{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f306bfd0-ac89-50bc-b1f6-301a74daadef",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.6.post10+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:2fcb1f39-ae44-5da7-849c-00759b4a8398",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49081 is fixed in version 3.8.6.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3003fc37-7acf-5aa4-95db-8a33df49da18",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49082 is fixed in version 3.8.6.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e579972f-4964-5f65-804a-a25f26661265",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23334 affects version 3.8.6.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df2362ec-3e03-5796-af1c-de113c89b529",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23829 is fixed in version 3.8.6.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f348c70e-f104-57d4-8dbc-d94cf07bfe95",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-27306 affects version 3.8.6.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71a950ea-4a15-5808-8319-dfc5ded74a85",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-30251 is fixed in version 3.8.6.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:529193f7-af4f-5d0e-989a-480ea2d55e59",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52304 affects version 3.8.6.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0c896a7-603e-5477-aaa9-8d7d87cba4df",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53643 is fixed in version 3.8.6.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abdf1e03-4f0f-5354-9641-049d322639e2",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.6.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2de9370-f978-56d0-a2b2-f504b596ff1a",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69224 is fixed in version 3.8.6.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:907be740-7ccb-541b-bea9-6cac1a5d7e99",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69225 affects version 3.8.6.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b0f52f1-5aa4-5d3e-89ee-cd7fa786f18a",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69226 is fixed in version 3.8.6.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33806bbe-2f73-5182-937a-baeeda89209c",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69227 is fixed in version 3.8.6.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5535aa67-033a-59cf-b513-9365cdde551d",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69228 is fixed in version 3.8.6.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:228e136b-535f-55e9-a1eb-8c7669b338dc",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69229 is fixed in version 3.8.6.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ba4a9a1-bd8e-5baa-8acf-44bffb932bd1",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.6.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87a5e761-e147-5af3-9f41-20e1d936b8d4",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22815 is fixed in version 3.8.6.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2424bb4e-c277-50d4-84e3-7a4d9653c8d1",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34513 is fixed in version 3.8.6.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c5972c1-bc07-5f94-af3f-57f417381f62",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34514 is fixed in version 3.8.6.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9d31785-fd9d-573d-a13d-a917c2ba1581",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.6.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed3b3016-7e08-58de-bcdd-3d0ff53cef33",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34516 is fixed in version 3.8.6.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0676b28-5ea9-5b02-b7dc-0a833279279c",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34517 is fixed in version 3.8.6.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:847df36e-2c36-585c-9e90-1c34a5a00637",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34518 is fixed in version 3.8.6.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c67e365-cecf-550c-a64e-ed6311833cf5",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34519 is fixed in version 3.8.6.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d87de1e-1be6-54be-a97e-ac1e7f444130",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34520 is fixed in version 3.8.6.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae814429-6782-507b-9fdf-f44ed060590d",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34525 is fixed in version 3.8.6.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43c4178d-bdc6-556a-9133-93270797cd09",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.6.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0cd34e9-85ef-5a28-996c-ec23ecd54749",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47265 is fixed in version 3.8.6.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86590e25-942f-54ce-a5ae-83813a50ca82",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50269 is fixed in version 3.8.6.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:068a2394-3bfa-545a-8b80-bb21a674ea28",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54273 is fixed in version 3.8.6.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d0300ef-c992-5b95-881d-4a2011c41d56",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54274 is fixed in version 3.8.6.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2656454d-2232-515a-a4a1-be2d131739aa",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.6.post10+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03381245-b03a-5163-a2d3-f1ce0dc2cc7c",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.6.post10+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e63165df-3cb2-5595-a925-053f8c9b9b7a",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54277 is fixed in version 3.8.6.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28130d14-789a-5dde-871f-ac11c2d50976",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54278 is fixed in version 3.8.6.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a12fa421-cebf-5622-b4dc-8bd2fcaf22df",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54279 is fixed in version 3.8.6.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c501bbc3-ef44-5198-ae7f-1ab233b3cb4c",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.6.post10+tuxcare of aiohttp. Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ea452e2-ad40-5429-ae41-3e3216619645",
      "id": "CVE-2026-59881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59881 is fixed in version 3.8.6.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6cf604d9-e732-5c72-951d-3615926a222a",
      "id": "CVE-2026-69243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69243 is fixed in version 3.8.6.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8788e6ee-d0de-5932-be5b-677266a41c80",
      "id": "CVE-2026-69244",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69244 is fixed in version 3.8.6.post10+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/aiohttp@3.8.6.post10+tuxcare"
    }
  ]
}