{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:251eefaa-d839-5fd1-b655-148a5327d428",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.1.post13+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:016e5df9-8b0d-53cc-a607-50940285344e",
      "id": "CVE-2022-33124",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-33124 is a false positive for aiohttp 3.8.1.post13+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1143eb51-62d6-570d-87ae-7ca437fdb6dc",
      "id": "CVE-2023-37276",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-37276 is fixed in version 3.8.1.post13+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04eecfb4-0084-568f-baaf-8c0484b29e41",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49081 is fixed in version 3.8.1.post13+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbe4a9b9-b0cf-5ba4-a0c8-f02b82f0d362",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49082 is fixed in version 3.8.1.post13+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca0ce8e7-f4a2-5e0c-8a2b-c9c65b2b2bd9",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23334 is fixed in version 3.8.1.post13+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:909e3c8c-5779-505a-ae9f-f62f44be4d19",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23829 is fixed in version 3.8.1.post13+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81372650-747f-5807-8f05-a5ed19281c0f",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-27306 is fixed in version 3.8.1.post13+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f04dfcf7-f29f-5a75-b5e4-ffc14e0e1d91",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-30251 is fixed in version 3.8.1.post13+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:404717e3-2796-528c-b406-b417e5c1d3a6",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52304 is fixed in version 3.8.1.post13+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50cf2de9-a43a-52cc-9739-fc2fc6b1b96a",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53643 is fixed in version 3.8.1.post13+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7b2f7d9-6e60-5d30-9858-426a322ac814",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.1.post13+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcc914a9-7fe2-5c46-acaa-784394d9944f",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69224 is fixed in version 3.8.1.post13+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afbfa1e8-2ab7-5cbe-a241-551ca56e7cb9",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69225 is fixed in version 3.8.1.post13+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc634fbb-5eb3-5f92-9335-2bb3e2876c2a",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.1.post13+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b1076bd-6b2b-52e8-a321-a181407a7bca",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69227 is fixed in version 3.8.1.post13+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c3bd67c-0d2b-5424-bafc-7f064141f4bb",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69228 is fixed in version 3.8.1.post13+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd81a241-0293-5db1-a363-200e4ba367f1",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69229 is fixed in version 3.8.1.post13+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29823ebd-9408-5651-816f-affa769f5e71",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.1.post13+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3010a80a-aaea-5bae-906f-183a0211a464",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22815 is fixed in version 3.8.1.post13+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92d944bd-cd7c-5f55-8156-e69e30db399e",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34513 is fixed in version 3.8.1.post13+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8861f02-9061-5470-b2da-de23ff54762c",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34514 is fixed in version 3.8.1.post13+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d6b9ba8-8092-5662-afb6-76efc94c16f3",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.1.post13+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a16c89d-602c-556e-a3e7-09367aef868c",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34516 is fixed in version 3.8.1.post13+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c0dd06e-a850-5e2e-868c-fa52dcef0c32",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34517 is fixed in version 3.8.1.post13+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b94c2087-9203-54fb-a239-589d76901a75",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34518 is fixed in version 3.8.1.post13+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ccabbf04-f37c-5dc3-928e-6e1e5fee1f07",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34519 is fixed in version 3.8.1.post13+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1be7924a-3bb8-5c36-9c48-365ea4f4ddc4",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34520 is fixed in version 3.8.1.post13+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88f67219-12e2-5a73-b8cd-392c0d1bd123",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34525 is fixed in version 3.8.1.post13+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:adfeccd3-4f39-5954-8f3b-60a3cbd7bb15",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.1.post13+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:667ce586-c1a3-5188-8924-f0890008129b",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.1.post13+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20f80777-6a8f-5c46-ab37-ff3b387b89da",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.1.post13+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97c030d0-3c5d-552b-ab93-b207307f0598",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.1.post13+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0390a16f-3f2e-5256-85fe-8c791960df67",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.1.post13+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95c869d4-4c69-57a2-951b-6bae413a1291",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.1.post13+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01bc9612-5e2c-5e11-bbc8-e007e280dcb2",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.1.post13+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc7f6426-10de-578d-8482-5899c72ee797",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.1.post13+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ecd0eda6-77c7-577c-a8d1-8e647d04c968",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.1.post13+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:516df9e1-dcdb-58ba-b235-a57ffa72418c",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.1.post13+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65ac75df-1413-5a4a-9751-9455703e3911",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.1.post13+tuxcare of aiohttp. CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe"
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66e9e9fb-cefa-51f8-a173-8ecf73133f0f",
      "id": "CVE-2026-59881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59881 is fixed in version 3.8.1.post13+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bbf31fa-442a-5f7c-b46e-7ee7b7b3949a",
      "id": "CVE-2026-69243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69243 is fixed in version 3.8.1.post13+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:064c8386-d631-5a02-a03b-7c5b8488e3ad",
      "id": "CVE-2026-69244",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-69244 does not affect version 3.8.1.post13+tuxcare of aiohttp. not_affected \u2014 Version 3.8.1 is not affected by CVE-2026-69244. The vulnerability exists in aiohttp 3.14+ where the C parser constructs detailed error messages with buffer snippets using llhttp_get_error_pos() followed by .split() on a raw pointer, causing out-of-bounds heap reads. Version 3.8.1 uses a simpler error reporting mechanism that only calls llhttp_get_error_reason() to get static error strings - it..."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29f90e7d-eab3-596d-bb7a-9dcf0ef01fec",
      "id": "GHSA-pjjw-qhg8-p2p9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-pjjw-qhg8-p2p9 is fixed in version 3.8.1.post13+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/aiohttp@3.8.1.post13+tuxcare"
    }
  ]
}