{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:0b97f3f7-3c3d-5cd4-ae1f-bd95962f5203",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.6.post9+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:9e6b2b06-06be-59bf-9aa2-71e0a73d505c",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49081 is fixed in version 3.8.6.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a49a2c57-5758-5325-b611-dde458d6bba8",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49082 is fixed in version 3.8.6.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bb27b42-7cc0-5b11-9cec-d1a0020f0f82",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23334 affects version 3.8.6.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47196b74-68e3-53ae-8721-ccf51884a47f",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23829 affects version 3.8.6.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc7ebc0f-beff-5029-beb9-f9936d79f9a3",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27306 affects version 3.8.6.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17800352-eff3-5797-949f-18e0f7ceca5c",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-30251 is fixed in version 3.8.6.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:977866f8-763f-580d-a8ad-7221ca9c4afb",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52304 affects version 3.8.6.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdab6b30-f819-5bab-ac43-fb0322287f20",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-53643 affects version 3.8.6.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1dffb830-ac67-549a-8a9c-cb374a0b3a70",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.6.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e2890e6-5065-5eb6-94bd-d8c54dc82507",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69224 affects version 3.8.6.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a139c4b1-079d-54c6-b279-af1f1e9f9b48",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.6.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6f1a38e-b629-584b-8add-3dd1fc7c2f3b",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.6.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b17b327b-1182-58d7-b9ca-307c5b99a9b8",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69227 affects version 3.8.6.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3408fcf5-5c82-5aa5-919a-84f805ee083f",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69228 affects version 3.8.6.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5d82816-04d6-5db4-a67c-94256619825d",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69229 affects version 3.8.6.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d2fa0df-8eb1-5bda-9bcd-223a5f55a385",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.6.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d14b16f-0b20-5511-b9f0-39d0faf284ad",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22815 is fixed in version 3.8.6.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:edef6e36-439f-502b-975a-5953fa00c573",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34513 is fixed in version 3.8.6.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2bb4ae6-9b93-54df-96e6-66d45e589e29",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34514 is fixed in version 3.8.6.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf020227-0530-5851-907d-4f2f9d2f8305",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.6.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a3f50ae-2bec-58b9-949b-b021b3eae02b",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34516 is fixed in version 3.8.6.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7912c76-9a1e-5ddc-bc2a-9a2c7dffaa7f",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34517 is fixed in version 3.8.6.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab674285-7a39-5596-9b71-6043ff9a270a",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34518 is fixed in version 3.8.6.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba273dae-63f4-5397-b564-1ef6d54b386c",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34519 is fixed in version 3.8.6.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5e35d10-2312-5dd7-8b69-a95226fff956",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34520 is fixed in version 3.8.6.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d419c3fc-2838-5e3c-946e-2230c21cdd45",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34525 is fixed in version 3.8.6.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f8e6605-1817-581f-804b-cb5c7ebdcac2",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.6.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bc45129-68f6-56ab-ac84-feb2db4a17b7",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47265 is fixed in version 3.8.6.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16028412-be73-5c9e-8a5f-a37a8130033b",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50269 is fixed in version 3.8.6.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:900dc0b5-0d54-5865-87e8-89c4bd7a8586",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54273 is fixed in version 3.8.6.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1833692e-811e-5e65-83a8-ae4e536cf671",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54274 is fixed in version 3.8.6.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ab40409-0cf8-5260-9a72-fe7362996f4f",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.6.post9+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:540c5c03-b5f4-52e5-a960-ed45436f299f",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.6.post9+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7dfe15d8-1495-5ba8-89c1-de43679530ec",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54277 is fixed in version 3.8.6.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83d16009-3545-5de3-a06b-479538d827f0",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54278 is fixed in version 3.8.6.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b7cbbdf-c6b3-5750-aeb9-053f2683e0d2",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54279 is fixed in version 3.8.6.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:868a2244-60c4-5a3a-815a-1293fbdb6c73",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.6.post9+tuxcare of aiohttp. Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fd14eeb-bc0d-596f-9dfe-aec9b91485f1",
      "id": "CVE-2026-59881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59881 is fixed in version 3.8.6.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebf5faa2-c3c2-5fa5-a26d-17ec408c44d5",
      "id": "CVE-2026-69243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69243 is fixed in version 3.8.6.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fbb1044-9621-53ab-97cc-d7ac86502f6d",
      "id": "CVE-2026-69244",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69244 is fixed in version 3.8.6.post9+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/aiohttp@3.8.6.post9+tuxcare"
    }
  ]
}