 5.9.0.post1+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0ceae4f-f5ff-5c32-9a9f-93b79715af24",
      "id": "CVE-2026-31826",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-31826 affects version 5.9.0.post1+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc83c065-78bf-5f72-9116-2083e3078ee7",
      "id": "CVE-2026-33123",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33123 affects version 5.9.0.post1+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fda20db4-046a-5a09-a630-292d9f0fdf6a",
      "id": "CVE-2026-33699",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33699 affects version 5.9.0.post1+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:167b145c-e8fe-56ec-a992-4065cda04dda",
      "id": "CVE-2026-40260",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40260 affects version 5.9.0.post1+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b8f55b4-c620-5da8-9fec-df8c3f69eb19",
      "id": "CVE-2026-41168",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41168 affects version 5.9.0.post1+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30bbfd22-0fef-5d07-9c5b-5d1ed7fdb744",
      "id": "CVE-2026-41312",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41312 affects version 5.9.0.post1+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:789d7daf-6c5e-528a-9bea-2aa21b77f13e",
      "id": "CVE-2026-41313",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41313 affects version 5.9.0.post1+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29a5a738-e6ec-510c-91f6-f427b8cee723",
      "id": "CVE-2026-41314",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41314 affects version 5.9.0.post1+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a76856e2-15d1-51cd-9fa3-16c6f063cd96",
      "id": "CVE-2026-48155",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48155 affects version 5.9.0.post1+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:540fafe1-a42b-52a3-ae07-c76b578d215d",
      "id": "CVE-2026-48156",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48156 affects version 5.9.0.post1+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:345da088-c4ad-5fbb-9524-fb6e2439a7f3",
      "id": "CVE-2026-48735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48735 affects version 5.9.0.post1+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd0a964f-c832-5ba7-987c-1cc348542a0c",
      "id": "CVE-2026-49460",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49460 affects version 5.9.0.post1+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4974d21-0dba-5a01-bb18-606903d0762f",
      "id": "CVE-2026-49461",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-49461 affects version 5.9.0.post1+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d22c982-89ed-5d9a-8274-781896656b36",
      "id": "CVE-2026-54530",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54530 affects version 5.9.0.post1+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96df2b83-6ebb-5b79-8d66-5104c80312ae",
      "id": "CVE-2026-54531",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54531 affects version 5.9.0.post1+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93078f42-553b-593c-9769-3f15bc81cd3e",
      "id": "CVE-2026-54651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54651 affects version 5.9.0.post1+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4458d29c-2885-595a-919c-51c51c67cc73",
      "id": "CVE-2026-59935",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59935 affects version 5.9.0.post1+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b93c1add-c6d7-5028-bc52-e0b3dc5b939d",
      "id": "CVE-2026-59936",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59936 affects version 5.9.0.post1+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d5eee1d-7321-5db1-8d61-123c3f89df97",
      "id": "CVE-2026-59937",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59937 affects version 5.9.0.post1+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:505db3d8-4aaf-5da7-90c0-36f1b1d5e7d1",
      "id": "CVE-2026-59938",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59938 affects version 5.9.0.post1+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1404a64-fe80-5f7a-8e77-e3eda568d6f4",
      "id": "GHSA-4pxv-j86v-mhcw",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-4pxv-j86v-mhcw affects version 5.9.0.post1+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:950bd9c5-d934-5bd7-886b-267fb0b62cce",
      "id": "GHSA-7gw9-cf7v-778f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-7gw9-cf7v-778f affects version 5.9.0.post1+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f3766e5-5acc-574b-be89-0f2ee0e0155f",
      "id": "GHSA-9m86-7pmv-2852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-9m86-7pmv-2852 affects version 5.9.0.post1+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c3842a0-27f3-585b-a9cc-576a833c2b93",
      "id": "GHSA-jj6c-8h6c-hppx",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-jj6c-8h6c-hppx affects version 5.9.0.post1+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be826ca6-5e14-5a5f-bc77-2d7aa5ec070d",
      "id": "GHSA-jm82-fx9c-mx94",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-jm82-fx9c-mx94 affects version 5.9.0.post1+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:679cbfd9-b996-5c10-b983-2dee15a16733",
      "id": "GHSA-x284-j5p8-9c5p",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-x284-j5p8-9c5p affects version 5.9.0.post1+tuxcare of pypdf."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa1d0038-3ee4-5ef1-8b43-f16e8cf0d339",
      "id": "CVE-2024-45231",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-45231 affects version 3.2.25.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@3.2.25.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23dc0f2d-31c9-560e-a76a-8b1f6298c774",
      "id": "CVE-2025-48432",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48432 affects version 3.2.25.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@3.2.25.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95731fd0-7dfc-554f-b48c-d1a1a941ecac",
      "id": "CVE-2025-57833",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-57833 is fixed in version 3.2.25.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@3.2.25.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15d9f3fe-7b71-5fe1-84de-3754610710cb",
      "id": "CVE-2025-64458",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64458 affects version 3.2.25.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@3.2.25.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:936a4544-0da6-5b19-8dc4-78b1a6239451",
      "id": "CVE-2025-64459",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64459 affects version 3.2.25.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@3.2.25.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9937d611-0a13-5bec-97dd-61205cab66a5",
      "id": "CVE-2024-6839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6839 affects version 4.0.2.post1+tuxcare of flask-cors."
      },
      "affects": [
        {
          "ref": "pkg:pypi/flask-cors@4.0.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6fc84f99-4fcf-53b6-9b04-79ee5d57d939",
      "id": "CVE-2024-6844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-6844 affects version 4.0.2.post1+tuxcare of flask-cors."
      },
      "affects": [
        {
          "ref": "pkg:pypi/flask-cors@4.0.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0a71921-9a8e-512f-ac20-d51603faf8f8",
      "id": "CVE-2024-6866",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6866 is fixed in version 4.0.2.post1+tuxcare of flask-cors."
      },
      "affects": [
        {
          "ref": "pkg:pypi/flask-cors@4.0.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3389a14-2e7d-507b-b9a5-4ac49cbaccf3",
      "id": "CVE-2025-50181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-50181 is fixed in version 1.26.20.post1+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.20.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69dae324-16c5-5fc1-a0f1-20038427db15",
      "id": "CVE-2025-66418",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66418 affects version 1.26.20.post1+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.20.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9eeaa331-d4bc-5ecb-9772-b8fdfd312ecb",
      "id": "CVE-2025-66471",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66471 affects version 1.26.20.post1+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.20.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2b4fdd2-37c3-5487-a1ae-8668e86b0756",
      "id": "CVE-2026-21441",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-21441 affects version 1.26.20.post1+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.20.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc812521-8d15-5dde-abed-55b140d4f99a",
      "id": "CVE-2026-44431",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44431 affects version 1.26.20.post1+tuxcare of urllib3."
      },
      "affects": [
        {
          "ref": "pkg:pypi/urllib3@1.26.20.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1dade9cc-ae37-5d35-9c58-885a1c362c0e",
      "id": "CVE-2024-24680",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-24680 is fixed in version 5.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab16aa01-91bf-5d26-90e8-09bba0a36de0",
      "id": "CVE-2024-27351",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27351 affects version 5.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59f734bb-d99a-572c-91f3-da2f4fbb03c3",
      "id": "CVE-2024-38875",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38875 is fixed in version 5.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfaa697a-1ab4-5157-9c13-5a89ab8b02df",
      "id": "CVE-2024-39329",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-39329 affects version 5.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ced7830-1ad2-555f-9a5a-fbf3e662160b",
      "id": "CVE-2024-39330",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-39330 is fixed in version 5.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3dcb0859-4030-5888-8bd9-6047606da832",
      "id": "CVE-2024-39614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-39614 is fixed in version 5.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56d2de25-65c8-50d7-ac0d-51d4aeb8d3f3",
      "id": "CVE-2024-41989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-41989 affects version 5.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5da8626-1319-5533-b575-612b84a7e357",
      "id": "CVE-2024-41990",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-41990 is fixed in version 5.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd12e8f9-c893-569f-a475-85ccef7ebcd5",
      "id": "CVE-2024-41991",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-41991 affects version 5.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36b5ff7e-585a-5800-9866-84216cf95360",
      "id": "CVE-2024-42005",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-42005 is fixed in version 5.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f15964e-7d6e-5206-9c2e-299fb6fa959c",
      "id": "CVE-2024-45230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-45230 affects version 5.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0105aa78-87a2-5ce6-bc34-2cea5c9c94eb",
      "id": "CVE-2024-45231",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-45231 affects version 5.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a42d702a-4829-51e2-bae7-b3ca26164103",
      "id": "CVE-2024-53907",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-53907 affects version 5.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66d20119-10c4-5d8c-80fc-f2c709165357",
      "id": "CVE-2024-53908",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-53908 affects version 5.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e2e43d5-dc5f-577b-87cf-5d802fd1e545",
      "id": "CVE-2024-56374",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56374 affects version 5.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0d32c3f-aa38-5f93-9772-a00dc64f2218",
      "id": "CVE-2025-13372",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13372 affects version 5.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b348be84-4f68-56a2-91e7-d71164e55685",
      "id": "CVE-2025-13473",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13473 affects version 5.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d93291a-8f82-5db1-a088-640514b94d80",
      "id": "CVE-2025-14550",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-14550 affects version 5.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ced16112-bdd2-5f3d-b8a2-515fcdfbf079",
      "id": "CVE-2025-26699",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-26699 affects version 5.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9671a3a5-1454-5aa9-bac7-1111d39bd33f",
      "id": "CVE-2025-27556",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27556 affects version 5.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45821a95-9a5c-5d03-98db-0171abc67ffe",
      "id": "CVE-2025-48432",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48432 affects version 5.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0a22a1a-7997-5946-9b0c-b197cece60a7",
      "id": "CVE-2025-57833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57833 affects version 5.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3150bf7e-1eab-5dc9-8558-ddebd3da69bc",
      "id": "CVE-2025-64458",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64458 affects version 5.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4c08cb8-bd09-5044-82a8-2c9c1072b2aa",
      "id": "CVE-2025-64459",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64459 affects version 5.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1021bc77-53a4-5ca5-aeef-1406f9ad697d",
      "id": "CVE-2025-64460",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64460 affects version 5.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e5532a5-c361-59f2-9ab9-d2d9c59b2842",
      "id": "CVE-2026-1207",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1207 affects version 5.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63cf8fb6-563e-530e-9145-d70d57e5f6b2",
      "id": "CVE-2026-1285",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1285 affects version 5.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89bf9a1b-697b-5146-a42e-8a2ac643f503",
      "id": "CVE-2026-1287",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1287 affects version 5.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:067f600c-ebe7-56cf-aff7-64d6c33572c7",
      "id": "CVE-2026-1312",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1312 affects version 5.0.post5+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3bc3e570-982c-5c63-bf43-44aaff29d83f",
      "id": "CVE-2024-0727",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-0727 affects version 42.0.0.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@42.0.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7d662aa-6193-54f8-a625-a05b81628df8",
      "id": "CVE-2024-12797",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-12797 is fixed in version 42.0.0.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@42.0.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03be594b-e0ac-56c0-ada8-f97a36fccaf2",
      "id": "CVE-2024-26130",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-26130 is fixed in version 42.0.0.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@42.0.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ecf4ad14-059b-5f9f-a841-c3813b9ed47e",
      "id": "CVE-2026-26007",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-26007 affects version 42.0.0.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@42.0.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c09641f-faf7-5b6d-99d4-a6e1f2a7b7c2",
      "id": "CVE-2026-34073",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34073 affects version 42.0.0.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@42.0.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f453673-bb14-59a8-81fc-2d594d0bd979",
      "id": "GHSA-537c-gmf6-5ccf",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-537c-gmf6-5ccf does not affect version 42.0.0.post1+tuxcare of cryptography. not_affected \u2014 The target repository (cryptography 42.0.0.post1+tuxcare source code) is not affected by GHSA-537c-gmf6-5ccf. This CVE concerns vulnerable OpenSSL bundled in pre-built PyPI wheels, not the cryptography source code itself. The CVE explicitly excludes source builds from its scope, stating that sdist users are responsible for their own OpenSSL. The target is a source repository with no vendored Op..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@42.0.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e29b62c-a31e-5f34-82b1-304b2d4ae0c1",
      "id": "GHSA-h4gh-qq45-vh27",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-h4gh-qq45-vh27 affects version 42.0.0.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@42.0.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b58fa07a-c826-5e88-abae-e2b33457f33e",
      "id": "CVE-2023-40267",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-40267 affects version 3.1.31.post1+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32efcfa8-56e4-5146-bc92-fb2e328d741f",
      "id": "CVE-2023-40590",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-40590 is fixed in version 3.1.31.post1+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90b6eadf-caa4-5d3b-af62-176b61fff71b",
      "id": "CVE-2023-41040",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41040 is fixed in version 3.1.31.post1+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d4bdf04-c11c-5703-b1bc-4b589e2c862e",
      "id": "CVE-2024-22190",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22190 is fixed in version 3.1.31.post1+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eaa44bcb-91f0-5bd3-9af4-bb80b0259ffe",
      "id": "CVE-2026-42215",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42215 affects version 3.1.31.post1+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c7648b4-4aa3-5753-8203-7b8624026be2",
      "id": "CVE-2026-42284",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42284 affects version 3.1.31.post1+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0701af79-327e-53f6-98e0-b5c880b5d68a",
      "id": "CVE-2026-44243",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44243 affects version 3.1.31.post1+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16a423f6-0a8d-52df-a2ee-c79efea4bdc6",
      "id": "CVE-2026-44244",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44244 affects version 3.1.31.post1+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8bea52e-2990-561d-a81b-0e57b87f572e",
      "id": "GHSA-2f96-g7mh-g2hx",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-2f96-g7mh-g2hx affects version 3.1.31.post1+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08cf58de-fd22-5b5b-ae58-cb211d9d9e6a",
      "id": "GHSA-3rp5-jjmw-4wv2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-3rp5-jjmw-4wv2 affects version 3.1.31.post1+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab522360-5851-5fe8-82d3-06e76875402b",
      "id": "GHSA-6p8h-3wgx-97gf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-6p8h-3wgx-97gf affects version 3.1.31.post1+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ae45e5c-5fe3-597c-a00c-b1767305e314",
      "id": "GHSA-94p4-4cq8-9g67",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-94p4-4cq8-9g67 affects version 3.1.31.post1+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dabe37fe-1eaa-5ae7-b97d-2d81e910b74d",
      "id": "GHSA-956x-8gvw-wg5v",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-956x-8gvw-wg5v affects version 3.1.31.post1+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3388b21-adbd-5a01-a691-cac5b8b3338d",
      "id": "GHSA-fjr4-x663-mwxc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-fjr4-x663-mwxc affects version 3.1.31.post1+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e43f3d1-9e48-5155-aa7c-d885d1809710",
      "id": "GHSA-mv93-w799-cj2w",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-mv93-w799-cj2w affects version 3.1.31.post1+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:daf98135-2b2c-54dc-9053-1aa2af2b26fe",
      "id": "GHSA-r9mr-m37c-5fr3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-r9mr-m37c-5fr3 affects version 3.1.31.post1+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66a569e6-18ec-57e2-98e5-75047f5c4efb",
      "id": "GHSA-rwj8-pgh3-r573",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-rwj8-pgh3-r573 affects version 3.1.31.post1+tuxcare of gitpython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5201cca2-9fc6-54f1-92fb-624e06414ac9",
      "id": "CVE-2024-29370",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2024-29370 is a false positive for python-jose 3.3.0.post1+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-jose@3.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:416adbb1-5160-5df9-9104-d6043257076b",
      "id": "CVE-2024-33663",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-33663 affects version 3.3.0.post1+tuxcare of python-jose."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-jose@3.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a47c39e-c233-5b49-82e3-eadfd602cdef",
      "id": "CVE-2024-33664",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-33664 is fixed in version 3.3.0.post1+tuxcare of python-jose."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-jose@3.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6b6ec57-a498-59a2-9e25-15b1a0433ff6",
      "id": "CVE-2023-47627",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-47627 is fixed in version 3.8.5.post1+tuxcare of orjson."
