{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:9f47cb44-85a4-5f62-b91c-3c6e0a59cdcb",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.1.post12+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:54df27ee-2651-5c62-a0d2-1007dcf7483b",
      "id": "CVE-2022-33124",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-33124 is a false positive for aiohttp 3.8.1.post12+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb1dfb38-e383-509e-9262-448d593ee873",
      "id": "CVE-2023-37276",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-37276 is fixed in version 3.8.1.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:386c6a24-8a73-5949-b958-01c623634457",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49081 is fixed in version 3.8.1.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c399d8e-a0cc-5245-86a6-54fded3cf091",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49082 is fixed in version 3.8.1.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d98d4a8-248d-5c8d-b18a-106c0f4f00f9",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23334 is fixed in version 3.8.1.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52055546-dcce-51a1-8df8-d48a717157fe",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23829 is fixed in version 3.8.1.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ceefc657-e5ce-58c1-8944-236a6b0ee8f4",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-27306 is fixed in version 3.8.1.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc3a5e10-6600-554f-9253-7f3fc381ad27",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-30251 is fixed in version 3.8.1.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10edcceb-f4a8-5264-a839-8c92db46334b",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52304 is fixed in version 3.8.1.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0baeef1d-e2f7-5ee3-9e45-4990a1e87f41",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53643 is fixed in version 3.8.1.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a1de733-78c2-5c66-8615-d0a1ebe187d9",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.1.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26d30cbc-6e07-5c3c-bb94-8730e14b23bc",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.1.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef1102a6-b4c3-5560-9362-611fda8cee13",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.1.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff404746-7120-5f83-9cb5-107ff2741feb",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.1.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7cd2e81b-88be-5c87-be71-44b389eb085d",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.1.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ccbf16d3-a2af-5157-bee1-e4b406ca74f7",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.1.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8b42c31-1c6f-5374-b6fb-d24e7e54370e",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.1.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b661c7b2-2207-563d-b32d-afb7b44e6286",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.1.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:260ceb50-e2ab-58e1-91b8-f6dd659d532f",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22815 is fixed in version 3.8.1.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d396ea8b-892c-5d4e-b42c-c18a028676a3",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34513 is fixed in version 3.8.1.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26443a97-a133-5291-8369-a5dba3f866d8",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34514 is fixed in version 3.8.1.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ecd5a4e3-ee4d-5694-8f09-39e41dca79ba",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.1.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:defd4db8-c156-5237-ae01-e97a206c9367",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34516 is fixed in version 3.8.1.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d29f446b-7d82-5443-b5a7-17aae5ba1b88",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34517 is fixed in version 3.8.1.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b08c8ff-fdb1-56c0-8856-f3d9b137fae7",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34518 is fixed in version 3.8.1.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c81f8cb4-6789-523f-a87c-6c531cf0a98d",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34519 is fixed in version 3.8.1.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a51ff386-d5a9-53db-9e2e-98f8456a1d9a",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34520 is fixed in version 3.8.1.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5301d672-e379-5d9f-a706-61e14f86919f",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34525 is fixed in version 3.8.1.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0de9c80-2f2c-5b3c-af88-e4bf8c1c0e91",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.1.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:761638c5-b2b1-529f-b737-927dceb06f6d",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.1.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:681483a3-73c5-5922-b18a-7a9c6c62741e",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.1.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35599a1b-ebd9-59a5-ad1e-17e1d469d531",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.1.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa14204a-21cc-5186-aeab-f3a9d592a989",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.1.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b77b9836-f3ec-52a5-96be-ac9090f09f69",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.1.post12+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2153fa13-3134-5e20-9e8e-e6538c3e9251",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.1.post12+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7be2b9e-3e5a-5fdb-bf35-c764de9d1395",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.1.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da671887-a50f-5c36-b66f-3d81d00a9784",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.1.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd811019-a8c7-5759-bfa3-647b69d64782",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.1.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36bdcc93-1eb0-5407-bd36-f6c10cf49ee6",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.1.post12+tuxcare of aiohttp. CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe"
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62d99978-a4fc-5b0c-a519-f1dce39aae9d",
      "id": "CVE-2026-59881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59881 is fixed in version 3.8.1.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c220670e-6aab-536a-84c2-1286d06ffb6c",
      "id": "CVE-2026-69243",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69243 affects version 3.8.1.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f772fc98-623b-59d5-9317-0b0edc5e905a",
      "id": "CVE-2026-69244",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-69244 does not affect version 3.8.1.post12+tuxcare of aiohttp. not_affected \u2014 Version 3.8.1 is not affected by CVE-2026-69244. The vulnerability exists in aiohttp 3.14+ where the C parser constructs detailed error messages with buffer snippets using llhttp_get_error_pos() followed by .split() on a raw pointer, causing out-of-bounds heap reads. Version 3.8.1 uses a simpler error reporting mechanism that only calls llhttp_get_error_reason() to get static error strings - it..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1001544f-1d35-53b7-b466-bfcc6875e234",
      "id": "GHSA-pjjw-qhg8-p2p9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-pjjw-qhg8-p2p9 is fixed in version 3.8.1.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/aiohttp@3.8.1.post12+tuxcare"
    }
  ]
}