{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4bda4734-84b8-54a1-be8c-8f36280ded51",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.6.post12+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:b3b4af8d-c70d-5120-b82b-016aed8d8809",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49081 is fixed in version 3.8.6.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f8dfe03-6620-552d-a812-f94a6b7f6c3b",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49082 is fixed in version 3.8.6.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca6ae757-43bd-510b-bf21-d67dc409152f",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23334 is fixed in version 3.8.6.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdd53753-7d0c-53f1-9522-4bf0a7b3eecf",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23829 is fixed in version 3.8.6.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce0ffb8d-f196-5e71-9026-f957456c9bcb",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-27306 is fixed in version 3.8.6.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c743dd0-07ea-5d42-a1ae-8b0a053be17a",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-30251 is fixed in version 3.8.6.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:184fad2a-4781-5f42-a300-ea5b5cae17cd",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52304 affects version 3.8.6.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebaf7607-7f58-53f8-9e90-aa36892cadd5",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53643 is fixed in version 3.8.6.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96db9e7d-6420-556e-9b02-fb82d29f7e7a",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.6.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7918c43-3248-5a11-b584-ae1da8832757",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69224 is fixed in version 3.8.6.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3aec4067-2908-53f5-92ed-eac6cc79db2a",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69225 is fixed in version 3.8.6.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:282a5f32-d9cf-5c48-807c-de867cbc045d",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69226 is fixed in version 3.8.6.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eaf4e41e-33da-57e9-80e7-c85eaa966336",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69227 is fixed in version 3.8.6.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:494d966e-d7cf-5fe8-b545-46505bed9495",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69228 is fixed in version 3.8.6.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f75e99e-d1cb-51bb-bab7-a995c749fc97",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69229 is fixed in version 3.8.6.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:582b3481-259b-506e-a1ea-6acceeb16b40",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.6.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d49fef9-cacf-5ec1-a97f-2d0aa75f173e",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22815 is fixed in version 3.8.6.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:815e1625-5597-59cb-8f49-eb703c7340a5",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34513 is fixed in version 3.8.6.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1e3215f-86e3-5028-bce4-498cfcedceea",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34514 is fixed in version 3.8.6.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0c8f946-1133-5dde-8e11-2a84eba79ae5",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.6.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0e89bcb-3e37-588b-9155-856f3022aa88",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34516 is fixed in version 3.8.6.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e73f67b7-9508-534a-8fdc-12614cf924e2",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34517 is fixed in version 3.8.6.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5bbf8062-9e9d-5b6f-9474-ab6a9ab3dfc8",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34518 is fixed in version 3.8.6.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0cfb9ed-485d-5c5a-a863-3c9daee72f50",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34519 is fixed in version 3.8.6.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:223cee2f-c679-582c-93ae-d5c2d7585ebf",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34520 is fixed in version 3.8.6.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70a82058-50ec-55c2-81ad-f77e4a9eab7f",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34525 is fixed in version 3.8.6.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d554e559-9c70-5a6e-ac0a-82ae81040668",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.6.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7b9c752-bbac-573e-9ca4-acb788875581",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47265 is fixed in version 3.8.6.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85f66fa3-ae2e-5ec7-aa0b-2d1535349f50",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50269 is fixed in version 3.8.6.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63479a8c-e3ee-5e9f-bdec-dfd1063587e1",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54273 is fixed in version 3.8.6.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:595576a0-5e37-5542-884b-a695169a0b1e",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54274 is fixed in version 3.8.6.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2a76ac6-2136-5cd8-a9db-1ab8ed2e112e",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.6.post12+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34562031-0d8b-57de-967f-2b914f9907f9",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.6.post12+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83bd1a4c-6676-5d54-93ec-a515e881b955",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54277 is fixed in version 3.8.6.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a7d31e7-f348-50c5-b9da-6ef45af62904",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54278 is fixed in version 3.8.6.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d28bc67-323d-5d24-9490-e8d6dcbb08e2",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54279 is fixed in version 3.8.6.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0f79109-bd0f-54bf-a88b-0a3a21531783",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.6.post12+tuxcare of aiohttp. Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be79700c-4a1e-5f60-a547-3f95c77c9780",
      "id": "CVE-2026-59881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59881 is fixed in version 3.8.6.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21517c45-068a-5c43-8a7d-90f652907ac2",
      "id": "CVE-2026-69243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69243 is fixed in version 3.8.6.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8322a337-3ee2-5b2f-9426-364f705f984a",
      "id": "CVE-2026-69244",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69244 is fixed in version 3.8.6.post12+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/aiohttp@3.8.6.post12+tuxcare"
    }
  ]
}