      },
      "affects": [
        {
          "ref": "pkg:pypi/orjson@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6903863b-0825-5eca-9722-145e65461e33",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49082 is fixed in version 3.8.5.post1+tuxcare of orjson."
      },
      "affects": [
        {
          "ref": "pkg:pypi/orjson@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1831ebef-9a05-5e06-99e0-4d5c87f37e0e",
      "id": "CVE-2024-27454",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-27454 is fixed in version 3.8.5.post1+tuxcare of orjson."
      },
      "affects": [
        {
          "ref": "pkg:pypi/orjson@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:558e2488-fb34-53ad-816d-38736d3f3d7b",
      "id": "CVE-2025-67221",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-67221 affects version 3.8.5.post1+tuxcare of orjson."
      },
      "affects": [
        {
          "ref": "pkg:pypi/orjson@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a721e2d-a40d-55b2-b985-c7c140c43697",
      "id": "CVE-2023-28858",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28858 is fixed in version 4.5.1.post1+tuxcare of redis."
      },
      "affects": [
        {
          "ref": "pkg:pypi/redis@4.5.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d4c7b12-a011-59f6-82fe-1705cc4450d8",
      "id": "CVE-2023-28859",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28859 is fixed in version 4.5.1.post1+tuxcare of redis."
      },
      "affects": [
        {
          "ref": "pkg:pypi/redis@4.5.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afa90a59-dcc6-5943-b5e9-03f2c61183b1",
      "id": "CVE-2024-3651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-3651 is fixed in version 3.6.post1+tuxcare of idna."
      },
      "affects": [
        {
          "ref": "pkg:pypi/idna@3.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87760c4e-802c-5a5d-8584-fc96fdbb378b",
      "id": "CVE-2026-45409",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45409 affects version 3.6.post1+tuxcare of idna."
      },
      "affects": [
        {
          "ref": "pkg:pypi/idna@3.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d753a27f-81a4-532d-81ea-1a9d8cbdeb0f",
      "id": "CVE-2024-34062",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34062 is fixed in version 4.66.1.post1+tuxcare of tqdm."
      },
      "affects": [
        {
          "ref": "pkg:pypi/tqdm@4.66.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:771b8036-73ed-5b00-ba41-1261518e99f9",
      "id": "CVE-2024-24762",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-24762 is fixed in version 0.0.6.post1+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2761cd8f-9fe5-5e94-bdf4-9647c52a8c61",
      "id": "CVE-2024-53981",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-53981 affects version 0.0.6.post1+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:474fd946-6f03-5b1e-b78e-6800f46c9fc6",
      "id": "CVE-2026-24486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24486 affects version 0.0.6.post1+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee73ffaa-c8a8-583f-94c7-b2c6dbb00b33",
      "id": "CVE-2026-40347",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40347 affects version 0.0.6.post1+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ffa40ecd-e121-5ed3-9b35-31c7dcbb806e",
      "id": "CVE-2026-42561",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42561 affects version 0.0.6.post1+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b5f50e8-9648-53f3-bb72-834743abfc18",
      "id": "CVE-2026-53537",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53537 affects version 0.0.6.post1+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e612ed6f-ceae-55e4-8bed-b8ca77e8f46e",
      "id": "CVE-2026-53538",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53538 affects version 0.0.6.post1+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e886bf29-7e3a-5203-bd0e-ce08a2d758d6",
      "id": "CVE-2026-53539",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53539 affects version 0.0.6.post1+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6124824f-a713-55f8-8134-78dbd6f746ce",
      "id": "CVE-2026-53540",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-53540 affects version 0.0.6.post1+tuxcare of python-multipart."
      },
      "affects": [
        {
          "ref": "pkg:pypi/python-multipart@0.0.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:721f7686-d836-5b0d-94a7-d910aeacc461",
      "id": "CVE-2023-48795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-48795 is fixed in version 3.0.0.post1+tuxcare of paramiko."
      },
      "affects": [
        {
          "ref": "pkg:pypi/paramiko@3.0.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0782d51b-5b6d-5783-97a0-baf24ea51db9",
      "id": "CVE-2026-44405",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-44405 affects version 3.0.0.post1+tuxcare of paramiko."
      },
      "affects": [
        {
          "ref": "pkg:pypi/paramiko@3.0.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c7f70e6-53fe-5dc9-b75b-9c3155340553",
      "id": "SNYK-PYTHON-PIEXIF-2312874",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability SNYK-PYTHON-PIEXIF-2312874 is fixed in version 1.1.3.post1+tuxcare of piexif."
      },
      "affects": [
        {
          "ref": "pkg:pypi/piexif@1.1.3.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:196ce2a4-93d0-52b1-9e8a-482c230f93d6",
      "id": "CVE-2025-58367",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-58367 is fixed in version 6.2.3.post1+tuxcare of deepdiff."
      },
      "affects": [
        {
          "ref": "pkg:pypi/deepdiff@6.2.3.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f19424c3-e900-5dee-8a41-ea3a6423ef05",
      "id": "CVE-2026-33155",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33155 affects version 6.2.3.post1+tuxcare of deepdiff."
      },
      "affects": [
        {
          "ref": "pkg:pypi/deepdiff@6.2.3.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae44aa24-b4f8-57b1-b461-5b250894a2a2",
      "id": "CVE-2024-3772",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-3772 is fixed in version v1.10.5.post1+tuxcare of pydantic."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pydantic@v1.10.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92fe2d2e-110e-5c75-8be2-14615fb0146b",
      "id": "CVE-2021-45115",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-45115 is fixed in version 4.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb3ca328-8c66-5252-9ad7-eb8403ae66c8",
      "id": "CVE-2021-45116",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-45116 is fixed in version 4.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd5cba00-0732-536b-a240-2bfa15ccbc3d",
      "id": "CVE-2021-45452",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-45452 is fixed in version 4.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed87c37c-c96b-556c-a56d-b22022b169c1",
      "id": "CVE-2022-22818",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22818 affects version 4.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae82f08f-5b85-5066-994b-3f5a3287a6ab",
      "id": "CVE-2022-23833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-23833 affects version 4.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c97961d7-1444-5af9-88e1-3a5e7f819c67",
      "id": "CVE-2022-28346",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-28346 is fixed in version 4.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:586d7e39-5e03-5db3-a383-e32c507e38a6",
      "id": "CVE-2022-28347",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-28347 is fixed in version 4.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0ab541a-597c-5385-ad9b-190c90c6ca2e",
      "id": "CVE-2022-34265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-34265 is fixed in version 4.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14bbf2a7-ceaa-5c91-a637-1f572d36c6ca",
      "id": "CVE-2022-36359",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-36359 is fixed in version 4.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b4de28d-19a4-5cf1-a6de-4042f75eaad6",
      "id": "CVE-2022-41323",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41323 is fixed in version 4.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:650cd73c-620d-59bd-870a-ae6742ed9d8e",
      "id": "CVE-2023-23969",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-23969 is fixed in version 4.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f589f61-9094-5bdd-b7ac-85cda716825f",
      "id": "CVE-2023-24580",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-24580 is fixed in version 4.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d8d2a53-e953-5ea8-9820-63db1f160748",
      "id": "CVE-2023-31047",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-31047 affects version 4.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d7b653c-f449-550d-a824-1173374101c8",
      "id": "CVE-2023-36053",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36053 affects version 4.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f531f8de-cab4-52ca-87e0-f4f4fbbce984",
      "id": "CVE-2023-43665",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-43665 affects version 4.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5990932b-6715-5d79-9ae4-7d8b0ed336f7",
      "id": "CVE-2023-46695",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46695 affects version 4.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d797745-a8fe-59d1-b6ba-d3bcdf785f37",
      "id": "CVE-2024-45231",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-45231 affects version 4.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:164e271c-f91e-5dca-ace9-21acb4cfe9f8",
      "id": "CVE-2025-13372",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13372 affects version 4.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b53d1d7-7331-5ec0-b1eb-7883b420b4db",
      "id": "CVE-2025-13473",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13473 affects version 4.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50086ff4-457b-5732-91da-3c0f1c3b86fe",
      "id": "CVE-2025-14550",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-14550 affects version 4.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d79cff71-7de9-5552-8681-6fa109b5e60c",
      "id": "CVE-2025-48432",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48432 affects version 4.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da1c9fa0-129b-5229-8d76-e9e59048e6c8",
      "id": "CVE-2025-57833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57833 affects version 4.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6be20e90-e4cf-5d1c-8e95-9239f566223c",
      "id": "CVE-2025-64458",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64458 affects version 4.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91e7ad79-f2d1-5289-a0cc-091271778887",
      "id": "CVE-2025-64459",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64459 affects version 4.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb2305c6-46ae-5772-a9ea-f30103a10dd4",
      "id": "CVE-2025-64460",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64460 affects version 4.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88dfbe04-7359-58ac-9ee2-a7f60234bb31",
      "id": "CVE-2026-1207",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1207 affects version 4.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6194d74b-7c5d-5cf6-a83d-a8107cc8aadf",
      "id": "CVE-2026-1285",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1285 affects version 4.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2955ccb1-b9c8-5f6e-9cce-c9aa44fa3e15",
      "id": "CVE-2026-1287",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1287 affects version 4.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c953caa9-6e15-58f5-b0a6-8fa712f5854c",
      "id": "CVE-2026-1312",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1312 affects version 4.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76dbb17b-3397-5f60-a29e-22d6573a2581",
      "id": "CVE-2022-29217",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29217 is fixed in version 2.3.0.post1+tuxcare of dnspython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/dnspython@2.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd49e2b9-85e1-5427-abdd-1b4ded920ad3",
      "id": "CVE-2023-29483",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-29483 is fixed in version 2.3.0.post1+tuxcare of dnspython."
      },
      "affects": [
        {
          "ref": "pkg:pypi/dnspython@2.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6bcf4d11-b10f-59e8-b86c-81ff3ec94c1d",
      "id": "CVE-2024-24680",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-24680 is fixed in version 5.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d20c19c4-6e48-5698-8ee3-03c867e4db62",
      "id": "CVE-2024-27351",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27351 affects version 5.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17e6ff2d-a998-544f-a456-1bad65abdaac",
      "id": "CVE-2024-38875",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38875 is fixed in version 5.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3efae7e-7fb8-55ff-99e3-85fe5d864ff8",
      "id": "CVE-2024-39329",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-39329 affects version 5.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4e5481a-d304-56f5-ab99-8b434fd50ebf",
      "id": "CVE-2024-39330",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-39330 is fixed in version 5.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa121924-f976-5eea-b140-a1e53100ab1e",
      "id": "CVE-2024-39614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-39614 is fixed in version 5.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab590678-0db3-5752-bf3f-908ee01506d0",
      "id": "CVE-2024-41989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-41989 affects version 5.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c53db13b-210e-5126-ad76-a06ab6e66d66",
      "id": "CVE-2024-41990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-41990 affects version 5.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7c25025-0fca-527e-978e-3c936b6627a8",
      "id": "CVE-2024-41991",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-41991 affects version 5.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f4dc8b0-9882-5041-b0a5-1eddbdacef9d",
      "id": "CVE-2024-42005",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-42005 affects version 5.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d62668c-5e27-5c00-9d20-6b928e9e462e",
      "id": "CVE-2024-45230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-45230 affects version 5.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:255e585b-7971-5346-ae55-7ddb774641fe",
      "id": "CVE-2024-45231",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-45231 affects version 5.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39168829-a658-5223-87ac-62cb856038db",
      "id": "CVE-2024-53907",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-53907 affects version 5.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00e69f14-2cf5-5b72-b7b5-2f43e67f3af2",
      "id": "CVE-2024-53908",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-53908 affects version 5.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95dfcb6a-ff0d-5da2-ad46-55db8ad7306d",
      "id": "CVE-2024-56374",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56374 affects version 5.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fabccf40-7b8b-58ab-8a88-e56b548492e9",
      "id": "CVE-2025-13372",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13372 affects version 5.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8ab7be7-f76e-55e7-a3de-845bb7a4a2a1",
      "id": "CVE-2025-13473",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13473 affects version 5.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ce230cf-9699-57d5-8249-c3ca97dd081b",
      "id": "CVE-2025-14550",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-14550 affects version 5.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcdef5cd-a920-542a-b518-3c57d655fe85",
      "id": "CVE-2025-26699",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-26699 affects version 5.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6ec3dda-0f00-5e47-8c8b-c47ca25d344e",
      "id": "CVE-2025-27556",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27556 affects version 5.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07a5cf81-3dfc-5640-800d-ecd528feadaf",
      "id": "CVE-2025-48432",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48432 affects version 5.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea6c7eda-be3f-5c47-adb6-bc3c3118674b",
      "id": "CVE-2025-57833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57833 affects version 5.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:654152af-e686-5460-a08a-6891bb5b803b",
      "id": "CVE-2025-64458",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64458 affects version 5.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e66bc466-df8d-5565-b872-a3caf66850ee",
      "id": "CVE-2025-64459",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64459 affects version 5.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:996529a2-0f4e-5eb3-bc00-f7b2516d12ca",
      "id": "CVE-2025-64460",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64460 affects version 5.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9fe303b-f961-5fa0-80ce-7b8e4c257906",
      "id": "CVE-2026-1207",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1207 affects version 5.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c53ed3ee-4b31-5622-9b1a-28592a0a6b6d",
      "id": "CVE-2026-1285",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1285 affects version 5.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f4d8e0f-70f1-58ce-8c2a-1a8f91772e49",
      "id": "CVE-2026-1287",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1287 affects version 5.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a493a11-76e4-5ea8-8176-3f6205b9a3c7",
      "id": "CVE-2026-1312",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1312 affects version 5.0.post4+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post4+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3c54e01-4045-5f3d-ade9-a0a1251f2310",
      "id": "CVE-2024-24680",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-24680 is fixed in version 5.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:936ebe31-5081-555f-bf55-2f4f7521da74",
      "id": "CVE-2024-27351",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27351 affects version 5.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fecb5f4-0159-5d71-b754-354509e39fd1",
      "id": "CVE-2024-38875",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38875 is fixed in version 5.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6c2358e-fc65-53a7-a3fe-e5605a4466ea",
      "id": "CVE-2024-39329",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-39329 affects version 5.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79ef016c-4ee0-56c0-a676-1cdb565a4286",
      "id": "CVE-2024-39330",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-39330 affects version 5.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36a086e1-2762-53bd-be72-914ecb664f0a",
      "id": "CVE-2024-39614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-39614 is fixed in version 5.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e75d5036-90bc-50a9-9b2a-2b4665235f86",
      "id": "CVE-2024-41989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-41989 affects version 5.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abefa817-a1f2-531d-b0ae-f64c7d44570e",
      "id": "CVE-2024-41990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-41990 affects version 5.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37256618-979c-5bdd-80bd-cbf93ad83128",
      "id": "CVE-2024-41991",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-41991 affects version 5.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8f3ef8f-6cbb-5263-8ba4-b2a9a2626c9b",
      "id": "CVE-2024-42005",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-42005 affects version 5.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f3abaf6-fb2d-5853-9cbe-8fdc7b544102",
      "id": "CVE-2024-45230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-45230 affects version 5.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efa5bbce-242c-58c4-8096-3c9928d2bb9d",
