{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:9ab9fbc3-e5f9-57b0-86ee-7b1bc65ea186",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare",
      "type": "library",
      "name": "aiohttp",
      "version": "3.8.6.post11+tuxcare",
      "purl": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:a686f409-c236-5a16-9c8d-a76ce2f14872",
      "id": "CVE-2023-49081",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49081 is fixed in version 3.8.6.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6d645f7-fec9-581b-b824-baa8c46018f9",
      "id": "CVE-2023-49082",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49082 is fixed in version 3.8.6.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b30af1d6-6f06-54e3-a8a5-8018889fda7c",
      "id": "CVE-2024-23334",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23334 affects version 3.8.6.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dccda761-14d5-5219-acb0-1590689ea971",
      "id": "CVE-2024-23829",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23829 is fixed in version 3.8.6.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5cd14941-1001-5626-aeb6-d059e703a041",
      "id": "CVE-2024-27306",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-27306 is fixed in version 3.8.6.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2186ea64-10f5-56c9-b8f6-fa3b95642853",
      "id": "CVE-2024-30251",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-30251 is fixed in version 3.8.6.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afa92345-308c-5502-8bae-4464a8355953",
      "id": "CVE-2024-52304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52304 affects version 3.8.6.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c51d5902-465d-56d2-949c-d06878cecdd5",
      "id": "CVE-2025-53643",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53643 is fixed in version 3.8.6.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41566c50-7dca-5530-bd75-973470c43930",
      "id": "CVE-2025-69223",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.6.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f51ebe8-5155-5451-91f9-71d58bd8eb4f",
      "id": "CVE-2025-69224",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69224 is fixed in version 3.8.6.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba10f8f4-6874-5cd5-9223-25350759bf81",
      "id": "CVE-2025-69225",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69225 is fixed in version 3.8.6.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14974d53-5bb6-54ba-b5cf-02aa81a771c1",
      "id": "CVE-2025-69226",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69226 is fixed in version 3.8.6.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d113f54-c7f0-546e-bf4c-8be68539aa9c",
      "id": "CVE-2025-69227",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69227 is fixed in version 3.8.6.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ee8a8d3-23fc-59b6-a968-e5208b361ef7",
      "id": "CVE-2025-69228",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69228 is fixed in version 3.8.6.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c1e4e61-9699-5754-a8e6-8cd3738f75b2",
      "id": "CVE-2025-69229",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69229 is fixed in version 3.8.6.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c567bf1-5364-5857-bf60-de84013613de",
      "id": "CVE-2025-69230",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.6.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cca7e85d-6a5a-51b2-abbe-3d553d023dca",
      "id": "CVE-2026-22815",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22815 is fixed in version 3.8.6.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c474377c-10a2-5208-964c-40333732ec45",
      "id": "CVE-2026-34513",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34513 is fixed in version 3.8.6.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f17e49fe-546a-5f6a-9ed2-2dd307349270",
      "id": "CVE-2026-34514",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34514 is fixed in version 3.8.6.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53edc1c4-2bb5-540b-b8cc-9deeffb5bab6",
      "id": "CVE-2026-34515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.6.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03953c28-4e80-5e04-aed1-994f0c8d21fe",
      "id": "CVE-2026-34516",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34516 is fixed in version 3.8.6.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7074ef1e-8d25-55e8-b7ef-e6f6e37c4ddb",
      "id": "CVE-2026-34517",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34517 is fixed in version 3.8.6.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79bb7703-28ae-5bfc-bc8f-c88a45a4afa5",
      "id": "CVE-2026-34518",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34518 is fixed in version 3.8.6.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e7c0b94-254f-5003-87a3-964d73eca0b2",
      "id": "CVE-2026-34519",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34519 is fixed in version 3.8.6.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0275331d-bad4-5c59-a4b6-661f1e80b060",
      "id": "CVE-2026-34520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34520 is fixed in version 3.8.6.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:174b1801-44c0-5d30-ba6c-7e303fe682dd",
      "id": "CVE-2026-34525",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34525 is fixed in version 3.8.6.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d18cd577-5a62-5675-9adf-266358f6e922",
      "id": "CVE-2026-34993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.6.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2068f5aa-2fba-50e9-b03c-42813e574ef7",
      "id": "CVE-2026-47265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47265 is fixed in version 3.8.6.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b931d71-5e2e-561b-aa6b-67553baca286",
      "id": "CVE-2026-50269",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50269 is fixed in version 3.8.6.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20dd86de-9d45-533b-8a58-4e260896ee2b",
      "id": "CVE-2026-54273",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54273 is fixed in version 3.8.6.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c512925d-81ca-5dd5-8c5e-4113f258f5a4",
      "id": "CVE-2026-54274",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54274 is fixed in version 3.8.6.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1d5f267-5fd9-5f41-a823-831ad6aaa3a9",
      "id": "CVE-2026-54275",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.6.post11+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8626aaa-4de9-5230-a0ce-e5af4af5ac38",
      "id": "CVE-2026-54276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.6.post11+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:328fcf04-60fa-5660-a2b2-cc95c3f26280",
      "id": "CVE-2026-54277",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54277 is fixed in version 3.8.6.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7a7ab97-ffe2-5392-ba2e-b50056230e2e",
      "id": "CVE-2026-54278",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54278 is fixed in version 3.8.6.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33d711ab-3345-5cf9-9d16-525bfadeac85",
      "id": "CVE-2026-54279",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54279 is fixed in version 3.8.6.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12e6b8e1-8a9f-5fbc-990a-ae04001234ce",
      "id": "CVE-2026-54280",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.6.post11+tuxcare of aiohttp. Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86992485-daf9-59a9-b7eb-d665109cf763",
      "id": "CVE-2026-59881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59881 is fixed in version 3.8.6.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e91e602-c941-5257-8fa2-4888806c6a61",
      "id": "CVE-2026-69243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69243 is fixed in version 3.8.6.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2806b52b-68b0-51fc-8a72-c7334c336187",
      "id": "CVE-2026-69244",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69244 is fixed in version 3.8.6.post11+tuxcare of aiohttp."
      },
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/aiohttp@3.8.6.post11+tuxcare"
    }
  ]
}