{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b4efb43e-003a-5a73-821b-a79259990b2c",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "aiohttp",
      "purl": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare",
      "type": "library",
      "bom-ref": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare",
      "version": "3.8.6.post14+tuxcare",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2023-49081",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:9fd09950-3a44-535d-973b-e40c9aaaefef",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49081 is fixed in version 3.8.6.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2023-49082",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:06998d14-c12b-5986-8972-1bf5607d4eea",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49082 is fixed in version 3.8.6.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2024-23334",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:f6e6fb3c-db05-5734-a8e5-15c9553330eb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23334 is fixed in version 3.8.6.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2024-23829",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:1fc7b0c8-67d6-523f-8d83-a127c050409b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23829 is fixed in version 3.8.6.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2024-27306",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:0fb53908-d6fe-5057-a75a-1c71660d74f8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-27306 is fixed in version 3.8.6.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2024-30251",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:3573e52d-e63c-5e87-8bbe-7a564f9deec8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-30251 is fixed in version 3.8.6.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2024-52304",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:37f71e44-044b-54e5-b19e-ff0d74384a00",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52304 affects version 3.8.6.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2025-53643",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:df9028d7-d57c-5d93-bf6b-6ee904082463",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53643 is fixed in version 3.8.6.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2025-69223",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:f36c142b-84aa-522b-a34a-604bb0ccfb1c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69223 is fixed in version 3.8.6.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2025-69224",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:5d4392e3-4431-52df-b8f1-04d91876d906",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69224 is fixed in version 3.8.6.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2025-69225",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:7941eef1-48ed-5098-b60f-8473f29800d6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69225 is fixed in version 3.8.6.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2025-69226",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:e18eb954-01be-5a88-9a96-aae562b222c7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69226 is fixed in version 3.8.6.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2025-69227",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:4b728bf9-f6b7-5595-88b9-e4ccfae38886",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69227 is fixed in version 3.8.6.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2025-69228",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:cfc404fa-4ba8-5d90-b91e-bd1671b82397",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69228 is fixed in version 3.8.6.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2025-69229",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:92361ff7-4f99-53f9-8bf6-b7e321ecc7ce",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69229 is fixed in version 3.8.6.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2025-69230",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:a4a0eb5d-cf08-58e8-b09c-72b9137206f7",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-69230 does not affect version 3.8.6.post14+tuxcare of aiohttp. aiohttp 3.8.6 has no aiohttp/_cookie_helpers.py and BaseRequest.cookies performs no logging at all (web_request.py does not reference internal_logger); it parses with stdlib SimpleCookie. The per-cookie warning loop that upstream 64629a08 replaces with one aggregated debug line does not exist on this branch, so the log-flooding path is absent. Same determination as 3.8.5 (VPV 18638) and 3.8.4 (VPV 18628).",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-22815",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:b130fcb6-d1c6-586b-aad4-7e90cd141324",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22815 is fixed in version 3.8.6.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-34513",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:888a37da-d86f-5c98-9c02-45566761d406",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34513 is fixed in version 3.8.6.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-34514",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:c3c4f540-22da-5780-9b05-9a203bb817e5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34514 is fixed in version 3.8.6.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-34515",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:7496a720-6d97-5318-b16d-861f66ab7cdd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34515 is fixed in version 3.8.6.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-34516",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:d0ea7b19-eb5b-557a-bafd-a1ad99100687",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34516 is fixed in version 3.8.6.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-34517",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:e6521bb2-1eea-544a-96a1-7a856a5af9ee",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34517 is fixed in version 3.8.6.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-34518",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:c40de505-0b8c-5027-ae0d-9a334e868f76",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34518 is fixed in version 3.8.6.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-34519",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:a141183b-f14f-5efc-9318-fa0e484c1cf5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34519 is fixed in version 3.8.6.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-34520",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:b4f0248b-34a6-5830-8af4-f4ba973047de",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34520 is fixed in version 3.8.6.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-34525",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:a76534cf-e546-5b2a-8163-d3b2750303c3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34525 is fixed in version 3.8.6.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-34993",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:48b681b1-58c2-5156-8a5c-736621dd7319",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34993 is fixed in version 3.8.6.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-47265",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:6bb24c77-fb56-5506-acf9-e2a6a3ea51ed",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47265 is fixed in version 3.8.6.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-50269",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:b0f0ce3a-384a-5ab4-b689-5fe2720ccf21",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50269 is fixed in version 3.8.6.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-54273",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:8a53e46a-e9db-5deb-a97d-27148bae93e0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54273 is fixed in version 3.8.6.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-54274",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:8f2440f4-d36b-585d-a1d8-d6a4e65e6d1c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54274 is fixed in version 3.8.6.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-54275",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:d607f886-985e-53cd-8819-857288fa36f6",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.6.post14+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-54276",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:7838847d-01a9-5124-8850-0a0a2c5752c7",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.6.post14+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-54277",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:4c2bd095-0b48-5cac-af62-05c64c80a05d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54277 is fixed in version 3.8.6.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-54278",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:82fbac36-44b2-5e2e-875e-207af94dcfce",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54278 is fixed in version 3.8.6.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-54279",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:ccac75d2-e319-5b27-bdb2-a25e4c804363",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54279 is fixed in version 3.8.6.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-54280",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:8eec1d26-78e0-5517-9f0c-7458ec39a116",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.6.post14+tuxcare of aiohttp. Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-59881",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:40fa74ff-4e22-5f17-b654-1bfc8aeeeff8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59881 is fixed in version 3.8.6.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-69243",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:c3625d9a-ace7-5b5f-8088-ae3364c63ddd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69243 is fixed in version 3.8.6.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-69244",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:9cc372a2-f08e-5d3b-9a58-7ccff0f70004",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69244 is fixed in version 3.8.6.post14+tuxcare of aiohttp."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/aiohttp@3.8.6.post14+tuxcare"
    }
  ]
}