{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:5ce03cda-106c-5dcf-a66b-3e2feda959b2",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "aiohttp",
      "purl": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
      "type": "library",
      "bom-ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare",
      "version": "3.8.1.post14+tuxcare",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2022-33124",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:1417a71d-7a70-5023-b740-02f6500b594d",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-33124 is a false positive for aiohttp 3.8.1.post14+tuxcare."
      }
    },
    {
      "id": "CVE-2023-37276",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:cbc0e1c2-4045-5053-9a77-2b1e86f96ff5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-37276 is fixed in version 3.8.1.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2023-47627",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:92e848ad-6e28-523d-b0a6-c727cd761400",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-47627 is fixed in version 3.8.1.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2023-49081",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:2b0be15f-9160-5811-b14c-dd92e377dbd4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49081 is fixed in version 3.8.1.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2023-49082",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:5b687d71-bdf2-5401-897b-b49854ed28c6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49082 is fixed in version 3.8.1.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2024-23334",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:af873c63-9ce4-5cf1-abbc-9964bfcecd58",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23334 is fixed in version 3.8.1.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2024-23829",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:64ef7b16-e7e6-59f7-a78d-d20987f066cb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23829 is fixed in version 3.8.1.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2024-27306",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:04dc4c88-f011-521d-a4cf-f65340a9d101",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-27306 is fixed in version 3.8.1.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2024-30251",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:b4c24e96-a330-55c0-83d4-d0d910d43034",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-30251 is fixed in version 3.8.1.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2024-52304",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:80e3012d-cf1e-5e35-8f65-7e0efe6522d7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52304 is fixed in version 3.8.1.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2025-53643",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:5569e6bb-2f03-545c-9cb4-4ff0290a2ba7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53643 is fixed in version 3.8.1.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2025-69223",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:b663ae12-6cbe-5ba4-977b-72f2bc3abee6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69223 is fixed in version 3.8.1.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2025-69224",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:bf22f43c-443d-50d2-b15c-8029f7bee28b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69224 is fixed in version 3.8.1.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2025-69225",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:0995089c-1508-5c24-8075-c2d3e909b945",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69225 is fixed in version 3.8.1.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2025-69226",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:a619f026-a2b6-58df-ac18-be6569a58017",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69226 affects version 3.8.1.post14+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare."
      }
    },
    {
      "id": "CVE-2025-69227",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:4b82dbb3-1a61-5533-8798-dc8b0bfa19b3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69227 is fixed in version 3.8.1.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2025-69228",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:47ec0c6b-4cf0-548d-b8b3-ba3c1a707e22",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69228 is fixed in version 3.8.1.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2025-69229",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:303b0759-be3f-5b20-99f3-62c52b96a68d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69229 is fixed in version 3.8.1.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2025-69230",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:7ee01b86-d21a-52f4-8fcc-ce505cb7fbee",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69230 affects version 3.8.1.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-22815",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:5133a25b-db75-52cb-9696-8e0db0978b31",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22815 is fixed in version 3.8.1.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-34513",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:0a753d52-a5c9-5831-a912-c1b8ce888782",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34513 is fixed in version 3.8.1.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-34514",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:3e3b95b5-b975-5e83-915d-252389a11adc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34514 is fixed in version 3.8.1.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-34515",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:5827d136-7bf8-5a47-ac78-10ff2dae9b95",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34515 affects version 3.8.1.post14+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare."
      }
    },
    {
      "id": "CVE-2026-34516",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:37c87dbe-3ec0-5f72-bcca-e8b01785bdde",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34516 is fixed in version 3.8.1.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-34517",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:4e991ed5-1e96-56b8-a78a-8e2b32c59acb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34517 is fixed in version 3.8.1.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-34518",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:aa437cf1-1d9b-5fdf-87f6-755bfb0c25e9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34518 is fixed in version 3.8.1.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-34519",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:5d4ca380-f3dd-58d9-9755-eba04c6ed1e0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34519 is fixed in version 3.8.1.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-34520",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:0b5d32ea-a034-5078-bbaa-c3354bd93093",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34520 is fixed in version 3.8.1.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-34525",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:9255dbb8-8e50-5c54-a8db-3f4e1fec0c09",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34525 is fixed in version 3.8.1.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-34993",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:64b84b9b-c3fb-5e86-807e-8dd7a0e01d8e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34993 affects version 3.8.1.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-47265",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:b55abe37-1deb-5366-ba10-9087d9da1c33",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-47265 affects version 3.8.1.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-50269",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:20363f4a-6e80-5a1d-901e-8b5872d4541e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50269 affects version 3.8.1.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-54273",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:94752d6f-1d2f-5209-b849-adbd7c3b1ef3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54273 affects version 3.8.1.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-54274",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:53381cf6-31df-57e0-b2da-a4a168118d51",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54274 affects version 3.8.1.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-54275",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:2c8694cd-8e54-5c6d-9a06-a64bdd75eeff",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.1.post14+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-54276",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:38b04fe0-9a50-5638-9456-e3efcd18aa0d",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.1.post14+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-54277",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:e9e2f374-6883-5c0b-8236-9ba7c5cd5461",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54277 affects version 3.8.1.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-54278",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:ecffc5bb-0e6b-5fbe-a2fb-3a7e56c6710d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54278 affects version 3.8.1.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-54279",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:78e64433-852e-5e87-a3c1-e0e8feaf54e9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54279 affects version 3.8.1.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-54280",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:0f0aaa98-9b9a-50ca-bee8-498f06f49024",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.1.post14+tuxcare of aiohttp. CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-59881",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:8eb2f920-9488-5491-a059-240c9ade2c30",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59881 is fixed in version 3.8.1.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-69243",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:4cccc949-11c5-54ed-b0be-6280be6b26a6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69243 is fixed in version 3.8.1.post14+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-69244",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:ee083b77-0860-54b1-afea-adce0c66727d",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-69244 does not affect version 3.8.1.post14+tuxcare of aiohttp. not_affected \u2014 Version 3.8.1 is not affected by CVE-2026-69244. The vulnerability exists in aiohttp 3.14+ where the C parser constructs detailed error messages with buffer snippets using llhttp_get_error_pos() followed by .split() on a raw pointer, causing out-of-bounds heap reads. Version 3.8.1 uses a simpler error reporting mechanism that only calls llhttp_get_error_reason() to get static error strings - it...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "GHSA-pjjw-qhg8-p2p9",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:f803534f-3ded-550f-9f37-34435c03db2c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-pjjw-qhg8-p2p9 is fixed in version 3.8.1.post14+tuxcare of aiohttp."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/aiohttp@3.8.1.post14+tuxcare"
    }
  ]
}