      "id": "CVE-2024-45231",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-45231 affects version 5.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a8068a5-39dd-51a4-be2b-40835935a65c",
      "id": "CVE-2024-53907",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-53907 affects version 5.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5037d6b-baa9-5981-a22f-5016f9e332fe",
      "id": "CVE-2024-53908",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-53908 affects version 5.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c6374b4-d2b6-5e8e-9069-3c28a53da3f2",
      "id": "CVE-2024-56374",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56374 affects version 5.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c0b00a6-c612-5fdb-b25a-feeabd7a8337",
      "id": "CVE-2025-13372",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13372 affects version 5.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45cc4afd-d433-50bc-8dc1-b122a9280b42",
      "id": "CVE-2025-13473",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13473 affects version 5.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5845ae31-603d-567c-995f-7305c54b655b",
      "id": "CVE-2025-14550",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-14550 affects version 5.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:454618e1-3e27-5cc2-a080-d9027bee6276",
      "id": "CVE-2025-26699",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-26699 affects version 5.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b44a3530-6bcb-5ff8-baae-8d205461eac9",
      "id": "CVE-2025-27556",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27556 affects version 5.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46fea74a-6e50-5ae6-b839-3d2f44287d14",
      "id": "CVE-2025-48432",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48432 affects version 5.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7bd926e-2b54-5edd-9c90-61b36d0fd133",
      "id": "CVE-2025-57833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57833 affects version 5.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d9afd0e-7f9f-5684-a36e-55fd54d3af72",
      "id": "CVE-2025-64458",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64458 affects version 5.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fd6f578-762c-57f2-882e-f406d15d4a27",
      "id": "CVE-2025-64459",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64459 affects version 5.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2008a026-53cf-58d1-a966-eda4aa138eaa",
      "id": "CVE-2025-64460",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64460 affects version 5.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:459e75ec-b26b-50d2-a92b-bfdd3469a777",
      "id": "CVE-2026-1207",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1207 affects version 5.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d503d961-536a-52c2-ac9a-9ca205d643e4",
      "id": "CVE-2026-1285",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1285 affects version 5.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:955076e2-87af-5cab-bf5e-e13954871f6c",
      "id": "CVE-2026-1287",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1287 affects version 5.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:772a3b21-5f17-5dae-8cce-58771b0b5e78",
      "id": "CVE-2026-1312",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1312 affects version 5.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:379e22df-1de6-563b-a570-a3b497f4be5e",
      "id": "CVE-2024-24680",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-24680 is fixed in version 5.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3819dd69-5461-581a-950c-49642f5832e3",
      "id": "CVE-2024-27351",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27351 affects version 5.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75ab30d0-783d-57e5-98cb-e6d7deefcdf3",
      "id": "CVE-2024-38875",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38875 affects version 5.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83a3475e-801c-5e47-97fb-c2aea082fbf1",
      "id": "CVE-2024-39329",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-39329 affects version 5.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c3f2850-9f35-57fd-a7ea-ebc4a1404ff4",
      "id": "CVE-2024-39330",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-39330 affects version 5.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:391ee506-b6e1-5830-9ef5-9da192d51e57",
      "id": "CVE-2024-39614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-39614 is fixed in version 5.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f21a19c5-4193-5d0c-80b4-fb7b1df78fe8",
      "id": "CVE-2024-41989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-41989 affects version 5.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b12ac0dd-43e1-59ad-ac82-0963ad15da6d",
      "id": "CVE-2024-41990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-41990 affects version 5.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3dff8cb8-2f0c-5331-8fe5-5666a9a2f05d",
      "id": "CVE-2024-41991",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-41991 affects version 5.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56fb615d-9ac1-5401-b52c-62d379c7198f",
      "id": "CVE-2024-42005",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-42005 affects version 5.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54009b81-8dab-5ae6-98f2-d3e2a3862279",
      "id": "CVE-2024-45230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-45230 affects version 5.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6336c57-4896-5207-8bdb-3916682ab0ab",
      "id": "CVE-2024-45231",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-45231 affects version 5.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6d8ce31-cd8d-566e-a2e3-44ebeeb1fc7c",
      "id": "CVE-2024-53907",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-53907 affects version 5.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04a2a32d-a98a-5665-b8dd-2ec95ecafdf4",
      "id": "CVE-2024-53908",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-53908 affects version 5.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55a9cd84-8826-501a-90de-013fbbf3ca81",
      "id": "CVE-2024-56374",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56374 affects version 5.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ddb721b6-1bc3-5cde-9c55-c67167cd088a",
      "id": "CVE-2025-13372",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13372 affects version 5.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c9786f8-5b3a-578a-a08e-74f8d6951cd6",
      "id": "CVE-2025-13473",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13473 affects version 5.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2d9a761-6b66-593d-b9e2-331f3aef8ae3",
      "id": "CVE-2025-14550",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-14550 affects version 5.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad11f9e4-571b-5313-811c-4d13159e94c0",
      "id": "CVE-2025-26699",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-26699 affects version 5.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05dd1d01-f932-5f68-9a7d-c1092e8106e1",
      "id": "CVE-2025-27556",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27556 affects version 5.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ffc8404c-5567-5e68-8b7f-b6350a64533b",
      "id": "CVE-2025-48432",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48432 affects version 5.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a48d357-cc3d-5001-b72b-3cafda4cbb01",
      "id": "CVE-2025-57833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57833 affects version 5.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7763d270-289a-533f-ae5f-486a2ccc4305",
      "id": "CVE-2025-64458",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64458 affects version 5.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f409515a-24ee-50ce-9e58-e56c5a6c8130",
      "id": "CVE-2025-64459",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64459 affects version 5.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd528a4c-1744-5f94-90a5-10d80037d299",
      "id": "CVE-2025-64460",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64460 affects version 5.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af5b3148-347c-5d46-8556-7bcd08d7859b",
      "id": "CVE-2026-1207",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1207 affects version 5.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1763973a-f691-5277-9dd3-83a6c8685dbd",
      "id": "CVE-2026-1285",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1285 affects version 5.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20b5bf2b-de86-57a7-aacb-f445239be996",
      "id": "CVE-2026-1287",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1287 affects version 5.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22592305-ca13-5554-a6e6-2263d9f4638d",
      "id": "CVE-2026-1312",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1312 affects version 5.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b767b3bf-e6da-5a59-811a-343b24aa4561",
      "id": "CVE-2025-45768",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-45768 is fixed in version 2.10.1.post1+tuxcare of pyjwt."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@2.10.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5c54e6e-0ff6-5e5f-99f8-3b1ec971fe6b",
      "id": "CVE-2026-32597",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32597 affects version 2.10.1.post1+tuxcare of pyjwt."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@2.10.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:602a1633-1f89-56e1-a983-8c8df57d7dad",
      "id": "CVE-2026-48522",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-48522 does not affect version 2.10.1.post1+tuxcare of pyjwt. already_fixed \u2014 CVE-2026-48522 describes PyJWKClient accepting non-HTTP(S) URI schemes (file://, ftp://, data:) which enables SSRF and token forgery. The target repository at version 2.10.1.post2+tuxcare (SHA 098e78a) already contains the exact defense recommended in the CVE. The fix was backported by TuxCare in commit afaaa88 as part of the PyJWT 2.13.0 security bundle. The same vulnerability reporter (Keijo ..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@2.10.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf2614df-3f50-53b3-b59e-0bee0658f083",
      "id": "CVE-2026-48523",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48523 affects version 2.10.1.post1+tuxcare of pyjwt."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@2.10.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:badaefeb-8f42-59f7-938e-54afb987354c",
      "id": "CVE-2026-48524",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48524 affects version 2.10.1.post1+tuxcare of pyjwt."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@2.10.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45b38166-80e5-59ae-b6a5-c1003e994d20",
      "id": "CVE-2026-48525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48525 affects version 2.10.1.post1+tuxcare of pyjwt."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@2.10.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3bebb4fb-bcf0-5866-9f34-ea6998ed6d05",
      "id": "CVE-2026-48526",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48526 affects version 2.10.1.post1+tuxcare of pyjwt."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@2.10.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:592d1281-6866-5261-825a-c6324b211c26",
      "id": "CVE-2024-24680",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-24680 is fixed in version 5.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7fede3a2-3efc-5250-b33b-7ca724663cd3",
      "id": "CVE-2024-27351",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27351 affects version 5.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:979d332b-63a9-597e-b797-f701617b3ed0",
      "id": "CVE-2024-38875",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38875 affects version 5.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d554143-1853-595d-8b64-dd50cde865b6",
      "id": "CVE-2024-39329",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-39329 affects version 5.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76e66a83-5cb5-564d-941d-527a10bfe59b",
      "id": "CVE-2024-39330",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-39330 affects version 5.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cdb9b724-e429-5449-b941-8c7966349b11",
      "id": "CVE-2024-39614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-39614 affects version 5.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fddd98cd-901d-5024-9fe4-a05594ab63b3",
      "id": "CVE-2024-41989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-41989 affects version 5.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbeeccfd-7d44-5f56-8c0d-9605791a8b81",
      "id": "CVE-2024-41990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-41990 affects version 5.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b99f2648-dc3a-5ac8-9b0f-d0474b9a5cb8",
      "id": "CVE-2024-41991",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-41991 affects version 5.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38fc28f3-633b-573c-a3ca-d8799804ab5d",
      "id": "CVE-2024-42005",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-42005 affects version 5.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11b1f239-9218-55ef-a139-b35f83238faa",
      "id": "CVE-2024-45230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-45230 affects version 5.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b166cd8-96a5-518f-b07b-975197e79e5d",
      "id": "CVE-2024-45231",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-45231 affects version 5.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c777720-cdec-540b-bfab-3095167b29d6",
      "id": "CVE-2024-53907",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-53907 affects version 5.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ad14e7d-82dd-5616-9908-027795289ae9",
      "id": "CVE-2024-53908",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-53908 affects version 5.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80f8b014-99c6-596f-b301-cc17d7e14fb2",
      "id": "CVE-2024-56374",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56374 affects version 5.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09366a70-bad5-5f96-8e08-18adef2f08ea",
      "id": "CVE-2025-13372",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13372 affects version 5.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb8d809c-f97a-56b0-b1d3-1e071ef87b86",
      "id": "CVE-2025-13473",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13473 affects version 5.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:675e47ac-86a7-5beb-b678-cc7ff2651d5a",
      "id": "CVE-2025-14550",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-14550 affects version 5.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd62d493-fd0c-56ec-b1d3-682451180b65",
      "id": "CVE-2025-26699",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-26699 affects version 5.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63b8656a-814a-556e-9aec-34097c450e04",
      "id": "CVE-2025-27556",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27556 affects version 5.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e930b4b1-1d4f-560a-b53f-98eab3096e5a",
      "id": "CVE-2025-48432",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48432 affects version 5.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68d8a84d-848a-5c3f-bccd-1c5317b1d5cd",
      "id": "CVE-2025-57833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57833 affects version 5.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0132ac1c-b1c9-56a0-a8f8-25c35a0e651e",
      "id": "CVE-2025-64458",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64458 affects version 5.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e43862c-2c01-55c3-8d3a-0555f1c13fc2",
      "id": "CVE-2025-64459",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64459 affects version 5.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a419e23-5877-5976-86e2-a7756cd1cda4",
      "id": "CVE-2025-64460",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64460 affects version 5.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b32c72a-de1d-5d73-b22c-fc9a90e09860",
      "id": "CVE-2026-1207",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1207 affects version 5.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1570ce9d-ab6a-587c-afaa-cca03b74ea46",
      "id": "CVE-2026-1285",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1285 affects version 5.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac95ea0f-df9b-5bba-90bf-cf8ec6c7fd72",
      "id": "CVE-2026-1287",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1287 affects version 5.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d734b3d5-f688-5559-b179-e10944f90707",
      "id": "CVE-2026-1312",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1312 affects version 5.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7497ca72-4d30-5bc2-a218-b459c7a79c46",
      "id": "CVE-2024-47874",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47874 is fixed in version 0.27.0.post1+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1cac683b-8f1f-5646-a30a-8564bef33c51",
      "id": "CVE-2025-54121",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-54121 affects version 0.27.0.post1+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:502e0b44-e518-5ef6-bfbe-a761e6016774",
      "id": "CVE-2025-62727",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-62727 does not affect version 0.27.0.post1+tuxcare of starlette. Version 0.27.0 is not vulnerable. Summary: The target repository (Starlette version 0.27.0) is NOT vulnerable to CVE-2025-62727. The vulnerable Range header parsing logic was introduced in version 0.39.0, and the target version 0.27.0 predates this introduction. The FileResponse class in version 0.27.0 does not implement any Range header parsing or processing functionality. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f6e420b-7c31-5c68-80a6-26ce04b40bf1",
      "id": "CVE-2026-48710",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48710 affects version 0.27.0.post1+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd1a649e-0870-59be-b9ab-caca8d0ef567",
      "id": "CVE-2026-48817",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48817 affects version 0.27.0.post1+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9776162e-929e-52db-ba08-06897f485f2e",
      "id": "CVE-2026-48818",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48818 affects version 0.27.0.post1+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9501175f-dc54-54f0-aacf-9f98809c30bf",
      "id": "CVE-2026-54282",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54282 affects version 0.27.0.post1+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ccf6d59b-54e2-5405-8b26-c1b01be872bb",
      "id": "CVE-2026-54283",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54283 affects version 0.27.0.post1+tuxcare of starlette."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:930102c7-0730-5f91-91ff-d90b7d747500",
      "id": "GHSA-93gm-qmq6-w238",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-93gm-qmq6-w238 is a false positive for starlette 0.27.0.post1+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/starlette@0.27.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e7dc9fd-5f7f-526b-aa62-a2a8df87e8d9",
      "id": "CVE-2021-45115",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-45115 affects version 4.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82ddd128-8275-5c8f-9298-48ec8963c506",
      "id": "CVE-2021-45116",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-45116 is fixed in version 4.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cacae3b9-d828-5998-a90c-c88a69b395a8",
      "id": "CVE-2021-45452",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-45452 affects version 4.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:729123ad-f219-55d6-af59-37b2274ca3d8",
      "id": "CVE-2022-22818",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22818 affects version 4.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7cb9573d-9302-503b-b922-f8f40ff127cf",
      "id": "CVE-2022-23833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-23833 affects version 4.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34d86827-a104-50d0-a07b-7507ffe9db87",
      "id": "CVE-2022-28346",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-28346 affects version 4.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:121f84a2-b176-5eb8-9a16-9fd0a2a51d98",
