{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:817901db-4906-59d8-8039-98b4a5fb8e85",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.4.post8+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:fedef24a-850f-51f0-b376-46bb4facf35b",
      "id": "CVE-2023-37276",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-37276 is fixed in version 3.8.4.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b45c8dd-bfff-5d6a-aedd-6cb697a6895c",
      "id": "CVE-2023-47627",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-47627 affects version 3.8.4.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4cb571d0-facf-5422-881b-c303dfa4db73",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49081 is fixed in version 3.8.4.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d1e92cc-6d55-5ca8-8c07-a4c76e23d7c0",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-49082 affects version 3.8.4.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b540279-e6e7-5497-ad8a-73bcf93b5f97",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23334 is fixed in version 3.8.4.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b76117b2-63f9-5966-b242-0ccc7c5c72ed",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23829 affects version 3.8.4.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ee9f056-0d4b-5c14-9cda-efba79d448eb",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-27306 is fixed in version 3.8.4.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8baa6bc3-8854-53a1-b3e3-4f7f65620267",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-30251 is fixed in version 3.8.4.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9cf5e52-9275-5462-afae-d700cab6fc0a",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52304 is fixed in version 3.8.4.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d736781-3ab5-5389-bf85-e11838afb3e3",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-53643 affects version 3.8.4.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0351f25-7f8d-55ef-bbaf-e4da535a2e94",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.4.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a34d64d7-9807-5ca4-8aad-57ae2bddc1c7",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69224 is fixed in version 3.8.4.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4e6d36c-b8b8-5058-9008-42b8c49a0282",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69225 is fixed in version 3.8.4.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6db8bd58-55eb-5a15-9438-fcb30796834f",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.4.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa6bd4ae-5792-5c1c-9725-4a5794ca588d",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69227 is fixed in version 3.8.4.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a44c00aa-a70c-5a7c-85bf-298030ac96a2",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69228 is fixed in version 3.8.4.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1525ec9d-817a-51f3-b66f-35df35801b21",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69229 is fixed in version 3.8.4.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6fc86848-94ba-5fdb-84f3-51aa5004ef5a",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.4.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51e74855-de26-5e29-afcd-491a5775027a",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22815 is fixed in version 3.8.4.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9593f61-389e-519a-a7ba-360392181dd4",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34513 is fixed in version 3.8.4.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:059b2323-6f84-5783-8c99-82968af80467",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34514 is fixed in version 3.8.4.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:904bf5ef-c35e-5eb3-a0b8-743262ca6740",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34515 is fixed in version 3.8.4.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:851bbaf9-cf16-5391-be86-9fcf175a9a49",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34516 is fixed in version 3.8.4.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48639f86-8b55-5904-b038-dbb87b2f1da3",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34517 is fixed in version 3.8.4.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef2f5a47-c6b5-5fe2-91f4-cedd56ddddad",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34518 is fixed in version 3.8.4.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c246bed-52f9-57ff-81f6-c937f1ccfdb3",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34519 is fixed in version 3.8.4.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef8dc56b-62b2-55c6-9240-8534b0519e08",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34520 is fixed in version 3.8.4.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a46ead3f-4f7f-5b49-b013-74c346a8bbe0",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34525 affects version 3.8.4.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a072c11-86be-52e1-8a00-a84f6a0e1f86",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.4.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d05b169d-944c-58cb-844b-1ac6e2ac15bd",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47265 is fixed in version 3.8.4.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69fc1c44-561c-57e9-80ca-e3acba18fc71",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.4.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4baa6ce5-bb1b-5443-8cf3-e50eb64c1c73",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.4.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c01bf1c4-92f6-5596-bc15-2550e1bf3c6a",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.4.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a17ef4db-9ce6-567e-acec-e482ea66be4e",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.4.post8+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.4.post4+tuxcare. The vulnerability requires the server_hostname parameter feature, which was not added until version 3.9.0+ (August 2023), six months after version 3.8.4 was released (February 2023). The target version cannot receive the malicious input described in the CVE."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:725e96a5-a9b5-5744-bf75-baf5cc8191c2",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.4.post8+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.4.post4+tuxcare) does not contain the DigestAuthMiddleware component. This feature was introduced in aiohttp version 3.12, which postdates the target version. The vulnerability cannot manifest because the affected code does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35cc3046-514a-5bd7-966e-8267c02270a3",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.4.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07ec3556-3db4-5a1a-9868-67992f19ebf9",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.4.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60f2c422-528a-5615-ad53-54645c223f52",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.4.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:293753f5-4f49-507e-b024-200d3fc6850d",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54280 is fixed in version 3.8.4.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1272451d-ba04-5b91-b91d-1253e28a8c05",
      "id": "CVE-2026-59881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59881 is fixed in version 3.8.4.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff3e0473-5b26-5125-98d5-e8df31e3a7cb",
      "id": "CVE-2026-69243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69243 is fixed in version 3.8.4.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9a623d8-554a-5392-a149-1524b3e6366b",
      "id": "CVE-2026-69244",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-69244 does not affect version 3.8.4.post8+tuxcare of aiohttp. not_affected \u2014 reassessed 2026-09-09 (PYELS-169). CVE-2026-69244 is an out-of-bounds heap read in the C response parser's error-snippet builder: it slices from llhttp_get_error_pos() as a NUL-terminated C string (upstream fix 49f65d54, PR #13223). That snippet code was introduced in aiohttp 3.8.5 (v3.8.4..v3.8.5 diff of _http_parser.pyx), not 3.9.0 as previously stated. tuxcare-current/3.8.4 calls parser_error_from_errno(self._cparser) with no snippet and never reads through the error position, so the vulnerable code is not present. Note: the CVE's regression tests rely on llhttp 9 rejecting bare-CR chunk framing; 3.8.4 still vendors llhttp 8.1.1, which accepts `0\\rX\\r\\n` as a chunk-size line (probed on the shipped 3.8.4.post8 wheel) \u2014 that is a separate hardening item (llhttp 9.1.3 bump, done on 3.8.5 in MR !133), not this CVE."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31b15d3a-4f19-59a0-b428-a4b26cef0c22",
      "id": "GHSA-pjjw-qhg8-p2p9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-pjjw-qhg8-p2p9 affects version 3.8.4.post8+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/aiohttp@3.8.4.post8+tuxcare"
    }
  ]
}