{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:8120f628-26a7-53c2-9209-7c72305bd70a",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.18",
      "type": "library",
      "name": "@angular/bazel",
      "version": "5.2.11-tuxcare.18",
      "purl": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.18"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:100df475-5cec-5271-9e82-1691f57ffa0b",
      "id": "CVE-2021-4231",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 5.2.11-tuxcare.18 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b41dc2bf-7c09-5484-8fca-b1620c487845",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 5.2.11-tuxcare.18 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7a1715d-07e0-5687-8b33-56808c36e956",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 5.2.11-tuxcare.18 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7e34ff9-cb77-5671-a871-f58d3960fe84",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 5.2.11-tuxcare.18 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bcc1722f-0dc6-5cbb-bb26-99ed073aee05",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 5.2.11-tuxcare.18 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:038b4321-a005-520c-848e-ea9e7bee1b9e",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 5.2.11-tuxcare.18 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01c4f4ff-18de-5114-bc0a-fdf077965e76",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 5.2.11-tuxcare.18 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2166b401-73fd-56c0-8359-9035da68082d",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 5.2.11-tuxcare.18 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e143a0f1-71fe-5c2e-9f27-2b0aa7fced14",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 5.2.11-tuxcare.18 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ae4b135-5a46-5108-9642-eb63bb75749d",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 5.2.11-tuxcare.18 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a691acf-1c14-53d3-9d2c-9e76451a6a33",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 5.2.11-tuxcare.18 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c0b82e0-999e-55f5-8b05-0b67071c6ac5",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 5.2.11-tuxcare.18 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88720239-4152-5108-92b8-21c710628007",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 5.2.11-tuxcare.18 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:874b4d87-c12c-5191-87ce-7688f8d7292b",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 5.2.11-tuxcare.18 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06830b93-de12-5302-943f-45696e5bdfa7",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 5.2.11-tuxcare.18 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5427061a-4478-5fcd-aa30-bbd6b840e75f",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 5.2.11-tuxcare.18 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e45c6f0-11d8-5b39-a6b4-987e54afc0f9",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 5.2.11-tuxcare.18 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b4f44d9-781b-52a8-b029-6d1b581c4726",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 5.2.11-tuxcare.18 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a26431b0-8fe4-5597-83c2-75ff6a5e35cf",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 5.2.11-tuxcare.18 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee906905-cc3f-55f1-991b-958cdb442da1",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 5.2.11-tuxcare.18 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4c19c58-e7aa-596a-834a-596f2bca4a35",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 5.2.11-tuxcare.18 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca1c268d-8cc3-58c1-a494-b2b9966d1bbc",
      "id": "CVE-2026-68945",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 5.2.11-tuxcare.18 of @angular/bazel. not_affected \u2014 Angular 5.2.11 is NOT affected by CVE-2026-68945. The vulnerable component `HttpTransferCache` does not exist in this version. This feature was introduced in Angular v16 as part of the modern SSR hydration system. Angular 5.2.11 only has the basic `TransferState` API (a generic key-value store for manual state transfer), not the automatic HTTP request caching interceptor that contains the vulne..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d217857e-760b-5213-b727-505b1b51fe1b",
      "id": "CVE-2026-69149",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 5.2.11-tuxcare.18 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8949c361-7088-51e5-9cbd-2049c4da4188",
      "id": "CVE-2026-69151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 5.2.11-tuxcare.18 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9067f8af-e2a4-5239-a222-e3be8804485d",
      "id": "CVE-2026-88056",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 5.2.11-tuxcare.18 of @angular/bazel. not_affected \u2014 Angular 5.2.11-tuxcare.19 does not contain the vulnerable URL resolution code pattern described in CVE-2026-88056. The vulnerability requires the url.ts file with parseUrl function calling String.prototype.trim() and the relativeUrlsTransformerInterceptorFn HTTP interceptor, both introduced in later Angular versions (post-June 2026). The target version uses a fundamentally different architectur..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47e83e52-05f6-5545-9e97-b50337ecb2a1",
      "id": "CVE-2026-88057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 5.2.11-tuxcare.18 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b17e1f69-e656-5d6a-ab7b-997e687b4825",
      "id": "CVE-2026-88059",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 5.2.11-tuxcare.18 of @angular/bazel. not_affected \u2014 Angular 5.2.11 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache with hierarchical HttpClient delegation (withRequestsMadeViaParent()), features that were introduced in Angular v16. Angular 5.2.11 predates these features by approximately 6+ years and contains only a basic HTTP interceptor architecture with no automatic response caching mechanism. While TransferStat..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.18"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70e352fe-348e-5d43-bd57-4a97691195f7",
      "id": "CVE-2026-88060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 5.2.11-tuxcare.18 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.18"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.18"
    }
  ]
}