      "id": "CVE-2022-28347",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-28347 is fixed in version 4.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f4f492b-5e9b-5fef-a08f-9310c9c0ca54",
      "id": "CVE-2022-34265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-34265 is fixed in version 4.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c795c26-1acf-5da6-baa4-b6fb9d109929",
      "id": "CVE-2022-36359",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-36359 is fixed in version 4.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d88c4321-7580-5c5f-a10f-6930df9acd50",
      "id": "CVE-2022-41323",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41323 is fixed in version 4.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6849b3fb-9de5-58c2-bf4e-a26e20c8893a",
      "id": "CVE-2023-23969",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-23969 is fixed in version 4.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc55de50-1fb8-5bde-8657-9d6d45dc72a9",
      "id": "CVE-2023-24580",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-24580 is fixed in version 4.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aca7ea58-818a-513a-ae21-7f45723598d2",
      "id": "CVE-2023-31047",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-31047 affects version 4.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba444ed1-16d3-5994-8f21-966c331f5226",
      "id": "CVE-2023-36053",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36053 affects version 4.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45a5fb9b-365e-5ae3-b0ee-494a61f19921",
      "id": "CVE-2023-43665",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-43665 affects version 4.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc8746b7-12ff-5d13-9e04-231061f3674a",
      "id": "CVE-2023-46695",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46695 affects version 4.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f0893d1-691c-5cbe-9d34-1190a63f3bb8",
      "id": "CVE-2024-45231",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-45231 affects version 4.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a260b096-d4fe-54d3-8381-2dc1856ec5eb",
      "id": "CVE-2025-13372",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13372 affects version 4.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bab64932-32ca-537a-8fbb-11f67a248e26",
      "id": "CVE-2025-13473",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13473 affects version 4.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcfa7112-83be-5ba4-ae3e-a129130a095b",
      "id": "CVE-2025-14550",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-14550 affects version 4.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a43f8a4-13d4-55c6-99cd-221d203b42cb",
      "id": "CVE-2025-48432",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48432 affects version 4.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4ef44df-c728-510b-aed8-0b76127a7533",
      "id": "CVE-2025-57833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57833 affects version 4.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5400f18-5ffd-5e92-94aa-4997de1c273b",
      "id": "CVE-2025-64458",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64458 affects version 4.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4cc17d19-0191-580a-9db4-a551bc1fd4cf",
      "id": "CVE-2025-64459",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64459 affects version 4.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aefb78f3-9082-5d18-a4a4-655fedc7d20e",
      "id": "CVE-2025-64460",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64460 affects version 4.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05137d8e-c7a5-54a3-bcdd-6d95fad02639",
      "id": "CVE-2026-1207",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1207 affects version 4.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38509dd4-557d-5c3d-8520-f89372eb1f65",
      "id": "CVE-2026-1285",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1285 affects version 4.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f9e2dcf-0ec5-5d64-b75f-e919232c6926",
      "id": "CVE-2026-1287",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1287 affects version 4.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b3feb7f-888b-5064-9224-ebc0b9a47c41",
      "id": "CVE-2026-1312",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1312 affects version 4.0.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bebce2b-8c61-5848-918c-dce3531f475e",
      "id": "CVE-2024-24680",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-24680 is fixed in version 5.0.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d933921-ebdf-5e83-9348-2fac3cfbba4a",
      "id": "CVE-2024-27351",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27351 affects version 5.0.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be2266f9-6927-5e42-89f3-78518814b387",
      "id": "CVE-2024-38875",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38875 affects version 5.0.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:630f5db4-a9e4-5666-b3b8-a3deb93e801d",
      "id": "CVE-2024-39329",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-39329 is fixed in version 5.0.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa4cbdb9-47a1-5719-8e77-f89c31e4a7c2",
      "id": "CVE-2024-39330",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-39330 affects version 5.0.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24a6dfbc-a768-5236-8655-dafd6a257322",
      "id": "CVE-2024-39614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-39614 affects version 5.0.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79709737-1908-58f7-a8d4-11b3400cba6b",
      "id": "CVE-2024-41989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-41989 is fixed in version 5.0.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b49ef08-5ea9-5b9d-b590-924c7270e02c",
      "id": "CVE-2024-41990",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-41990 does not affect version 5.0.1.post3+tuxcare of django. not_affected \u2014 Django 5.0.1.post3+tuxcare uses a refactored architecture that does not contain the vulnerable code pattern from CVE-2024-41990. The target implementation uses html.unescape() upfront, while the CVE affects a different implementation with repeated rfind() calls that was introduced later in Django 5.0.7."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3cfe31d-de8f-5cc4-a589-684bb142d205",
      "id": "CVE-2024-41991",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-41991 is fixed in version 5.0.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d4d4369-9b0d-5352-9dad-78e1e14724f1",
      "id": "CVE-2024-42005",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-42005 affects version 5.0.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f73cd021-19a2-5ac7-9283-d7970371d868",
      "id": "CVE-2024-45230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-45230 affects version 5.0.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4a60e85-1e24-53da-a8ec-9473b0436288",
      "id": "CVE-2024-45231",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-45231 affects version 5.0.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:326d2c92-658d-5eda-bb61-34e4ca36d962",
      "id": "CVE-2024-53907",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-53907 affects version 5.0.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f836fff-b4d3-5570-ab73-9d0cbf8cfc9b",
      "id": "CVE-2024-53908",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-53908 affects version 5.0.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4901740-5849-5341-a3c9-db9b7c02562d",
      "id": "CVE-2024-56374",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56374 affects version 5.0.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74bda841-5ca6-59c0-8cc0-1eebba896007",
      "id": "CVE-2025-13372",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13372 affects version 5.0.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d96a5e36-2d75-5a3f-a01f-67c891cda9e8",
      "id": "CVE-2025-13473",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13473 affects version 5.0.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d02da5c2-6371-5e15-b330-be94cc04ff94",
      "id": "CVE-2025-14550",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-14550 affects version 5.0.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6f8fdea-2216-542e-a46c-6a33d60bfcef",
      "id": "CVE-2025-26699",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-26699 affects version 5.0.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf888988-8eca-553e-a9f8-0d40ee8dc659",
      "id": "CVE-2025-27556",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27556 affects version 5.0.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd496bd3-6c3d-5765-a9c2-81f16edabc04",
      "id": "CVE-2025-48432",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48432 affects version 5.0.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06f2a3a2-b0e3-5e80-963b-44182ba81513",
      "id": "CVE-2025-57833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57833 affects version 5.0.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d7c2d4c-4d2d-5f67-b022-4496e46d131e",
      "id": "CVE-2025-64458",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64458 affects version 5.0.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:898a54d2-6a72-5bfe-8f0d-2483b573267c",
      "id": "CVE-2025-64459",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64459 affects version 5.0.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8b5a2cb-bb2f-5dfd-9ac3-dde4b73ff6af",
      "id": "CVE-2025-64460",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64460 affects version 5.0.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b95f6d7c-30e0-5926-9f27-40dd79c5146c",
      "id": "CVE-2026-1207",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1207 affects version 5.0.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a53204e-ba24-595c-80cf-0c9fc5de7c75",
      "id": "CVE-2026-1285",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1285 affects version 5.0.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c0c3ae3-b27a-5cfe-9af2-ccb2b6f2eb32",
      "id": "CVE-2026-1287",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1287 affects version 5.0.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa5d2fa9-2e5d-57b0-9d91-f0af6407f47b",
      "id": "CVE-2026-1312",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1312 affects version 5.0.1.post3+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:375e7370-5666-56ff-bbc8-8852a9947eb3",
      "id": "CVE-2022-29217",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29217 is fixed in version 2.3.0.post1+tuxcare of pyjwt."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5cc006d6-9a70-5832-bf6f-8579237633c4",
      "id": "CVE-2023-29483",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-29483 is fixed in version 2.3.0.post1+tuxcare of pyjwt."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2090cbde-024f-5cf1-8f4b-ae6f63d18a47",
      "id": "CVE-2026-32597",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32597 affects version 2.3.0.post1+tuxcare of pyjwt."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ae30f31-b3c9-5919-b4b5-93bfe84e163a",
      "id": "CVE-2026-48522",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48522 affects version 2.3.0.post1+tuxcare of pyjwt."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ccad75c3-35bf-56a9-9854-e04e0a5c9175",
      "id": "CVE-2026-48524",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-48524 does not affect version 2.3.0.post1+tuxcare of pyjwt. not_affected \u2014 Target PyJWT version 2.3.0 is not affected by CVE-2026-48524. The vulnerability requires the jwk_set_cache feature with a finally-block cache-clearing pattern that was introduced in version 2.5.0. Version 2.3.0 predates this feature and uses a simpler lru_cache-based architecture that inherently avoids the cache-clearing behavior."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e03f98d9-6962-5315-b9a6-5086eaaa206a",
      "id": "CVE-2026-48525",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-48525 does not affect version 2.3.0.post1+tuxcare of pyjwt. not_affected \u2014 Version 2.3.0.post1+tuxcare does not support RFC 7797 detached payloads (b64=false feature), which is the attack vector for CVE-2026-48525. The vulnerability-specific code path does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8f40422-2d96-5ef3-b906-938ebe3d8271",
      "id": "CVE-2026-48526",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48526 affects version 2.3.0.post1+tuxcare of pyjwt."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a55f781f-1b92-56da-97ed-462e9939714d",
      "id": "CVE-2025-45768",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-45768 is fixed in version 2.8.0.post1+tuxcare of pyjwt."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@2.8.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae539d44-8431-58df-b948-87420c91262d",
      "id": "CVE-2026-32597",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32597 affects version 2.8.0.post1+tuxcare of pyjwt."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@2.8.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b846acf7-a447-544a-b236-4e84710d0ace",
      "id": "CVE-2026-48522",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-48522 does not affect version 2.8.0.post1+tuxcare of pyjwt. already_fixed \u2014 CVE-2026-48522: PyJWKClient URI scheme SSRF vulnerability is already fixed in the target repository. The fix was introduced via commit 67029b7 (Backport CVE-2026-48526 to 2.8.0) on 2026-07-13, which added URI scheme validation to reject non-HTTP(S) schemes (file://, ftp://, data:, etc.) before any fetch operation. While the version number was later reverted from 2.8.0.post2+tuxcare to 2.8.0.pos..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@2.8.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51d79640-d91c-5a7d-8b0b-d3f1068068fc",
      "id": "CVE-2026-48524",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48524 affects version 2.8.0.post1+tuxcare of pyjwt."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@2.8.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb1702be-8bb7-544e-a011-b0e6a2963f2c",
      "id": "CVE-2026-48525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48525 affects version 2.8.0.post1+tuxcare of pyjwt."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@2.8.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2dca2dd-7ef3-5106-989d-809864a96277",
      "id": "CVE-2026-48526",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-48526 affects version 2.8.0.post1+tuxcare of pyjwt."
      },
      "affects": [
        {
          "ref": "pkg:pypi/pyjwt@2.8.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e6bc725-d88a-5985-865d-fb4c4d165402",
      "id": "CVE-2024-24680",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-24680 is fixed in version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0139a248-0a3d-506b-b727-6dabfc77ca79",
      "id": "CVE-2024-27351",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27351 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07ea92c3-3b82-5b56-85cf-1cb0ab2b9842",
      "id": "CVE-2024-38875",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38875 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06464612-f997-5f23-bf03-747ea32ddbb9",
      "id": "CVE-2024-39329",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-39329 is fixed in version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58b6bd33-7bec-5baf-a236-177c833d2c45",
      "id": "CVE-2024-39330",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-39330 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fde25b4-8de1-5bd1-885b-9d754d01aaf4",
      "id": "CVE-2024-39614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-39614 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfa4f26f-39cb-5e54-8823-156332348a08",
      "id": "CVE-2024-41989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-41989 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbe87fd8-8f69-5ec1-acb6-3889d6336dee",
      "id": "CVE-2024-41990",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-41990 does not affect version 5.0.1.post2+tuxcare of django. not_affected \u2014 Django 5.0.1.post3+tuxcare uses a refactored architecture that does not contain the vulnerable code pattern from CVE-2024-41990. The target implementation uses html.unescape() upfront, while the CVE affects a different implementation with repeated rfind() calls that was introduced later in Django 5.0.7."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7989c9d9-164f-55da-a460-1aa845f1a8b8",
      "id": "CVE-2024-41991",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-41991 is fixed in version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06fc9401-7fca-51f9-981d-391a0588701b",
      "id": "CVE-2024-42005",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-42005 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51cb02ec-308e-5643-8d2e-3a9d2121eab7",
      "id": "CVE-2024-45230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-45230 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40b4bc44-f990-5e7b-a4ee-ef5baf0d2b1f",
      "id": "CVE-2024-45231",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-45231 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a19ef7eb-a1cc-5413-ac27-883d4dad7e56",
      "id": "CVE-2024-53907",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-53907 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21f6d873-5670-558c-a277-fd2a760ced27",
      "id": "CVE-2024-53908",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-53908 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b40f062-e03e-5396-92d9-80d5355ec6a7",
      "id": "CVE-2024-56374",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56374 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bbe902b-0e82-5552-b358-9affc72bb648",
      "id": "CVE-2025-13372",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13372 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d98ba4a2-21a4-51bf-ba3d-6896a72376a3",
      "id": "CVE-2025-13473",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13473 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:171b3e12-6d9a-5630-b01d-52bad5c537e9",
      "id": "CVE-2025-14550",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-14550 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63215615-49c6-5125-89b6-8f91797b55f5",
      "id": "CVE-2025-26699",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-26699 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:684ff4a2-7eeb-57fe-87e9-56a0a5c9453f",
      "id": "CVE-2025-27556",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27556 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e3944b7-e762-5e72-975c-f43d13ca0ec5",
      "id": "CVE-2025-48432",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48432 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e67b853-c075-53af-9e14-138cae240dc5",
      "id": "CVE-2025-57833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57833 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3984632-21b7-52fa-a6b6-5ab512f2c06a",
      "id": "CVE-2025-64458",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64458 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72877962-a2de-5598-9962-53c5a07ca027",
      "id": "CVE-2025-64459",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64459 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61bb6da9-6207-5161-936f-936faaac9017",
      "id": "CVE-2025-64460",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64460 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5cd02e56-9a25-5902-985a-3c013ea1cc6a",
      "id": "CVE-2026-1207",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1207 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6cce08b-d540-568a-ad91-ab2f6c8ccb68",
      "id": "CVE-2026-1285",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1285 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6fc8015-c0b4-5f22-a556-46e51e103c36",
      "id": "CVE-2026-1287",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1287 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e9a9a29-7e23-52a5-b218-7ccaa4554125",
      "id": "CVE-2026-1312",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1312 affects version 5.0.1.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18cbc991-0c20-59bf-b662-9de1d9949f9d",
      "id": "CVE-2021-23727",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-23727 is fixed in version v5.1.2.post1+tuxcare of celery."
