{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:36299ae0-06b1-55ee-a640-c259de965207",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/animations@12.2.16",
      "type": "library",
      "name": "@angular/animations",
      "version": "12.2.16",
      "purl": "pkg:npm/%40angular/animations@12.2.16"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:b8588025-38f6-52b7-b6ba-385959acb38c",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50170 does not affect version 12.2.16 of @angular/animations. not_affected \u2014 Angular v12.2.16-tuxcare.2 is NOT affected by CVE-2026-50170. The vulnerability concerns the HttpTransferCache feature that caches credentialed HTTP responses during server-side rendering (SSR) and replays them during client hydration. This feature was introduced in Angular v16 and does not exist in v12.2.16. The target repository lacks the transfer_cache.ts file, HttpTransferCache class, trans..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@12.2.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cdb6b387-37ec-5ca3-9f75-dde8cef9f414",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54264 does not affect version 12.2.16 of @angular/animations. not_affected \u2014 Angular 12.2.16-tuxcare.2 is NOT affected by CVE-2026-54264. The vulnerable code pattern does not exist in this version. The service worker creates fresh requests using only the redirect URL without copying any headers from the original request, preventing credential leakage to third-party origins on cross-origin redirects."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@12.2.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbd4cbf6-3279-5fb2-924d-e58607248832",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 12.2.16 of @angular/animations. not_affected \u2014 Angular 12.2.16 is not affected by CVE-2026-54265. The vulnerability exists in Angular's modern template pipeline compiler architecture (introduced in Angular 16+) where TwoWayProperty IR operations bypassed sanitizer resolution. Angular 12.2.16 uses the older architecture where two-way bindings are desugared into separate property and event bindings, and the property binding inherently goes th..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@12.2.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93ff43ad-9da9-5190-9c1b-1ecb60826128",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54266 does not affect version 12.2.16 of @angular/animations. not_affected \u2014 Angular 12.2.16-tuxcare.2 does not contain the vulnerable HttpTransferCache feature. The feature was introduced in Angular 16.0.0 (March 31, 2023), several major versions after this release. Without HttpTransferCache, the attack chain from HTTP request properties to hash-based cache key generation to cache poisoning cannot occur."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@12.2.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ee86658-f533-5c96-9c63-96f569377ad5",
      "id": "CVE-2026-68945",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 12.2.16 of @angular/animations. not_affected \u2014 Angular version 12.2.16 is NOT AFFECTED by CVE-2026-68945. The vulnerable HttpTransferCache feature was introduced in Angular 16.0.0 and does not exist in version 12.2.16. The file packages/common/http/src/transfer_cache.ts, the cache key generation logic, and all related APIs (provideClientHydration, withNoHttpTransferCache) are absent from this version. Version 12.2.16 predates the vulnerable..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@12.2.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bb0b3b4-562b-561c-ac92-bae9511f4c6e",
      "id": "CVE-2026-88056",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 12.2.16 of @angular/animations. not_affected \u2014 Angular v12.2.16-tuxcare.4 is not affected by CVE-2026-88056. The vulnerability requires a `String.prototype.trim()` call in the parseUrl function that strips Unicode whitespace, converting same-origin validated URLs into cross-origin protocol-relative URLs. This vulnerable code pattern was introduced in Angular v22.x (May 2026) via commit 6e71049021, over 4 years after v12.2.16 was released (J..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@12.2.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b631cfb-e49f-56ce-b946-77aa3701cbe6",
      "id": "CVE-2026-88057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 12.2.16 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@12.2.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f56d936-115f-52a9-9ef3-1c63fa34328d",
      "id": "CVE-2026-88059",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 12.2.16 of @angular/animations. not_affected \u2014 Angular 12.2.16 is not affected by CVE-2026-88059. The vulnerability requires the HttpTransferCache feature with hierarchical HttpClient delegation (withRequestsMadeViaParent()), which was introduced in Angular 16.0.0. Angular 12.2.16 predates this feature by 4 major versions and contains none of the required components: no HttpTransferCache, no withRequestsMadeViaParent(), no provideClientHydr..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@12.2.16"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14bdf2be-b181-511d-9990-84c0ab93c38e",
      "id": "CVE-2026-88060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 12.2.16 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@12.2.16"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/animations@12.2.16"
    }
  ]
}