{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:0c6dd538-aae0-5c12-96c0-fbf1ba9054d4",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.1.post3+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:f561711f-cffd-511d-8e85-193a2c2c3458",
      "id": "CVE-2022-33124",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-33124 is a false positive for aiohttp 3.8.1.post3+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f27f48b-e34e-5fe9-af6f-b9ce927a6d1b",
      "id": "CVE-2023-37276",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-37276 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5566c92e-0217-51bc-848f-b2cf1cbf0143",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49081 is fixed in version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd21f0c3-4aea-5994-beec-b719ecf919fd",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-49082 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c41c94ed-f2d7-5a7d-afa3-4a43ed19eb61",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23334 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f48496e0-8199-55fb-8e1f-f16b11cea9b0",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23829 is fixed in version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79b9b3c5-4d21-5320-ba95-0914aef791f7",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27306 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4376f3c2-813d-5141-8575-b70e9ed3956d",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-30251 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9af1bc88-9396-5c1f-8258-8fedeeedc9b5",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52304 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97f30527-f2c9-5cfd-af79-e62b5e29ef88",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-53643 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c9e36f3-7432-51d4-ba3b-fd51dd9c3ac6",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12223501-79fa-5573-826c-e5d965778731",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6cb52fc4-3e95-50ef-abf2-9450a4885f4f",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a222ba27-7161-5155-a1d8-1e19ce531f55",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73b54f12-833b-5e14-a264-2cc786aaea2c",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30a51f83-a348-58a3-9cff-dfa083afaa9d",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc29a11b-08dd-5ddf-b68b-fc42fc4f0261",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0af739b-a06b-5cc2-bc9b-a65578fcd0a9",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89b9c61a-3822-5bb4-b202-0594e6e8ebd7",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22815 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e889c1a-b78b-5c36-9c63-f5858595dfd3",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34513 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:073c16ba-318b-57f1-80af-a82dfabd6033",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34514 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44bf6f39-0104-5c9a-b207-c4ea32010f32",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d295fa7-a486-5d2b-9098-b61ff9871c4a",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34516 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86e1a292-07ae-560a-8fd7-7b6f0cc83082",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34517 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb1b6a15-f93a-56ae-8724-3736c30793df",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34518 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56ced25a-756b-5c1d-a6b7-6304e7356e7a",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34519 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d701cbf-8646-5c40-b220-021223992bb0",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34520 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34c3421a-c5da-5567-8acb-b15f5116b5cf",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34525 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67b0619b-f376-5f34-9003-9af108c1a616",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04e18713-c5b5-5950-9a9f-9c78e743018d",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:700bfe3e-c16d-5225-862d-6d19aa49114e",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b01e683e-b094-5695-8075-642961450132",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4cc08478-9e01-5bf6-8937-ea876ed6c706",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b4190cd-68bd-5f5a-80e3-6864246a9556",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.1.post3+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f9ccc90-75fc-52ea-b414-6a96260ad36a",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.1.post3+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02a9921e-9e08-523e-a3cd-711fca0d5812",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9dfb0767-39c9-5853-8866-2682029fee81",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96166790-d8da-5c7b-9db7-203fb1c02375",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f68bd78-bd5d-58a8-9327-bc9d5200c09a",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.1.post3+tuxcare of aiohttp. CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe"
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89a9fe06-1e4d-5ab7-af40-43293624c872",
      "id": "GHSA-pjjw-qhg8-p2p9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.1.post3+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/aiohttp@3.8.1.post3+tuxcare"
    }
  ]
}