      },
      "affects": [
        {
          "ref": "pkg:pypi/celery@v5.1.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2789f92d-1232-53b6-9819-ca71ef7c4f80",
      "id": "CVE-2022-41323",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41323 is fixed in version 5.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b57a121-fae7-51c3-917a-4050c929aebd",
      "id": "CVE-2024-45230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-45230 affects version 5.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93b27166-125b-5b66-b1fa-5f38e63d9342",
      "id": "CVE-2024-45231",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-45231 affects version 5.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8edafc4-bb28-57e9-b6bd-c4ed9c714d89",
      "id": "CVE-2024-53907",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-53907 affects version 5.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3facd694-a3b6-522a-9701-efebb73b8793",
      "id": "CVE-2024-53908",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-53908 affects version 5.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:721a6034-34da-53ca-a11d-99e2a732238c",
      "id": "CVE-2024-56374",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56374 affects version 5.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56b9eb1c-fe4b-5877-b628-05788b3ce715",
      "id": "CVE-2025-13372",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13372 affects version 5.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f7006dd-d99d-56c1-8008-95bdc2bc11b3",
      "id": "CVE-2025-13473",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13473 affects version 5.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab144b7b-a884-5e40-8df7-06c856868888",
      "id": "CVE-2025-14550",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-14550 affects version 5.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:414d5280-e09e-5e3b-8d60-0a4c33c29a4b",
      "id": "CVE-2025-26699",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-26699 affects version 5.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a8595e1-24b9-5e2e-9a55-9280c14ad819",
      "id": "CVE-2025-27556",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27556 affects version 5.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19b0b575-8709-5c6d-b8a8-5d176cd7bae9",
      "id": "CVE-2025-32873",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-32873 affects version 5.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24b607f3-e603-5492-8d13-b74e0ea9f838",
      "id": "CVE-2025-48432",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48432 affects version 5.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70ad8a79-d575-5295-a72b-69f04320e595",
      "id": "CVE-2025-57833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57833 affects version 5.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c16aa8d-ea9a-5762-8e67-b03399c1a888",
      "id": "CVE-2025-59681",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59681 affects version 5.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3084b095-5d09-597c-a8d3-6a20591fc882",
      "id": "CVE-2025-59682",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59682 affects version 5.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94fc7423-12a8-5373-b1ba-bc9e1aa00967",
      "id": "CVE-2025-64458",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64458 affects version 5.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db539da7-b868-577b-b023-858e64dfa0f6",
      "id": "CVE-2025-64459",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64459 affects version 5.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c5ae15f-71d2-58ce-bea9-9e5a3bafe3dd",
      "id": "CVE-2025-64460",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64460 affects version 5.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac252b72-ed86-56d8-8eea-b2571c03eb8b",
      "id": "CVE-2026-1207",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1207 affects version 5.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66560344-8d6f-5414-82f3-d59dc2c0d97e",
      "id": "CVE-2026-1285",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1285 affects version 5.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:678ee86f-2c42-5ff4-a36c-a53fa1328c1f",
      "id": "CVE-2026-1287",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1287 affects version 5.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75155d6e-30f7-5cfa-beff-4f90942b9e2e",
      "id": "CVE-2026-1312",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1312 affects version 5.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83555172-732f-5ccb-92e6-0dc5d3efa22e",
      "id": "CVE-2021-45115",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-45115 affects version 4.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:482437ca-f1a5-5367-b6f2-b3a08607958e",
      "id": "CVE-2021-45116",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-45116 is fixed in version 4.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:354221bc-08cb-5ec9-ad42-1805f9fc066a",
      "id": "CVE-2021-45452",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-45452 affects version 4.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9964b409-03b3-5c3a-aa91-ea746a7ee480",
      "id": "CVE-2022-22818",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22818 affects version 4.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b2fa4b4-1220-521d-91cd-399d29187351",
      "id": "CVE-2022-23833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-23833 affects version 4.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:566f1f15-5b8c-569c-b1ee-87616b1b844b",
      "id": "CVE-2022-28346",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-28346 affects version 4.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c74717d-e0c8-51de-bb01-908d7f252f22",
      "id": "CVE-2022-28347",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-28347 affects version 4.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c64d5b83-1b1e-50df-9440-85565b7fcd20",
      "id": "CVE-2022-34265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34265 affects version 4.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3b4acf9-d58a-5a08-bc92-c4ce48588778",
      "id": "CVE-2022-36359",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-36359 affects version 4.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72024402-8eaf-501b-8337-0a8040e70fbe",
      "id": "CVE-2022-41323",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41323 is fixed in version 4.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d1afde1-53ed-5002-9015-435fb39b23b7",
      "id": "CVE-2023-23969",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-23969 is fixed in version 4.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5997048-09b0-5eba-a7b2-e807277a3efa",
      "id": "CVE-2023-24580",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-24580 is fixed in version 4.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:517064fc-5362-539f-a738-86830019039d",
      "id": "CVE-2023-31047",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-31047 affects version 4.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb090e4d-6ed8-5f18-8b99-7835028f6336",
      "id": "CVE-2023-36053",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36053 affects version 4.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7968a5ba-cfe3-512b-a2ec-7ab825cbf9da",
      "id": "CVE-2023-43665",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-43665 affects version 4.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a6be278-5cd7-5d73-baa4-11e1be56a103",
      "id": "CVE-2023-46695",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46695 affects version 4.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90a59763-9c40-50cb-8101-9d712f5c2df9",
      "id": "CVE-2024-45231",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-45231 affects version 4.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a12026d9-f79f-5d91-8b48-d5a77a886236",
      "id": "CVE-2025-13372",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13372 affects version 4.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:994e8991-413b-529a-9584-dfd7f40f0cfd",
      "id": "CVE-2025-13473",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13473 affects version 4.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb25304f-043b-581b-ac48-b29486683013",
      "id": "CVE-2025-14550",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-14550 affects version 4.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:101e9b76-5d7f-5d83-a81b-e71768cb3952",
      "id": "CVE-2025-48432",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48432 affects version 4.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4330afcb-48e0-5eed-baaa-1bf1b8fe8d8a",
      "id": "CVE-2025-57833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57833 affects version 4.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b13fbb50-10b4-5ec3-89a2-7b72a4e82f3c",
      "id": "CVE-2025-64458",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64458 affects version 4.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a30519e-44ff-5018-9c3e-6e2c8109f24a",
      "id": "CVE-2025-64459",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64459 affects version 4.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5868011c-d010-55e9-8354-6901377451bb",
      "id": "CVE-2025-64460",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64460 affects version 4.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:080f2bb2-f2e1-53e8-b706-71121af0c53e",
      "id": "CVE-2026-1207",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1207 affects version 4.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be239827-2789-5ad8-820b-91dfcab35cb9",
      "id": "CVE-2026-1285",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1285 affects version 4.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e9140a8-459c-5505-91ea-731b0869bfae",
      "id": "CVE-2026-1287",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1287 affects version 4.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57f5cf87-d9c0-5ea9-a0ba-268a06a067d7",
      "id": "CVE-2026-1312",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1312 affects version 4.0.post2+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac5fa9c6-9858-5259-86d3-72850c1d8452",
      "id": "CVE-2022-33124",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-33124 is a false positive for aiohttp 3.8.1.post1+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a8f04ef-a9e2-580c-b5e3-fbd040c99f5c",
      "id": "CVE-2023-37276",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-37276 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e03962f-97eb-5ba7-ab96-0e78cc1a2fa1",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-49081 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a384c8db-c82a-57cd-b716-0b623c7de149",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-49082 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43df72e3-36fa-5e41-9650-ef9a9c5374fc",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23334 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6757cbd1-42a1-554d-b0ba-479c9ea9ecd3",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23829 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2ae0902-8f11-5c97-9e32-9dd3e5ef6524",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27306 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1ed5888-c28d-5314-92f9-036348ac10d1",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-30251 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32d3257d-5c49-5d4a-8bf3-2afac5e10a0d",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52304 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8db62e05-1c39-54f6-b25c-f5609663459a",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-53643 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22600a1c-8378-5fd1-9458-087304371172",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b87ecfd-0e87-5cd1-9c68-54cbd4055b06",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09ca2978-497e-542a-87ef-d00a2603d3e9",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fd6df35-32c4-5d93-8e72-5a9946f384a0",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e520fa43-f5aa-5f5a-ad14-99c285cc5eb1",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afb20e44-25b6-5eec-857e-68acc6431a40",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6bf86a1-42b1-52da-9766-c4978d5514e0",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c58fae00-1fbc-5f67-b27d-6e715412c7c0",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f53b1104-9321-5129-92d5-f16665d8cdd3",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22815 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a746f5b-b5ae-5d3c-82eb-abcbd7215e06",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34513 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:796fe057-450f-598a-9643-fe7b37a4d2c8",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34514 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:188c30bc-17d4-59dc-a92f-1c8f9c0e3feb",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66a77b03-65d1-50e4-a3f8-4eb517746cfc",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34516 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9563427-ceb8-57d0-aa86-85bfd3381256",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34517 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0393d81c-04c3-554b-8683-ca5d7b9f1e4e",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34518 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f164672-a029-57b0-a451-5355e616964d",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34519 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10c6a6ad-ffe8-50ee-978c-349fc0eee1bf",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34520 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e792919-a08e-53df-ad10-11a7c556c2d5",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34525 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0292573d-1019-50dc-b51a-d072f440ba5d",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d54e9c8-81ae-5251-9da5-cbcb059db192",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9c5e56e-b003-5c05-b4e7-87859401f692",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50f2c1bd-f164-5204-bbc7-ebeb13214a09",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13e29fee-75ce-5593-948b-b5993a413876",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42fae804-7cc6-5e58-8763-e4bc1018eadc",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.1.post1+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2515679a-cf90-530e-b627-104964fd4c25",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.1.post1+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:021336f3-add6-553a-a539-62b0cb4117ab",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ccac468-48e6-5c91-87da-73f45b5548dd",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fdb9f16a-52a1-595d-a492-3886df56ab6b",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5f246a5-6589-5622-84e2-1a229c298625",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.1.post1+tuxcare of aiohttp. CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe"
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91ea5cee-da26-51ea-90e7-336517c263c2",
      "id": "GHSA-pjjw-qhg8-p2p9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.1.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15f22cb3-8230-5c79-bf3d-e810b0fbae7e",
      "id": "CVE-2021-45115",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-45115 affects version 4.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbad0cca-2e16-57eb-90b2-b10391af60de",
      "id": "CVE-2021-45116",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-45116 affects version 4.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5eecddf5-def6-5e98-a484-467687531e8a",
      "id": "CVE-2021-45452",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-45452 affects version 4.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3187da3a-9f72-5a02-9a05-18837cbc6599",
      "id": "CVE-2022-22818",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22818 affects version 4.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87217360-201c-595d-a74c-1289d6038ba0",
      "id": "CVE-2022-23833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-23833 affects version 4.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65cb792f-88ea-58e4-9c45-8634524a3ce3",
      "id": "CVE-2022-28346",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-28346 affects version 4.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42b4744a-174b-5a6b-915a-2b14788160a9",
      "id": "CVE-2022-28347",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-28347 affects version 4.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d379f14-ddcb-59fe-a614-60ed7136da57",
      "id": "CVE-2022-34265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34265 affects version 4.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5899cffd-c097-5caa-92da-888454fdecc7",
      "id": "CVE-2022-36359",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-36359 affects version 4.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de62cf30-ba3e-5ea9-9cc5-47653837b90e",
      "id": "CVE-2022-41323",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-41323 affects version 4.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:319725eb-4de1-5fa6-96d8-02b395055378",
      "id": "CVE-2023-23969",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-23969 is fixed in version 4.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bf6f184-69b2-5ce6-850d-797b3168c3e8",
      "id": "CVE-2023-24580",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-24580 is fixed in version 4.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b373c823-da3a-5feb-a35f-4f531c2076e0",
      "id": "CVE-2023-31047",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-31047 affects version 4.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93841008-2761-5232-99a1-b9beec378cd3",
      "id": "CVE-2023-36053",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-36053 affects version 4.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:102a5fb9-1a13-5244-a597-67278a943a2b",
      "id": "CVE-2023-43665",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-43665 affects version 4.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:715c2dcc-e144-568b-b98d-324e4d5dafd4",
      "id": "CVE-2023-46695",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46695 affects version 4.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb1c683e-65b4-5b38-80a4-419587f01296",
      "id": "CVE-2024-45231",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-45231 affects version 4.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9243236d-434b-5a42-bdf4-0e84fb4d5545",
      "id": "CVE-2025-13372",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13372 affects version 4.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:080ad072-2a63-504a-9ad3-351cb97ac958",
      "id": "CVE-2025-13473",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13473 affects version 4.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80efe4bb-3483-535f-bf99-194881b8f177",
      "id": "CVE-2025-14550",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-14550 affects version 4.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e25241d-c714-5e07-ade3-9b57ee3ac590",
      "id": "CVE-2025-48432",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48432 affects version 4.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3be2b689-be61-51dc-b0e9-70762637dfdc",
      "id": "CVE-2025-57833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57833 affects version 4.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8d1fda7-8899-550d-a1b0-d6ed469d5d08",
      "id": "CVE-2025-64458",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64458 affects version 4.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42fdf595-39f0-5712-86db-7527a4b8c5c7",
      "id": "CVE-2025-64459",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64459 affects version 4.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c664d08d-39ad-5f60-a0df-b1a80b9a9381",
      "id": "CVE-2025-64460",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64460 affects version 4.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7b579e6-6d5f-5b7f-95e7-e5b33cec289f",
      "id": "CVE-2026-1207",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1207 affects version 4.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56ef14da-5aff-5b6c-ad72-21d87bee2ffa",
      "id": "CVE-2026-1285",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1285 affects version 4.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be4a168c-c551-522f-8403-3d1bca0a196f",
      "id": "CVE-2026-1287",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1287 affects version 4.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19bfa807-e874-57a8-983f-2d65f6d533cf",
      "id": "CVE-2026-1312",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1312 affects version 4.0.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@4.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:880f1108-80dd-5b7f-ad2a-74340ffdecd8",
      "id": "CVE-2024-24762",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-24762 is fixed in version 0.104.1.post1+tuxcare of fastapi."
      },
      "affects": [
        {
          "ref": "pkg:pypi/fastapi@0.104.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7adf649d-9443-5719-9c4d-ddbe02cc8b16",
      "id": "GHSA-qf9m-vfgh-m389",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-qf9m-vfgh-m389 is a false positive for fastapi 0.104.1.post1+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/fastapi@0.104.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e6dbcca-fd31-5ed6-a553-1caaae7fc899",
      "id": "CVE-2025-50817",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-50817 is a false positive for future 1.0.0.post1+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/future@1.0.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1160392b-bc19-5ffe-8b33-3f1d969ee654",
      "id": "CVE-2020-7694",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-7694 is fixed in version 0.11.6.post1+tuxcare of uvicorn."
      },
      "affects": [
        {
          "ref": "pkg:pypi/uvicorn@0.11.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06303e9f-1a2e-58eb-846d-994d5538ae64",
      "id": "CVE-2020-7695",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-7695 is fixed in version 0.11.6.post1+tuxcare of uvicorn."
      },
      "affects": [
        {
          "ref": "pkg:pypi/uvicorn@0.11.6.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2e3d397-74a2-536c-a564-5452adda1092",
      "id": "CVE-2019-6446",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-6446 is fixed in version 1.15.4.post1+tuxcare of numpy."
      },
      "affects": [
        {
          "ref": "pkg:pypi/numpy@1.15.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f1b856e-2c5b-5003-85c4-6dd363fc3af9",
      "id": "CVE-2021-33430",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-33430 affects version 1.15.4.post1+tuxcare of numpy."
      },
      "affects": [
        {
          "ref": "pkg:pypi/numpy@1.15.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0d27ae6-3195-582f-bb77-bb56b712dc95",
      "id": "CVE-2021-34141",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-34141 is fixed in version 1.15.4.post1+tuxcare of numpy."
      },
      "affects": [
        {
          "ref": "pkg:pypi/numpy@1.15.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ba6f43c-897f-5627-917b-27dd0db32f75",
      "id": "CVE-2021-41495",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41495 affects version 1.15.4.post1+tuxcare of numpy."
      },
      "affects": [
        {
          "ref": "pkg:pypi/numpy@1.15.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca9e6366-60ce-5374-985d-1ad655817fb4",
      "id": "CVE-2021-41496",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41496 affects version 1.15.4.post1+tuxcare of numpy."
      },
      "affects": [
        {
          "ref": "pkg:pypi/numpy@1.15.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37c0fc7b-720e-5deb-9564-f8505e835160",
      "id": "CVE-2021-32677",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-32677 is fixed in version 0.63.0.post2+tuxcare of fastapi."
      },
      "affects": [
        {
          "ref": "pkg:pypi/fastapi@0.63.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b56a2bfb-dace-5c57-b0d2-19d1e5c2947a",
      "id": "CVE-2024-24762",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-24762 is fixed in version 0.63.0.post2+tuxcare of fastapi."
      },
      "affects": [
        {
          "ref": "pkg:pypi/fastapi@0.63.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13c555b7-e491-54ad-8aa6-733feff65d5a",
      "id": "GHSA-qf9m-vfgh-m389",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-qf9m-vfgh-m389 is a false positive for fastapi 0.63.0.post2+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/fastapi@0.63.0.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ae0b35f-141e-57a7-a1b5-446c085aa9fa",
      "id": "CVE-2021-32677",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-32677 is fixed in version 0.63.0.post1+tuxcare of fastapi."
      },
      "affects": [
        {
          "ref": "pkg:pypi/fastapi@0.63.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b283f7b-e426-56e2-bcff-588fee82de8e",
      "id": "CVE-2024-24762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24762 affects version 0.63.0.post1+tuxcare of fastapi."
