{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:7f3506f7-801a-5096-bf7d-8ec905742e9b",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "aiohttp",
      "purl": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare",
      "type": "library",
      "bom-ref": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare",
      "version": "3.8.6.post13+tuxcare",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2023-49081",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:bc1876f8-4457-5caa-8159-936fa7bd735a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49081 is fixed in version 3.8.6.post13+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2023-49082",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:3d845674-d500-5cc6-a109-1a8cde0d3533",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-49082 is fixed in version 3.8.6.post13+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2024-23334",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:70ea0683-394c-5c59-9005-fc0c92ee7bc2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23334 is fixed in version 3.8.6.post13+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2024-23829",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:9eccfe79-b946-5c10-91b7-378ff9f93c65",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23829 is fixed in version 3.8.6.post13+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2024-27306",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:d77f25c1-a2fe-5f2a-817a-780e6e855f14",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-27306 is fixed in version 3.8.6.post13+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2024-30251",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:061004be-139e-509c-ae0d-91bb1620b929",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-30251 is fixed in version 3.8.6.post13+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2024-52304",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:ad86a493-b10c-537f-9110-f7a2e035833f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52304 affects version 3.8.6.post13+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2025-53643",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:d39a1040-62b9-5f6a-adcd-30d7cfeaa178",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53643 is fixed in version 3.8.6.post13+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2025-69223",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:84eed91f-52cb-56d2-a8ad-2e5600dba6e1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-69223 affects version 3.8.6.post13+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2025-69224",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:645d2e4b-de73-5ddb-9d9c-3c7e0f877a71",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69224 is fixed in version 3.8.6.post13+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2025-69225",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:37c1a8fb-5668-56f4-a916-4f10c403093f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69225 is fixed in version 3.8.6.post13+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2025-69226",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:f8a29a92-5f67-5375-be09-a0e3923a8466",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69226 is fixed in version 3.8.6.post13+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2025-69227",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:b81db5dc-aca7-5b14-a0db-8ff59d2d1fd1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69227 is fixed in version 3.8.6.post13+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2025-69228",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:113ceda0-352e-50e5-90d2-285ded1f2bfc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69228 is fixed in version 3.8.6.post13+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2025-69229",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:d1831b9f-d5bb-5c1d-8882-3c622f82fa07",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-69229 is fixed in version 3.8.6.post13+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2025-69230",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:b7f418d4-f47c-5e5f-bd86-009ec13a2759",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-69230 does not affect version 3.8.6.post13+tuxcare of aiohttp. aiohttp 3.8.6 has no aiohttp/_cookie_helpers.py and BaseRequest.cookies performs no logging at all (web_request.py does not reference internal_logger); it parses with stdlib SimpleCookie. The per-cookie warning loop that upstream 64629a08 replaces with one aggregated debug line does not exist on this branch, so the log-flooding path is absent. Same determination as 3.8.5 (VPV 18638) and 3.8.4 (VPV 18628).",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-22815",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:453cdc6b-2632-582d-a295-2ea91c263f22",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22815 is fixed in version 3.8.6.post13+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-34513",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:779b9a46-c833-50b1-8a25-a98d77e1b420",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34513 is fixed in version 3.8.6.post13+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-34514",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:c242a485-6507-58f4-a300-bad079f643a6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34514 is fixed in version 3.8.6.post13+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-34515",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:d8731f07-c5aa-528d-ad8c-31c59c03a0c8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34515 is fixed in version 3.8.6.post13+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-34516",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:0472fd98-c7cf-5209-8c84-ee96bef96e36",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34516 is fixed in version 3.8.6.post13+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-34517",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:e5738ee6-d9cd-5508-ab17-47c5cfec0a20",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34517 is fixed in version 3.8.6.post13+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-34518",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:18be5b66-b585-5e19-a88e-be1e2d57f07b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34518 is fixed in version 3.8.6.post13+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-34519",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:cb4aa448-71d7-5c04-ab85-6eace7a8dd79",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34519 is fixed in version 3.8.6.post13+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-34520",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:34772e6f-603b-5584-a8d9-e6c280b7c313",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34520 is fixed in version 3.8.6.post13+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-34525",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:160c0343-0200-55c9-be3d-3715b350b7d6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34525 is fixed in version 3.8.6.post13+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-34993",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:0ca5def6-41b2-58e1-b1cb-4e34aa7f0c8f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34993 is fixed in version 3.8.6.post13+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-47265",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:55b55136-e3bc-5c9d-9272-a4b3f1ab8bd2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47265 is fixed in version 3.8.6.post13+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-50269",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:ae099fc2-e15d-564a-917e-0b78e872a578",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50269 is fixed in version 3.8.6.post13+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-54273",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:770eab6a-cb3e-5de4-8dea-93ac223f20c1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54273 is fixed in version 3.8.6.post13+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-54274",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:818ca909-4e24-5835-b933-4aed8054eba1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54274 is fixed in version 3.8.6.post13+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-54275",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:72d8cc6c-1e53-5c2c-9cdb-503d93502b90",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54275 does not affect version 3.8.6.post13+tuxcare of aiohttp. not_affected \u2014 CVE-2026-54275 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability requires the per-request server_hostname parameter feature, which was introduced in version 3.9.0 and does not exist in this version.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-54276",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:cf2ac98e-9fd9-5b10-ac4a-469366b19616",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54276 does not affect version 3.8.6.post13+tuxcare of aiohttp. not_affected \u2014 The target repository (aiohttp version 3.8.6.post6+tuxcare) does not contain the DigestAuthMiddleware component that is affected by CVE-2026-54276. This feature was introduced in aiohttp version 3.12, but the target runs version 3.8.6. Without DigestAuthMiddleware, the cross-origin credential disclosure vulnerability cannot manifest.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-54277",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:073c7fd9-92a5-5a29-8c06-6a5ec8b086dc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54277 is fixed in version 3.8.6.post13+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-54278",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:3c1cb4ca-736f-5192-bc1b-3be740cfb693",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54278 is fixed in version 3.8.6.post13+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-54279",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:52acead9-8c83-5247-a07d-1f46ddee1002",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54279 is fixed in version 3.8.6.post13+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-54280",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:bbb0acd8-e8eb-55dd-85b4-1d0c1ee091a2",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54280 does not affect version 3.8.6.post13+tuxcare of aiohttp. Version 3.8.6 is not vulnerable. Summary: CVE-2026-54280 does not affect aiohttp version 3.8.6.post6+tuxcare. The vulnerability is specific to versions that have the Payload.close() method (introduced in May 2025), which is absent in this version released in October 2023. The target version uses a different architecture where file-based payloads handle cleanup internally via finally blocks in their write() methods.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-59881",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:085cf8f7-f3ee-5d81-8454-7ed227c8e2de",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59881 is fixed in version 3.8.6.post13+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-69243",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:6809f14d-2c80-5491-85ce-974e51f5afff",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69243 is fixed in version 3.8.6.post13+tuxcare of aiohttp."
      }
    },
    {
      "id": "CVE-2026-69244",
      "affects": [
        {
          "ref": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
        }
      ],
      "bom-ref": "urn:uuid:1a77d664-9bba-580f-af59-e601b0761bee",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69244 is fixed in version 3.8.6.post13+tuxcare of aiohttp."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:pypi/aiohttp@3.8.6.post13+tuxcare"
    }
  ]
}