{
  "@id": "urn:uuid:d91e6635-9279-48c1-80ca-7e44eb0cacfd",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 4,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-30T06:25:00.246700+00:00",
  "statements": [
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-37276 is fixed in version 3.8.1.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-37276"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-47627 is fixed in version 3.8.1.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-47627"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49081 is fixed in version 3.8.1.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49081"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2023-49082 is fixed in version 3.8.1.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2023-49082"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23334 is fixed in version 3.8.1.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23334"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-23829 is fixed in version 3.8.1.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-23829"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-27306 is fixed in version 3.8.1.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-27306"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-30251 is fixed in version 3.8.1.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-30251"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2024-52304 is fixed in version 3.8.1.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2024-52304"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-53643 is fixed in version 3.8.1.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-53643"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-29T12:34:26.611716+00:00",
      "status_notes": "Vulnerability CVE-2025-69223 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post14+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69223"
      },
      "action_statement": "Vulnerability CVE-2025-69223 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post14+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69224 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69224"
      },
      "action_statement": "Vulnerability CVE-2025-69224 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69225 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69225"
      },
      "action_statement": "Vulnerability CVE-2025-69225 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:25:00.246700+00:00",
      "status_notes": "Vulnerability CVE-2025-69226 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69226"
      },
      "action_statement": "Vulnerability CVE-2025-69226 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69227 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69227"
      },
      "action_statement": "Vulnerability CVE-2025-69227 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69228 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69228"
      },
      "action_statement": "Vulnerability CVE-2025-69228 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69229 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2025-69229"
      },
      "action_statement": "Vulnerability CVE-2025-69229 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2025-69230 affects version 3.8.1.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2025-69230"
      },
      "action_statement": "Vulnerability CVE-2025-69230 affects version 3.8.1.post7+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-22815 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post9+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-22815"
      },
      "action_statement": "Vulnerability CVE-2026-22815 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post9+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34513 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34513"
      },
      "action_statement": "Vulnerability CVE-2026-34513 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34514 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34514"
      },
      "action_statement": "Vulnerability CVE-2026-34514 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-30T06:25:00.246700+00:00",
      "status_notes": "Vulnerability CVE-2026-34515 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34515"
      },
      "action_statement": "Vulnerability CVE-2026-34515 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post15+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34516 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34516"
      },
      "action_statement": "Vulnerability CVE-2026-34516 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34517 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post8+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34517"
      },
      "action_statement": "Vulnerability CVE-2026-34517 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post8+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34518 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34518"
      },
      "action_statement": "Vulnerability CVE-2026-34518 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34519 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34519"
      },
      "action_statement": "Vulnerability CVE-2026-34519 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34520 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post10+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34520"
      },
      "action_statement": "Vulnerability CVE-2026-34520 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post10+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34525 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-34525"
      },
      "action_statement": "Vulnerability CVE-2026-34525 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post11+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-34993 affects version 3.8.1.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-34993"
      },
      "action_statement": "Vulnerability CVE-2026-34993 affects version 3.8.1.post7+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-47265 affects version 3.8.1.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-47265"
      },
      "action_statement": "Vulnerability CVE-2026-47265 affects version 3.8.1.post7+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-50269 affects version 3.8.1.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-50269"
      },
      "action_statement": "Vulnerability CVE-2026-50269 affects version 3.8.1.post7+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54273 affects version 3.8.1.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54273"
      },
      "action_statement": "Vulnerability CVE-2026-54273 affects version 3.8.1.post7+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54274 affects version 3.8.1.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54274"
      },
      "action_statement": "Vulnerability CVE-2026-54274 affects version 3.8.1.post7+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54275 does not affect version 3.8.1.post7+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54275"
      },
      "impact_statement": "not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.1.post10+tuxcare. The vulnerability requires the ability to specify custom per-request server_hostname parameters, a feature that was introduced in version 3.10.0. Version 3.8.1 hardcodes server_hostname to the request host, making the attack scenario impossible."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54276 does not affect version 3.8.1.post7+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54276"
      },
      "impact_statement": "not_affected \u2014 The target repository (aiohttp 3.8.1.post10+tuxcare) is not affected by CVE-2026-54276. The vulnerable component DigestAuthMiddleware was introduced in version 3.12+ and does not exist in this older version."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54277 affects version 3.8.1.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54277"
      },
      "action_statement": "Vulnerability CVE-2026-54277 affects version 3.8.1.post7+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54278 affects version 3.8.1.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54278"
      },
      "action_statement": "Vulnerability CVE-2026-54278 affects version 3.8.1.post7+tuxcare of aiohttp."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54279 affects version 3.8.1.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "CVE-2026-54279"
      },
      "action_statement": "Vulnerability CVE-2026-54279 affects version 3.8.1.post7+tuxcare of aiohttp."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-54280 does not affect version 3.8.1.post7+tuxcare of aiohttp. CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54280"
      },
      "impact_statement": "CVE-2026-54280 fix already exists in commit 5eba7627a9a5f887219dfb68908be995c0e15cbe"
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-59881 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post12+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-59881"
      },
      "action_statement": "Vulnerability CVE-2026-59881 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post12+tuxcare."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69243 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare.",
      "vulnerability": {
        "name": "CVE-2026-69243"
      },
      "action_statement": "Vulnerability CVE-2026-69243 affects version 3.8.1.post7+tuxcare of aiohttp, and is fixed in 3.8.1.post13+tuxcare."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-69244 does not affect version 3.8.1.post7+tuxcare of aiohttp. not_affected \u2014 Version 3.8.1 is not affected by CVE-2026-69244. The vulnerability exists in aiohttp 3.14+ where the C parser constructs detailed error messages with buffer snippets using llhttp_get_error_pos() followed by .split() on a raw pointer, causing out-of-bounds heap reads. Version 3.8.1 uses a simpler error reporting mechanism that only calls llhttp_get_error_reason() to get static error strings - it...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-69244"
      },
      "impact_statement": "not_affected \u2014 Version 3.8.1 is not affected by CVE-2026-69244. The vulnerability exists in aiohttp 3.14+ where the C parser constructs detailed error messages with buffer snippets using llhttp_get_error_pos() followed by .split() on a raw pointer, causing out-of-bounds heap reads. Version 3.8.1 uses a simpler error reporting mechanism that only calls llhttp_get_error_reason() to get static error strings - it..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare",
          "identifiers": {
            "purl": "pkg:pypi/aiohttp@3.8.1.post7+tuxcare"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability GHSA-pjjw-qhg8-p2p9 is fixed in version 3.8.1.post7+tuxcare of aiohttp.",
      "vulnerability": {
        "name": "GHSA-pjjw-qhg8-p2p9"
      }
    }
  ]
}