      },
      "affects": [
        {
          "ref": "pkg:pypi/fastapi@0.63.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65c00c49-0cbf-5c58-a930-fb45ac10392d",
      "id": "GHSA-qf9m-vfgh-m389",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability GHSA-qf9m-vfgh-m389 is a false positive for fastapi 0.63.0.post1+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/fastapi@0.63.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4120d49b-0596-5e94-817e-96c95d77bd69",
      "id": "CVE-2024-56374",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56374 is fixed in version 5.1.4.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00d4db14-a511-5314-ad2a-172a4ce12ec3",
      "id": "CVE-2025-13372",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13372 affects version 5.1.4.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76bb1ba4-a7c5-5ced-82da-0066261334d6",
      "id": "CVE-2025-13473",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13473 affects version 5.1.4.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98081d22-b545-5938-bf1b-ad447a802989",
      "id": "CVE-2025-14550",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-14550 affects version 5.1.4.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:563c1b80-6a73-5306-b1ca-ef711144bb11",
      "id": "CVE-2025-26699",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-26699 affects version 5.1.4.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fac5c8d-3fb4-5342-8c43-d81e14ca6254",
      "id": "CVE-2025-27556",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27556 affects version 5.1.4.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fec3ca37-ad46-5fd1-a4ef-296521ea8d9f",
      "id": "CVE-2025-32873",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-32873 affects version 5.1.4.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b262e502-a55d-5db4-927d-447575b36636",
      "id": "CVE-2025-48432",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48432 affects version 5.1.4.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7335c40-1437-513b-a0e1-eae7a415e418",
      "id": "CVE-2025-57833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57833 affects version 5.1.4.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5a3cb81-efcc-5504-a0b7-0aa93491b1e5",
      "id": "CVE-2025-59681",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59681 affects version 5.1.4.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3efe5a49-eb1d-5932-aec4-c468c72d7adf",
      "id": "CVE-2025-59682",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59682 affects version 5.1.4.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c0d4316-5b63-540f-b7f1-d3a9a3595667",
      "id": "CVE-2025-64458",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64458 affects version 5.1.4.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81d97296-5191-55d9-adef-7c9961abf9ea",
      "id": "CVE-2025-64459",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64459 affects version 5.1.4.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:798428bf-610b-5f2d-be83-46c91d2eb4f8",
      "id": "CVE-2025-64460",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64460 affects version 5.1.4.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:046109e1-ce2f-50d7-a697-fbc5e82648bc",
      "id": "CVE-2026-1207",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1207 affects version 5.1.4.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:129e8ba4-82d2-50e8-add3-29360b64067c",
      "id": "CVE-2026-1285",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1285 affects version 5.1.4.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e19bd4c2-8b50-5bbd-9f02-538a867bae1e",
      "id": "CVE-2026-1287",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1287 affects version 5.1.4.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7242c0b9-816c-5768-b165-8ac49a169d2a",
      "id": "CVE-2026-1312",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1312 affects version 5.1.4.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4cd749e-8a59-547c-a4c0-1a7d939d1434",
      "id": "CVE-2025-13372",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13372 affects version 5.1.9.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.9.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4d0d3fb-8289-5865-9d55-09a6571cf678",
      "id": "CVE-2025-13473",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13473 affects version 5.1.9.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.9.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f7167f5-6cce-52b6-96d3-100fc564bfcf",
      "id": "CVE-2025-14550",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-14550 affects version 5.1.9.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.9.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a87593a7-3ef7-5b0a-b1ca-a2e2aca13586",
      "id": "CVE-2025-48432",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48432 is fixed in version 5.1.9.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.9.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b3658e3-2b4f-5e11-9817-6647df676cf8",
      "id": "CVE-2025-57833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57833 affects version 5.1.9.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.9.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be3bd04a-46d2-5383-b735-e5b7248ad7e6",
      "id": "CVE-2025-59681",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59681 affects version 5.1.9.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.9.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5673ff95-2430-5923-a796-80649285b4d5",
      "id": "CVE-2025-59682",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59682 affects version 5.1.9.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.9.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5466adeb-c16b-5647-826f-b7f4298a438b",
      "id": "CVE-2025-64458",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64458 affects version 5.1.9.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.9.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64ba913d-f929-5f1c-8abd-39aab5891b9e",
      "id": "CVE-2025-64459",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64459 affects version 5.1.9.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.9.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2091a73-0978-52b7-80fa-0bfab3bb0ecb",
      "id": "CVE-2025-64460",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64460 affects version 5.1.9.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.9.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdeeb7dc-a77d-5985-a338-b89f22f2fca8",
      "id": "CVE-2026-1207",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1207 affects version 5.1.9.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.9.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6fe8c6ee-9244-5cb7-b544-6b91c19c9869",
      "id": "CVE-2026-1285",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1285 affects version 5.1.9.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.9.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8f06f8a-d3a8-553f-929d-05a7392e270f",
      "id": "CVE-2026-1287",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1287 affects version 5.1.9.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.9.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6dfe4464-db22-59b6-82a4-541201027f60",
      "id": "CVE-2026-1312",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1312 affects version 5.1.9.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.1.9.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3fba221a-93ff-530f-a323-0f7c6d179949",
      "id": "CVE-2024-27351",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-27351 is fixed in version 5.0.2.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3529c1e4-dd0d-5708-b597-c43bb3bd2855",
      "id": "CVE-2024-38875",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38875 affects version 5.0.2.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26eef603-f683-5f8c-8b5b-29df6adc9b6e",
      "id": "CVE-2024-39329",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-39329 affects version 5.0.2.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f83d6e54-f047-5615-a3af-2c2da3160f8b",
      "id": "CVE-2024-39330",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-39330 affects version 5.0.2.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9fd3c79-0673-58d4-8f36-4f134060eedd",
      "id": "CVE-2024-39614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-39614 affects version 5.0.2.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e65d40df-8ef3-5018-bca3-dd3c9a6df1ab",
      "id": "CVE-2024-41989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-41989 affects version 5.0.2.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68ddbbc1-52ac-52ed-950c-712b2171a6d1",
      "id": "CVE-2024-41990",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-41990 does not affect version 5.0.2.post1+tuxcare of django. not_affected \u2014 Django 5.0.2 uses the original simple trim_punctuation implementation that lacks the vulnerable code pattern. CVE-2024-41990's DoS vulnerability was introduced by the CVE-2024-38875 fix (commit d666457453, June 2024) which replaced the simple implementation with a complex CountsDict-based one containing repeated rfind('&') calls. The target version predates this architectural change and therefo..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e4ba1ab-b5eb-51f7-be84-981e6ff42779",
      "id": "CVE-2024-41991",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-41991 affects version 5.0.2.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:643868c7-d072-5595-927a-c98139751c90",
      "id": "CVE-2024-42005",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-42005 affects version 5.0.2.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f210f80-2d65-53ab-a2f6-deee7ab56ee2",
      "id": "CVE-2024-45230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-45230 affects version 5.0.2.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bef00501-5104-5a46-9677-e8760c85b0f6",
      "id": "CVE-2024-45231",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-45231 affects version 5.0.2.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81e229f5-9ef6-5624-b876-b5596fe1abbe",
      "id": "CVE-2024-53907",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-53907 affects version 5.0.2.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e64a171a-d67f-51de-8cfd-3c8173b5b2d9",
      "id": "CVE-2024-53908",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-53908 affects version 5.0.2.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf7e6634-9f21-5e29-bd04-429bc963fea3",
      "id": "CVE-2024-56374",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56374 affects version 5.0.2.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:122d71c2-7247-5ac2-82c3-e9e899e6f1c8",
      "id": "CVE-2025-13372",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13372 affects version 5.0.2.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5408f979-e20e-50b4-85dc-111001d03ef5",
      "id": "CVE-2025-13473",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13473 affects version 5.0.2.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:811f5bc0-1b41-536c-be0f-5fc17a2e30cf",
      "id": "CVE-2025-14550",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-14550 affects version 5.0.2.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9d76d80-bf5b-5781-a05b-cd5709e83071",
      "id": "CVE-2025-26699",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-26699 affects version 5.0.2.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3fb179d2-e686-5ea9-afd2-48da3626a0ba",
      "id": "CVE-2025-27556",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27556 affects version 5.0.2.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e721eba2-ae8e-5070-8d9b-e0a3fae0a47d",
      "id": "CVE-2025-48432",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48432 affects version 5.0.2.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b456886b-ed8a-56c4-8a9a-11d1311a59cd",
      "id": "CVE-2025-57833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57833 affects version 5.0.2.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70b1df50-eedf-5b1d-b642-ee01892e9a0b",
      "id": "CVE-2025-64458",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64458 affects version 5.0.2.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5b63489-cf6f-5528-8e4d-f29b7f5a2706",
      "id": "CVE-2025-64459",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64459 affects version 5.0.2.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:505e8cbd-4ec7-5e24-97a6-ad758a0f56d8",
      "id": "CVE-2025-64460",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64460 affects version 5.0.2.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d55b097b-1003-5743-917b-4f213c5e88ba",
      "id": "CVE-2026-1207",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1207 affects version 5.0.2.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9169416e-5f24-5bcd-afef-a961cddc88c9",
      "id": "CVE-2026-1285",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1285 affects version 5.0.2.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e84c0752-4901-5e31-a874-b407e99f9681",
      "id": "CVE-2026-1287",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1287 affects version 5.0.2.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e7467bb-cee2-5826-83ae-1da6c039f975",
      "id": "CVE-2026-1312",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1312 affects version 5.0.2.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52dba537-68ac-5079-9a2b-a1cf439077d0",
      "id": "CVE-2019-6446",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-6446 is fixed in version 1.16.0.post1+tuxcare of numpy."
      },
      "affects": [
        {
          "ref": "pkg:pypi/numpy@1.16.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c242618c-229d-5b67-a820-e2e48ce77905",
      "id": "CVE-2021-33430",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-33430 affects version 1.16.0.post1+tuxcare of numpy."
      },
      "affects": [
        {
          "ref": "pkg:pypi/numpy@1.16.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e75fec8b-b0c7-5871-8ed9-ff559e436895",
      "id": "CVE-2021-34141",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-34141 affects version 1.16.0.post1+tuxcare of numpy."
      },
      "affects": [
        {
          "ref": "pkg:pypi/numpy@1.16.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3bd5d698-5cd4-5f2e-864d-c7eda53779ca",
      "id": "CVE-2021-41495",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41495 affects version 1.16.0.post1+tuxcare of numpy."
      },
      "affects": [
        {
          "ref": "pkg:pypi/numpy@1.16.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47134ae1-6976-5b86-b668-8470ea7e8991",
      "id": "CVE-2021-41496",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-41496 is fixed in version 1.16.0.post1+tuxcare of numpy."
      },
      "affects": [
        {
          "ref": "pkg:pypi/numpy@1.16.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2e16421-bfe1-57f9-953f-51da55974682",
      "id": "CVE-2023-47627",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-47627 is fixed in version 3.8.5.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58f4fe62-e5bd-50f8-8c82-233a498899b8",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-49081 affects version 3.8.5.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb9469d5-43dd-5e14-a2c7-cd18cdf974a8",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49082 is fixed in version 3.8.5.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:984045fb-ec7f-5688-8566-5e00b0185cbc",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23334 affects version 3.8.5.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf506a1b-b4ff-50ca-8340-69f601f3cc75",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23829 affects version 3.8.5.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c34d42cd-f8d5-596b-b051-b8df79a8d9ca",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27306 affects version 3.8.5.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a47b3951-6cb4-54b0-af93-370aa5f9aa7d",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-30251 affects version 3.8.5.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2704365-11eb-5cb5-a049-7fdd9e803f2a",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52304 is fixed in version 3.8.5.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34567212-2c49-51bc-9f94-066e3f210395",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-53643 affects version 3.8.5.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0c2b25d-c91d-578f-92bf-d369a12d8dba",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.5.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d18a9f6-940b-530a-926b-c233668ad828",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.5.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cee41ffc-d3bf-5ea0-b1b7-f72aacad30e0",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.5.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76e4139b-cf04-5075-972c-fdac5034a733",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.5.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e700148d-108b-574b-b2ef-e55cbd86d6c2",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.5.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9ae5bd2-ece2-57dc-9159-c34546e9d6d5",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.5.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b035dd09-7368-5987-9e41-560cc1d7d339",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.5.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:281ae715-9d65-5ed5-b074-749fb166efd9",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.5.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ecc9e488-a536-59ca-87b0-17201bdd2ab4",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22815 affects version 3.8.5.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1f59da2-642f-56de-a11a-d97ba794a9b0",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34513 affects version 3.8.5.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41bbf6a1-2880-5e4b-9fe4-f330da49dddf",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34514 affects version 3.8.5.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15401d18-c4d3-53f6-9ab1-1c0026f1cf57",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.5.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d623c16-c9d9-56e8-8d89-6d8f3a512bc0",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34516 affects version 3.8.5.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82540dcc-e101-57e9-9bb6-3afd62386755",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34517 affects version 3.8.5.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e4a9b92-352c-5bf5-be40-b964bd3f3c10",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34518 affects version 3.8.5.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc86eb0d-41d8-5ef5-88ae-7ae37b67faba",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34519 affects version 3.8.5.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6416773-8588-58dc-a11e-55645c3dd086",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34520 affects version 3.8.5.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7f29edb-5fce-5838-ac0e-67f2711378d3",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34525 affects version 3.8.5.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:beadb5ff-6bef-5ade-844d-1feba864a6c4",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.5.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69f27795-9b5f-588c-a0cc-7a591058931f",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.5.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b541d878-2ead-525a-994c-1c8839cd1d69",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.5.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8cc16633-c812-52d3-9977-b924d9acec40",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.5.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59927dee-c371-5200-8793-ada9b35f549c",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.5.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b69cc8ca-d2d6-5fbe-9d1a-35e8dac8bc00",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.5.post2+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd499294-1f73-5f27-a2d1-f1b3f1d8d79f",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.5.post2+tuxcare of aiohttp. not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38f62020-42b8-5e9c-a4f7-d814fe7dee41",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.5.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49730ae8-e010-5555-854c-86fad5ab81df",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.5.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:141aee3d-4979-509c-bb84-6efe7f3c411c",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.5.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c4eaf93-9c9f-581f-9930-56342a46343f",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.5.post2+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76172bfe-45c3-512b-b379-194bf5075cf6",
      "id": "GHSA-pjjw-qhg8-p2p9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.5.post2+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ad70969-7ae0-519d-b853-d1be5cb79f6a",
      "id": "CVE-2023-37276",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-37276 is fixed in version 3.8.4.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc9b9a0e-56f9-5a5c-abd3-5031c763d85b",
