{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b690b2ac-cb3b-5a7b-86a7-15115603263e",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.19",
      "type": "library",
      "name": "@angular/animations",
      "version": "5.2.11-tuxcare.19",
      "purl": "pkg:npm/%40angular/animations@5.2.11-tuxcare.19"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:2e764864-68db-555e-b1c2-97d64620477e",
      "id": "CVE-2021-4231",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 5.2.11-tuxcare.19 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b0e94f9-3a87-5a75-901d-f41513566524",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 5.2.11-tuxcare.19 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0aa5e04-bf06-5954-9353-5fa2e4a201cc",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 5.2.11-tuxcare.19 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae77b384-497c-55cc-be8f-44383be8edd2",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 5.2.11-tuxcare.19 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c32bbe8-1ac9-5094-b50f-690dd5379d5f",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 5.2.11-tuxcare.19 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35cf6c9f-4829-57ee-98d0-8f12caee86b9",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 5.2.11-tuxcare.19 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3aafac3d-fc18-542c-91ba-a36d53afd18e",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 5.2.11-tuxcare.19 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50e687a0-b6e7-5523-a3e0-5294d1f24048",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 5.2.11-tuxcare.19 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4692f738-2e70-533c-8e73-ea6968dd235b",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 5.2.11-tuxcare.19 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:722889fd-4abd-579c-85ef-548a55c12826",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 5.2.11-tuxcare.19 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8cf00cd-022f-5b8d-b4fb-6476bbc43d2d",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 5.2.11-tuxcare.19 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec7c384a-7701-539c-a789-513ec012d5a3",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 5.2.11-tuxcare.19 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9b396ac-9b4b-5426-8d42-a13fd17610ab",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 5.2.11-tuxcare.19 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81fe8e3f-ff1d-539f-9852-f518cb33f8dc",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 5.2.11-tuxcare.19 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e8bf746-9298-5843-8d0f-fc0bae350ed2",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 5.2.11-tuxcare.19 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8e632ad-5648-5258-8248-66440f6cb0d1",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 5.2.11-tuxcare.19 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:708456be-5277-5c8c-9b2f-2abdcd7ef780",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 5.2.11-tuxcare.19 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f9a7708-716a-5f75-bc9f-7789e043499f",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 5.2.11-tuxcare.19 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd624789-8f63-5dde-991c-07fb415ab116",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 5.2.11-tuxcare.19 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ff07371-6dba-54f6-957e-ccab390d02f9",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 5.2.11-tuxcare.19 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31b5640c-4406-5bbd-886c-6a6afd16b3ff",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 5.2.11-tuxcare.19 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f4999d3-c68e-5d5e-8f6a-618bf112d0d7",
      "id": "CVE-2026-68945",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 5.2.11-tuxcare.19 of @angular/animations. not_affected \u2014 Angular 5.2.11 is NOT affected by CVE-2026-68945. The vulnerable component `HttpTransferCache` does not exist in this version. This feature was introduced in Angular v16 as part of the modern SSR hydration system. Angular 5.2.11 only has the basic `TransferState` API (a generic key-value store for manual state transfer), not the automatic HTTP request caching interceptor that contains the vulne..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4cd8c7f9-ce9b-5923-9a70-443a5458574a",
      "id": "CVE-2026-69149",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 5.2.11-tuxcare.19 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65155f2a-78d1-5135-86ca-9c9d95c7a1f9",
      "id": "CVE-2026-69151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 5.2.11-tuxcare.19 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bca7be1b-3e88-5a85-a089-cf4582db456c",
      "id": "CVE-2026-88056",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 5.2.11-tuxcare.19 of @angular/animations. not_affected \u2014 Angular 5.2.11-tuxcare.19 does not contain the vulnerable URL resolution code pattern described in CVE-2026-88056. The vulnerability requires the url.ts file with parseUrl function calling String.prototype.trim() and the relativeUrlsTransformerInterceptorFn HTTP interceptor, both introduced in later Angular versions (post-June 2026). The target version uses a fundamentally different architectur..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6c9030a-3f0f-5461-9b39-1e14f52d3024",
      "id": "CVE-2026-88057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 5.2.11-tuxcare.19 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f577d16-4f21-588d-8b34-c3b617e375ed",
      "id": "CVE-2026-88059",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 5.2.11-tuxcare.19 of @angular/animations. not_affected \u2014 Angular 5.2.11 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache with hierarchical HttpClient delegation (withRequestsMadeViaParent()), features that were introduced in Angular v16. Angular 5.2.11 predates these features by approximately 6+ years and contains only a basic HTTP interceptor architecture with no automatic response caching mechanism. While TransferStat..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f66c6549-7b03-573a-b1bc-518fd311eb3b",
      "id": "CVE-2026-88060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 5.2.11-tuxcare.19 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.19"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.19"
    }
  ]
}