      "id": "CVE-2023-47627",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-47627 affects version 3.8.4.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83611c2a-dca4-569d-ad81-809e4cd9f9ca",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-49081 affects version 3.8.4.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e71899f1-c390-5c83-929b-01d7f733a37a",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-49082 affects version 3.8.4.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a123a900-b3e3-5155-a2f6-d80b642112c1",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23334 affects version 3.8.4.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:012429fa-4d81-514c-bcb4-9c14de0e8237",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23829 affects version 3.8.4.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a866e2a-16e9-50d5-9258-fd36443bd35b",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27306 affects version 3.8.4.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57038a74-9342-5584-b905-67814cb76906",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-30251 affects version 3.8.4.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12e1cc11-4344-52b4-b554-f96b91834b8e",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52304 affects version 3.8.4.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:faf3f91b-e3c1-55a8-a5b8-6a8fd02ae448",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-53643 affects version 3.8.4.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71c285e0-594e-551f-964e-2bb90aaca3ba",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.4.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:319b92a1-ae37-5ffe-bc4a-618afa1dbf6c",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.4.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1168f771-fde2-5f05-a3a4-a3e881e51e68",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.4.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f8bc0a5-9724-589e-bca8-849c20351a35",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.4.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9124740b-b86d-51fd-8301-0899a24deeb4",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.4.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:053717a5-c835-53bd-9704-d340f80846c1",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.4.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e6abecb-ec5b-58a0-af88-6c550e6422ba",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.4.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3257852-a063-5e64-9574-89b2000062ee",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.4.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f52fa62-fbca-52fe-b9e0-b0bf3d80b1ce",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22815 affects version 3.8.4.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c13dee8-19a5-5dfb-a398-df3f8c036f40",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34513 affects version 3.8.4.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8aa1beab-6ab0-5dd4-90fa-aa0d9ea49aad",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34514 affects version 3.8.4.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:785a48f1-daaa-55a4-b3ce-7679598826bf",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.4.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a54c438a-17c7-57cd-9d75-cba7ae7ac0dc",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34516 affects version 3.8.4.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14bbc317-0497-560a-95c1-1199d880da86",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34517 affects version 3.8.4.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74bc674f-7063-5509-954f-90097863af20",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34518 affects version 3.8.4.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a907207-6a86-5f95-884c-9ca0460571dc",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34519 affects version 3.8.4.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82679718-4203-5724-9fa0-f89b4fd7619c",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34520 affects version 3.8.4.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f26003e3-84c3-54e4-8e39-28ddeed41c4a",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34525 affects version 3.8.4.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:421251f4-fd13-51c2-b9d3-48d1abe86c67",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.4.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ce3d6f1-f7b0-5073-906e-6c7a826ccbd0",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.4.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9df5bcb4-4b83-55b9-8162-bf0885fd612f",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.4.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00f3c168-d0d8-5068-a3be-4cedeed1a765",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.4.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5912363-91d7-5c14-92d4-6fcde9e82e8e",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.4.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86f3ce53-c052-526a-9268-5120c5bead0e",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.4.post1+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.4.post4+tuxcare. The vulnerability requires the server_hostname parameter feature, which was not added until version 3.9.0+ (August 2023), six months after version 3.8.4 was released (February 2023). The target version cannot receive the malicious input described in the CVE."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03017126-f5c6-5f58-bdd6-b12390e361bd",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.4.post1+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.4.post4+tuxcare) does not contain the DigestAuthMiddleware component. This feature was introduced in aiohttp version 3.12, which postdates the target version. The vulnerability cannot manifest because the affected code does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c1dc605-da0a-55b7-9aa1-0a69ad722018",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.4.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0bf03050-112d-5553-a341-950405236d73",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.4.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86414412-b3d3-54a6-a191-605dab5f9023",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.4.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f658756c-81f3-5919-af46-b18e598dc6d5",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54280 affects version 3.8.4.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f52a372-e370-5a27-bab2-788a1e1a55e5",
      "id": "GHSA-pjjw-qhg8-p2p9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.4.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9908734-7258-5922-993e-430ac3098ff8",
      "id": "CVE-2024-24680",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-24680 is fixed in version 5.0.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d53053b1-8335-5943-b6b3-2afde6c82b00",
      "id": "CVE-2024-27351",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27351 affects version 5.0.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a399d0b-0284-50d0-ae58-b094fe8f3c1d",
      "id": "CVE-2024-38875",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38875 affects version 5.0.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24c69604-5531-542a-8430-bd47d595c967",
      "id": "CVE-2024-39329",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-39329 affects version 5.0.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:412f68b7-c046-5d99-a18e-6b09b5612646",
      "id": "CVE-2024-39330",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-39330 affects version 5.0.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f41bf9db-9413-5763-afce-16ee2f18d835",
      "id": "CVE-2024-39614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-39614 affects version 5.0.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cec9b101-7579-5611-ad95-d23aec173bc2",
      "id": "CVE-2024-41989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-41989 affects version 5.0.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91bc4fbe-f78a-5b3a-a24a-0ccc0587b3d0",
      "id": "CVE-2024-41990",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-41990 does not affect version 5.0.1.post1+tuxcare of django. not_affected \u2014 Django 5.0.1.post3+tuxcare uses a refactored architecture that does not contain the vulnerable code pattern from CVE-2024-41990. The target implementation uses html.unescape() upfront, while the CVE affects a different implementation with repeated rfind() calls that was introduced later in Django 5.0.7."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96accbf3-7dac-5949-9442-2fdf9e016986",
      "id": "CVE-2024-41991",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-41991 affects version 5.0.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:991975e2-0936-5f0e-99b0-6ca5d48fc962",
      "id": "CVE-2024-42005",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-42005 affects version 5.0.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d4ae78e-7a19-53e8-be9b-2b448168670a",
      "id": "CVE-2024-45230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-45230 affects version 5.0.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50dfc149-61ef-5bd0-9c2d-156993910d9e",
      "id": "CVE-2024-45231",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-45231 affects version 5.0.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4c2ca87-a4e3-5528-b240-d74070e64cfd",
      "id": "CVE-2024-53907",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-53907 affects version 5.0.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a8db8a4-a9f6-5c7c-a6d7-2484f4e2d1bb",
      "id": "CVE-2024-53908",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-53908 affects version 5.0.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd1f5548-3366-5178-925a-9db7fdb612bc",
      "id": "CVE-2024-56374",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56374 affects version 5.0.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:945b4019-5948-546c-a384-103e4bade8e6",
      "id": "CVE-2025-13372",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13372 affects version 5.0.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d6b86bf-bdb0-5a8c-bb1b-e3e56a0a28dc",
      "id": "CVE-2025-13473",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-13473 affects version 5.0.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd357d14-34db-54a3-908d-7e16b2be075d",
      "id": "CVE-2025-14550",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-14550 affects version 5.0.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5838405a-0cbd-51c9-96cc-e7d8c430eae4",
      "id": "CVE-2025-26699",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-26699 affects version 5.0.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:660576bd-90f4-50f2-b599-66d307b72962",
      "id": "CVE-2025-27556",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27556 affects version 5.0.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60b31b52-6a44-57b5-b8ad-fdb98a0eda40",
      "id": "CVE-2025-48432",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48432 affects version 5.0.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:715cfe94-ff82-5c0a-97dc-4f7b10910275",
      "id": "CVE-2025-57833",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57833 affects version 5.0.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f84f8010-0db8-5c4d-b052-7c23fe14b26e",
      "id": "CVE-2025-64458",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64458 affects version 5.0.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1898e5c6-d11e-5128-8165-c4bad67ec493",
      "id": "CVE-2025-64459",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64459 affects version 5.0.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63569006-6224-5044-a127-9910a9467116",
      "id": "CVE-2025-64460",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-64460 affects version 5.0.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8001c99f-70a9-5b8c-a246-f03e567d2a3d",
      "id": "CVE-2026-1207",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1207 affects version 5.0.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e9c74b6-ad7d-57c3-be8e-c6b5f105b3da",
      "id": "CVE-2026-1285",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1285 affects version 5.0.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14b2eb1f-fee8-5e12-90ba-23a9788c9947",
      "id": "CVE-2026-1287",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1287 affects version 5.0.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff87666d-e3c7-58d3-98b2-fceb0cda484d",
      "id": "CVE-2026-1312",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-1312 affects version 5.0.1.post1+tuxcare of django."
      },
      "affects": [
        {
          "ref": "pkg:pypi/django@5.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5425462d-9562-56aa-baed-ee5086491137",
      "id": "AIKIDO-2024-10275",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2024-10275 is fixed in version 0.14.4.post1+tuxcare of statsmodels."
      },
      "affects": [
        {
          "ref": "pkg:pypi/statsmodels@0.14.4.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60f15c47-f441-5c8d-abd8-adb6758a8e35",
      "id": "CVE-2023-47627",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-47627 is fixed in version 3.8.5.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae4ef9ba-33c9-5d86-bc91-71d9542f6f89",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-49081 affects version 3.8.5.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a793282a-2da3-5687-b853-fe94fb0f214f",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49082 is fixed in version 3.8.5.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4229ab5-04f3-5fe2-91cc-6dd5ad1fbe0e",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23334 affects version 3.8.5.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:923f4355-aab0-5a90-b38e-8f542b64fce2",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23829 affects version 3.8.5.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81f7b700-9567-5d4b-b7d7-bb89003cf586",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27306 affects version 3.8.5.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b00ca5c-4add-56f9-8585-988cc87fbbea",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-30251 affects version 3.8.5.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e88fad2-0871-5ca2-a00f-42f7ab6efe88",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52304 affects version 3.8.5.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff111d57-1e63-5ee4-ab76-cce8ccba5137",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-53643 affects version 3.8.5.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9172bae-857f-54ee-8ed1-e08f24a1a8db",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.5.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3037add6-af85-54ff-b803-8204a3ee3eff",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.5.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8c3c605-e265-55c8-b698-e4dd03a357dd",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.5.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97c87452-b968-5727-b595-eaec5db19f6d",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.5.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da306470-3fed-5cb8-8326-4661e6fb0a97",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.5.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2dda09f6-86dc-56e6-8682-6bd627e778cf",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.5.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db8158aa-db7a-5b1d-9d0a-265219e3bf39",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.5.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56f88108-b52b-5731-9b12-6bacc4772b89",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.5.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d421bd0c-70b7-5156-ba27-39aae4974a4e",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22815 affects version 3.8.5.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff16e635-209c-519d-a1e8-b9ca538f41f5",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34513 affects version 3.8.5.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f3ef282-5eb4-56a8-8f66-cb75bc93c3fa",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34514 affects version 3.8.5.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4bd93e2-be70-53ef-9d76-ef2dc7f04383",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.5.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a816c51a-c3a1-5da7-80bc-b5ed7409a1d2",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34516 affects version 3.8.5.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88eab6a9-c82e-5983-b0cb-7791d96148b3",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34517 affects version 3.8.5.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d29cd9f3-617d-5623-abd3-663de4842b1a",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34518 affects version 3.8.5.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48dee826-583b-510c-aa42-be704b77bc6d",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34519 affects version 3.8.5.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58dc2989-01e2-59bf-b13a-ec742ecc8e39",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34520 affects version 3.8.5.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d34a8cfe-bd31-5c18-bde4-f6d45f885349",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34525 affects version 3.8.5.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94ea6421-4918-5054-b622-b8b6e6f8962e",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.5.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6dac26b0-b42a-511c-8452-7ec28d2468bc",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.5.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:410e3460-c51c-52f5-919a-ff57c3dd3483",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.5.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39010c8a-be25-598f-a7e9-d76700ea45fd",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.5.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f733e281-f566-523b-a168-46b25901b12d",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.5.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db2f4fcc-08f0-55bf-b3ef-1707a72a9422",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.5.post1+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 does not support the per-request server_hostname parameter feature required to trigger this vulnerability. The server_hostname is always derived from req.host internally, which is already included in the ConnectionKey, preventing incorrect connection reuse."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9dac7ee5-9ace-5cd4-a07c-a3f6317cf56a",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.5.post1+tuxcare of aiohttp. not_affected \u2014 DigestAuthMiddleware component does not exist in aiohttp version 3.8.5. The vulnerable component was introduced 4623 commits later in May 2025. The target version only supports BasicAuth, which already includes cross-origin protection that strips Authorization headers on redirects to different origins."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb0a182a-9395-58ef-ac0e-7c9432f185cc",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.5.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c17ad970-b33e-5467-8e93-2219f44c58f3",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.5.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9656024-8a36-5529-b553-13367ccb5a8e",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.5.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b89614a-c64c-5972-a88e-b15d9a115819",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.5.post1+tuxcare of aiohttp. not_affected \u2014 Version 3.8.5 is not affected by CVE-2026-54280. The vulnerability requires the Payload.close() architecture introduced in aiohttp 3.14+, where write_eof() must explicitly call close() in a try/finally block. Version 3.8.5 uses a fundamentally different pattern: file cleanup is embedded within payload write() methods via try/finally blocks, ensuring resources are released even when transmission..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b2aa6e9-99d3-5dba-836e-5e5a9e5346fa",
      "id": "GHSA-pjjw-qhg8-p2p9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.5.post1+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f78be256-ff26-5f34-bb75-769174a3feca",
      "id": "CVE-2021-41945",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-41945 is fixed in version 0.22.0.post1+tuxcare of httpx."
      },
      "affects": [
        {
          "ref": "pkg:pypi/httpx@0.22.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:261d1362-4110-5e25-ba95-852c0d2e27c7",
      "id": "CVE-2025-47273",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-47273 is fixed in version 75.8.0.post1+tuxcare of setuptools."
      },
      "affects": [
        {
          "ref": "pkg:pypi/setuptools@75.8.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9fe0f94-ec2b-5cd5-9bd7-f60696543f5d",
      "id": "CVE-2026-59890",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59890 affects version 75.8.0.post1+tuxcare of setuptools."
      },
      "affects": [
        {
          "ref": "pkg:pypi/setuptools@75.8.0.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40ee1027-e02e-5916-a455-30fa20125115",
      "id": "CVE-2024-12797",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-12797 is fixed in version 43.0.1.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@43.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5cefba3e-e7e7-5443-98a4-dd5724d95392",
      "id": "CVE-2026-26007",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-26007 affects version 43.0.1.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@43.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80b40d1b-45bb-5609-9b53-acf018bc7320",
      "id": "CVE-2026-34073",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34073 affects version 43.0.1.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@43.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:575a27db-cdc4-5fde-a466-77e3097a7a99",
      "id": "GHSA-537c-gmf6-5ccf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-537c-gmf6-5ccf affects version 43.0.1.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@43.0.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ad86f1b-2f20-5773-8d49-92d8ba0db84c",
      "id": "CVE-2024-3651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-3651 is fixed in version 2.8.post1+tuxcare of idna."
      },
      "affects": [
        {
          "ref": "pkg:pypi/idna@2.8.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:020ab9ae-ed38-51c8-92a8-9beec43e6939",
      "id": "CVE-2026-45409",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45409 affects version 2.8.post1+tuxcare of idna."
      },
      "affects": [
        {
          "ref": "pkg:pypi/idna@2.8.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a594bcc-33a5-52bd-b156-7c739487c26f",
      "id": "CVE-2024-3651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-3651 is fixed in version 2.1.post1+tuxcare of idna."
      },
      "affects": [
        {
          "ref": "pkg:pypi/idna@2.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b49639d-7fee-542a-8d59-7a7edf5cd4b1",
      "id": "CVE-2026-45409",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-45409 affects version 2.1.post1+tuxcare of idna."
      },
      "affects": [
        {
          "ref": "pkg:pypi/idna@2.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e290f622-b5a0-5895-ade5-7e1a18335ee5",
      "id": "CVE-2024-6345",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-6345 is fixed in version 65.5.1.post1+tuxcare of setuptools."
      },
      "affects": [
        {
          "ref": "pkg:pypi/setuptools@65.5.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b2dc2c9-f374-5d84-9cb9-063022cfb3ec",
      "id": "CVE-2025-47273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-47273 affects version 65.5.1.post1+tuxcare of setuptools."
      },
      "affects": [
        {
          "ref": "pkg:pypi/setuptools@65.5.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b665f48-61c4-5991-8f00-1aea3603036c",
      "id": "CVE-2026-59890",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-59890 affects version 65.5.1.post1+tuxcare of setuptools."
      },
      "affects": [
        {
          "ref": "pkg:pypi/setuptools@65.5.1.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06149bbc-abf4-573b-932a-0df215e2030d",
      "id": "CVE-2024-49768",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-49768 is fixed in version 2.1.2.post2+tuxcare of waitress."
      },
      "affects": [
        {
          "ref": "pkg:pypi/waitress@2.1.2.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3bf2e0fb-6732-5040-bb96-4e3974bb3b09",
      "id": "CVE-2024-49769",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-49769 is fixed in version 2.1.2.post2+tuxcare of waitress."
      },
      "affects": [
        {
          "ref": "pkg:pypi/waitress@2.1.2.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b152a23-b0aa-5086-86f7-a64ca5ba94ed",
      "id": "CVE-2025-64439",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64439 is fixed in version 2.1.2.post2+tuxcare of waitress."
      },
      "affects": [
        {
          "ref": "pkg:pypi/waitress@2.1.2.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:436fa77b-20b0-5efe-9204-28e7f45de1ed",
      "id": "CVE-2026-27794",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27794 is fixed in version 2.1.2.post2+tuxcare of waitress."
      },
      "affects": [
        {
          "ref": "pkg:pypi/waitress@2.1.2.post2+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a03648e-db61-54ec-9dc6-066b6aed311a",
      "id": "CVE-2024-49768",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-49768 is fixed in version 2.1.2.post1+tuxcare of waitress."
      },
      "affects": [
        {
          "ref": "pkg:pypi/waitress@2.1.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:296c6cf1-12a9-52ae-a5d9-9c8e0a4b0cf4",
      "id": "CVE-2024-49769",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-49769 affects version 2.1.2.post1+tuxcare of waitress."
      },
      "affects": [
        {
          "ref": "pkg:pypi/waitress@2.1.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa1b6523-f1cc-549d-b5c6-6fdd243aade4",
      "id": "CVE-2025-64439",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-64439 is fixed in version 2.1.2.post1+tuxcare of waitress."
      },
      "affects": [
        {
          "ref": "pkg:pypi/waitress@2.1.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d977d74-1b4f-5995-87c9-df976f9881fc",
      "id": "CVE-2026-27794",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27794 affects version 2.1.2.post1+tuxcare of waitress."
      },
      "affects": [
        {
          "ref": "pkg:pypi/waitress@2.1.2.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3a952dd-aedb-593b-94cc-c57ae347ab68",
      "id": "CVE-2024-12797",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-12797 is fixed in version 43.0.3.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@43.0.3.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b4c9185-1b5d-5732-82b8-42795a1a5a4c",
      "id": "CVE-2026-26007",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-26007 affects version 43.0.3.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@43.0.3.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:862dc9dc-42c3-5cc1-ae39-375566e89c35",
      "id": "CVE-2026-34073",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34073 affects version 43.0.3.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@43.0.3.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52888de3-6139-5757-8c8a-9a21964d88c0",
      "id": "GHSA-537c-gmf6-5ccf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-537c-gmf6-5ccf affects version 43.0.3.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@43.0.3.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e8de730-2d29-5081-82d7-fa98246e8466",
      "id": "CVE-2024-12797",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-12797 is fixed in version 42.0.8.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@42.0.8.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4cf85982-8206-5647-ae69-af58486b0661",
      "id": "CVE-2026-26007",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-26007 affects version 42.0.8.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@42.0.8.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba370924-504c-5067-a6d4-f6646938200d",
      "id": "CVE-2026-34073",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34073 affects version 42.0.8.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@42.0.8.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51741a0b-e33c-5341-9b29-4e9876ab916f",
      "id": "GHSA-537c-gmf6-5ccf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-537c-gmf6-5ccf affects version 42.0.8.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@42.0.8.post1+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18a0d747-71da-5acd-bd27-835045acc413",
      "id": "GHSA-h4gh-qq45-vh27",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-h4gh-qq45-vh27 is fixed in version 42.0.8.post1+tuxcare of cryptography."
      },
      "affects": [
        {
          "ref": "pkg:pypi/cryptography@42.0.8.post1+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/aiohttp@3.8.6.post7+tuxcare"
    },
    {
      "ref": "pkg:pypi/aiohttp@3.8.4.post5+tuxcare"
    },
    {
      "ref": "pkg:pypi/aiohttp@3.8.1.post11+tuxcare"
    },
    {
      "ref": "pkg:pypi/tornado@6.1.0.post5+tuxcare"
    },
    {
      "ref": "pkg:pypi/django@4.0.post7+tuxcare"
    },
    {
      "ref": "pkg:pypi/dulwich@0.25.2.post6+tuxcare"
    },
    {
      "ref": "pkg:pypi/cryptography@43.0.3.post3+tuxcare"
    },
    {
      "ref": "pkg:pypi/gitpython@3.1.31.post3+tuxcare"
    },
    {
      "ref": "pkg:pypi/gitpython@3.1.31.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/starlette@0.27.0.post6+tuxcare"
    },
    {
      "ref": "pkg:pypi/pypdf@5.9.0.post11+tuxcare"
    },
    {
      "ref": "pkg:pypi/transformers@4.57.6.post3+tuxcare"
    },
    {
      "ref": "pkg:pypi/python-multipart@0.0.6.post6+tuxcare"
    },
    {
      "ref": "pkg:pypi/mlflow@2.22.4.post6+tuxcare"
    },
    {
      "ref": "pkg:pypi/cryptography@44.0.3.post3+tuxcare"
    },
    {
      "ref": "pkg:pypi/langgraph-checkpoint@2.1.2.post3+tuxcare"
    },
    {
      "ref": "pkg:pypi/pypdf@5.9.0.post10+tuxcare"
    },
    {
      "ref": "pkg:pypi/transformers@4.57.6.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/mlflow@2.22.4.post5+tuxcare"
    },
    {
      "ref": "pkg:pypi/pypdf@5.9.0.post9+tuxcare"
    },
    {
      "ref": "pkg:pypi/tornado@6.1.0.post4+tuxcare"
    },
    {
      "ref": "pkg:pypi/dulwich@0.25.2.post5+tuxcare"
    },
    {
      "ref": "pkg:pypi/pyjwt@2.10.1.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/python-multipart@0.0.6.post5+tuxcare"
    },
    {
      "ref": "pkg:pypi/pypdf@5.9.0.post8+tuxcare"
    },
    {
      "ref": "pkg:pypi/starlette@0.27.0.post5+tuxcare"
    },
    {
      "ref": "pkg:pypi/urllib3@1.25.11.post6+tuxcare"
    },
    {
      "ref": "pkg:pypi/pypdf@5.9.0.post7+tuxcare"
    },
    {
      "ref": "pkg:pypi/starlette@0.27.0.post4+tuxcare"
    },
    {
      "ref": "pkg:pypi/python-multipart@0.0.6.post4+tuxcare"
    },
    {
      "ref": "pkg:pypi/gunicorn@20.1.0.post3+tuxcare"
    },
    {
      "ref": "pkg:pypi/cryptography@44.0.3.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/gunicorn@23.0.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/cryptography@46.0.7.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/pillow@11.3.0.post3+tuxcare"
    },
    {
      "ref": "pkg:pypi/werkzeug@2.3.8.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/urllib3@1.26.20.post4+tuxcare"
    },
    {
      "ref": "pkg:pypi/virtualenv@20.39.1.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/aiohttp@3.8.6.post6+tuxcare"
    },
    {
      "ref": "pkg:pypi/tornado@6.1.0.post3+tuxcare"
    },
    {
      "ref": "pkg:pypi/pillow@11.2.1.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/pypdf@5.9.0.post6+tuxcare"
    },
    {
      "ref": "pkg:pypi/paramiko@3.0.0.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/langchain-core@0.3.83.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/python-multipart@0.0.6.post3+tuxcare"
    },
    {
      "ref": "pkg:pypi/dulwich@0.25.2.post4+tuxcare"
    },
    {
      "ref": "pkg:pypi/requests@2.31.0.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/pypdf@5.9.0.post5+tuxcare"
    },
    {
      "ref": "pkg:pypi/dulwich@0.25.2.post3+tuxcare"
    },
    {
      "ref": "pkg:pypi/aiohttp@3.8.5.post9+tuxcare"
    },
    {
      "ref": "pkg:pypi/requests@2.30.0.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/cryptography@45.0.7.post3+tuxcare"
    },
    {
      "ref": "pkg:pypi/numpy@1.21.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/deepdiff@6.2.3.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/flask-cors@4.0.2.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/fastmcp@2.14.7.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/starlette@0.13.6.post3+tuxcare"
    },
    {
      "ref": "pkg:pypi/starlette@0.27.0.post3+tuxcare"
    },
    {
      "ref": "pkg:pypi/dulwich@0.25.2.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/langgraph-checkpoint@2.1.2.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/mlflow@2.22.4.post4+tuxcare"
    },
    {
      "ref": "pkg:pypi/requests@2.32.3.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/mlflow@2.9.1.post4+tuxcare"
    },
    {
      "ref": "pkg:pypi/mlflow@2.22.4.post3+tuxcare"
    },
    {
      "ref": "pkg:pypi/aiohttp@3.8.1.post10+tuxcare"
    },
    {
      "ref": "pkg:pypi/aiohttp@3.8.6.post5+tuxcare"
    },
    {
      "ref": "pkg:pypi/mlflow@2.9.1.post3+tuxcare"
    },
    {
      "ref": "pkg:pypi/aiohttp@3.8.5.post8+tuxcare"
    },
    {
      "ref": "pkg:pypi/aiohttp@3.8.4.post4+tuxcare"
    },
    {
      "ref": "pkg:pypi/aiohttp@3.8.1.post9+tuxcare"
    },
    {
      "ref": "pkg:pypi/aiohttp@3.8.4.post3+tuxcare"
    },
    {
      "ref": "pkg:pypi/aiohttp@3.8.5.post7+tuxcare"
    },
    {
      "ref": "pkg:pypi/dulwich@0.25.2.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/apache-airflow-providers-http@4.13.3.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/langgraph-checkpoint@2.1.2.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/langchain-text-splitters@0.3.11.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/lxml@5.4.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/lxml@4.9.4.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/transformers@4.57.6.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/pyarrow@12.0.1.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/pytest@7.4.4.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/pytest@8.4.2.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/keras@2.15.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/fastmcp@2.14.7.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/pypdf@5.9.0.post4+tuxcare"
    },
    {
      "ref": "pkg:pypi/pillow@11.3.0.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/cryptography@45.0.7.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/aiohttp@3.8.1.post8+tuxcare"
    },
    {
      "ref": "pkg:pypi/aiohttp@3.8.5.post6+tuxcare"
    },
    {
      "ref": "pkg:pypi/aiohttp@3.8.5.post5+tuxcare"
    },
    {
      "ref": "pkg:pypi/aiohttp@3.8.4.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/urllib3@1.25.11.post5+tuxcare"
    },
    {
      "ref": "pkg:pypi/aiohttp@3.8.6.post4+tuxcare"
    },
    {
      "ref": "pkg:pypi/pillow@10.4.0.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/lightgbm@3.3.5.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/aiohttp@3.8.6.post3+tuxcare"
    },
    {
      "ref": "pkg:pypi/tornado@6.1.0.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/pyopenssl@24.3.0.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/google-cloud-storage@2.19.0.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/langchain-core@0.3.83.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/pyopenssl@25.3.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/pyopenssl@24.3.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/pyopenssl@23.3.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/mlflow@2.9.1.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/mlflow@2.22.4.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/pyjwt@1.7.1.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/setuptools@59.8.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/pillow@11.3.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/pillow@10.4.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/tornado@5.1.1.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/mlflow@2.9.1.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/fastmcp@2.14.5.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/cryptography@43.0.3.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/cryptography@44.0.3.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/cryptography@41.0.7.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/cryptography@45.0.7.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/cryptography@42.0.8.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
    },
    {
      "ref": "pkg:pypi/werkzeug@2.2.3.post4+tuxcare"
    },
    {
      "ref": "pkg:pypi/werkzeug@1.0.1.post4+tuxcare"
    },
    {
      "ref": "pkg:pypi/aiohttp@3.8.1.post6+tuxcare"
    },
    {
      "ref": "pkg:pypi/aiohttp@3.8.1.post5+tuxcare"
    },
    {
      "ref": "pkg:pypi/pip@9.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/werkzeug@2.3.8.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/certifi@2022.12.7.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/pillow@9.4.0.post3+tuxcare"
    },
    {
      "ref": "pkg:pypi/certifi@2021.10.8.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/werkzeug@2.2.3.post3+tuxcare"
    },
    {
      "ref": "pkg:pypi/gunicorn@20.1.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/gunicorn@20.0.4.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/requests@2.32.3.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/gunicorn@21.2.0.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/anyio@3.7.1.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/gunicorn@21.2.0.post3+tuxcare"
    },
    {
      "ref": "pkg:pypi/requests@2.25.1.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/requests@2.31.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/requests@2.30.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/gunicorn@20.1.0.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/gunicorn@22.0.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/tornado@6.1.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/pymongo@3.13.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/pdfkit@0.6.1.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/jaraco-context@5.3.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/pillow@9.5.0.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/jinja2@2.11.3.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/jinja2@3.0.3.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/pillow@8.4.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/jinja2@2.11.3.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/flask@1.1.4.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/flask@2.2.1.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/pillow@9.4.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/werkzeug@1.0.1.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/pillow@9.5.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/werkzeug@1.0.1.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/gunicorn@20.0.4.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/werkzeug@1.0.1.post3+tuxcare"
    },
    {
      "ref": "pkg:pypi/pillow@9.4.0.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/werkzeug@2.2.3.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/pillow@11.2.1.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/flask@1.1.2.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/flask@0.12.5.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/certifi@2022.12.7.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/cryptography@3.4.8.post5+tuxcare"
    },
    {
      "ref": "pkg:pypi/cryptography@3.4.8.post4+tuxcare"
    },
    {
      "ref": "pkg:pypi/cryptography@3.4.8.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/cryptography@3.4.8.post3+tuxcare"
    },
    {
      "ref": "pkg:pypi/certifi@2021.10.8.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/cryptography@3.4.8.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/certifi@2023.7.22.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/py@1.11.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/aiohttp@3.8.6.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/mlflow@2.22.4.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/protobuf@4.25.8.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/urllib3@1.26.20.post3+tuxcare"
    },
    {
      "ref": "pkg:pypi/celery@4.4.7.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/aiohttp@3.8.1.post4+tuxcare"
    },
    {
      "ref": "pkg:pypi/aiohttp@3.8.6.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/protobuf@3.17.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/python-jose@3.3.0.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/urllib3@1.25.11.post4+tuxcare"
    },
    {
      "ref": "pkg:pypi/python-multipart@0.0.6.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/urllib3@1.26.4.post4+tuxcare"
    },
    {
      "ref": "pkg:pypi/aiohttp@3.8.5.post4+tuxcare"
    },
    {
      "ref": "pkg:pypi/starlette@0.13.6.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/pymysql@0.10.1.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
    },
    {
      "ref": "pkg:pypi/django@3.2.25.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/urllib3@1.26.4.post3+tuxcare"
    },
    {
      "ref": "pkg:pypi/urllib3@1.25.11.post3+tuxcare"
    },
    {
      "ref": "pkg:pypi/aiohttp@3.8.1.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/scikit-learn@1.0.2.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/urllib3@1.26.20.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/aiohttp@3.8.5.post3+tuxcare"
    },
    {
      "ref": "pkg:pypi/h11@0.9.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/urllib3@2.0.7.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/numpy@1.16.0.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/pypdf@5.9.0.post3+tuxcare"
    },
    {
      "ref": "pkg:pypi/pyyaml@3.13.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/sentence-transformers@2.7.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/mysql-connector-python@8.4.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/pyjwt@1.7.1.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/pypdf@5.9.0.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/starlette@0.13.6.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/websockets@8.1.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/starlette@0.27.0.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/urllib3@1.26.4.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/idna@2.10.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/statsmodels@0.14.5.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/torch@1.13.1.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/pyyaml@5.3.1.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/twisted@20.3.0.post4+tuxcare"
    },
    {
      "ref": "pkg:pypi/django@5.1.post3+tuxcare"
    },
    {
      "ref": "pkg:pypi/protobuf@4.24.3.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/django@4.2.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/django@4.0.post6+tuxcare"
    },
    {
      "ref": "pkg:pypi/django@5.1.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/django@4.0.post5+tuxcare"
    },
    {
      "ref": "pkg:pypi/urllib3@1.26.4.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/torch@1.13.1.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/urllib3@1.25.11.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/numpy@1.15.4.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/setuptools@68.0.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/setuptools@75.0.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/setuptools@70.3.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/cryptography@41.0.7.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/pypdf@5.9.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/django@3.2.25.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/flask-cors@4.0.2.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/urllib3@1.26.20.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/django@5.0.post5+tuxcare"
    },
    {
      "ref": "pkg:pypi/cryptography@42.0.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/gitpython@3.1.31.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/python-jose@3.3.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/orjson@3.8.5.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/redis@4.5.1.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/idna@3.6.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/tqdm@4.66.1.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/python-multipart@0.0.6.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/paramiko@3.0.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/piexif@1.1.3.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/deepdiff@6.2.3.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/pydantic@v1.10.5.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/django@4.0.post4+tuxcare"
    },
    {
      "ref": "pkg:pypi/dnspython@2.3.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/django@5.0.post4+tuxcare"
    },
    {
      "ref": "pkg:pypi/django@5.0.post3+tuxcare"
    },
    {
      "ref": "pkg:pypi/pandas@2.2.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/django@5.0.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/pyjwt@2.10.1.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/django@5.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/starlette@0.27.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/django@4.0.post3+tuxcare"
    },
    {
      "ref": "pkg:pypi/django@5.0.1.post3+tuxcare"
    },
    {
      "ref": "pkg:pypi/pyjwt@2.3.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/pyjwt@2.8.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/django@5.0.1.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/celery@v5.1.2.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/django@5.1.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/django@4.0.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/aiohttp@3.8.1.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/pandas@2.2.2.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/django@4.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/fastapi@0.104.1.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/future@1.0.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/uvicorn@0.11.6.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/numpy@1.15.4.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/fastapi@0.63.0.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/fastapi@0.63.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/django@5.1.4.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/django@5.1.9.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/django@5.0.2.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/numpy@1.16.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/aiohttp@3.8.5.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/aiohttp@3.8.4.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/django@5.0.1.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/statsmodels@0.14.4.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/aiohttp@3.8.5.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/httpx@0.22.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/setuptools@75.8.0.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/cryptography@43.0.1.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/idna@2.8.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/idna@2.1.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/setuptools@65.5.1.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/waitress@2.1.2.post2+tuxcare"
    },
    {
      "ref": "pkg:pypi/waitress@2.1.2.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/cryptography@43.0.3.post1+tuxcare"
    },
    {
      "ref": "pkg:pypi/cryptography@42.0.8.post1+tuxcare"
    }
  ]
}