{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:1b591e44-55e7-57a1-a675-b9ad8f8df498",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/benchpress@13.4.0-tuxcare.9",
      "type": "library",
      "name": "@angular/benchpress",
      "version": "13.4.0-tuxcare.9",
      "purl": "pkg:npm/%40angular/benchpress@13.4.0-tuxcare.9"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:fdaedbec-9f8a-532d-bfd8-1e877302e4a3",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 13.4.0-tuxcare.9 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@13.4.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:276f4764-7b8a-5122-aaea-967410a9479f",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 13.4.0-tuxcare.9 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@13.4.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:349b59b6-316b-506f-a735-0cd1d523c4e5",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 13.4.0-tuxcare.9 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@13.4.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efc28dea-2783-50cc-a9b4-4d18faceb0fd",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 13.4.0-tuxcare.9 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@13.4.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c103b126-c6ce-55cc-9a63-bc25eef52d5b",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 13.4.0-tuxcare.9 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@13.4.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39d49439-6838-59be-86e8-e59b5279c734",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 13.4.0-tuxcare.9 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@13.4.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9cecdb4e-7dd2-5400-a16b-31b682896dd6",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 13.4.0-tuxcare.9 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@13.4.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a49db86c-8a2d-5f81-9159-d4513ceb1e54",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 13.4.0-tuxcare.9 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@13.4.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6edd232e-c956-5992-87e9-5116b71d4010",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 13.4.0-tuxcare.9 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@13.4.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3243466-434b-5c8a-92cd-175b3e3dbf7d",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 13.4.0-tuxcare.9 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@13.4.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:324417f8-616d-5047-9293-48258f0bc4fd",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 13.4.0-tuxcare.9 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@13.4.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35caaebc-6639-5db4-91d6-87e5701a6e92",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 13.4.0-tuxcare.9 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@13.4.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46fbd68f-95a0-50f6-8819-dfb60f3890e2",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 13.4.0-tuxcare.9 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@13.4.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c8a263e-513e-5207-9c29-74f0b7f5692d",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 13.4.0-tuxcare.9 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@13.4.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7eb656d5-5128-5101-92cd-93fbc8fac260",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 13.4.0-tuxcare.9 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@13.4.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d1564e6-e491-5cdb-8184-679d479c3737",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 13.4.0-tuxcare.9 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@13.4.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c604fe99-03cf-5418-a321-a0d37b29c5f9",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 13.4.0-tuxcare.9 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@13.4.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96c35041-03fd-57ed-9973-6ca8e8fa0d50",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 13.4.0-tuxcare.9 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@13.4.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec620bfa-0009-5063-9506-ab8ede1bc4b7",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 13.4.0-tuxcare.9 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@13.4.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c13af03-14f5-5518-b516-a155cd00c4d5",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 13.4.0-tuxcare.9 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@13.4.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:631ca516-ae05-52a2-b780-d54b2e6b78f2",
      "id": "CVE-2026-68945",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 13.4.0-tuxcare.9 of @angular/benchpress. not_affected \u2014 Angular v13.4.0 is NOT AFFECTED by CVE-2026-68945. The HttpTransferCache feature, which is the subject of this vulnerability, was introduced in Angular v16.0.0 and does not exist in v13.4.0. Without HttpTransferCache, the cache key collision vulnerability involving HttpParams serialization cannot occur. This assessment is consistent with two other HttpTransferCache CVEs (CVE-2026-54266 and CVE-..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@13.4.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6541b87-673b-55d8-abd1-8c8f55e8fbea",
      "id": "CVE-2026-69149",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 13.4.0-tuxcare.9 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@13.4.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e1cd335-5bb4-5080-a130-e1dca6a36d32",
      "id": "CVE-2026-69151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 13.4.0-tuxcare.9 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@13.4.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b35ae2d8-9630-5e8c-b72c-fe944b485794",
      "id": "CVE-2026-88056",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 13.4.0-tuxcare.9 of @angular/benchpress. not_affected \u2014 Angular version 13.4.0 is not affected by CVE-2026-88056. The vulnerable code pattern (String.prototype.trim() on URL strings in parseUrl) never existed in this version. The url.ts file was created by TuxCare in June 2026 (commit 0a33393ba5) with a safe implementation that preserves Unicode whitespace, preventing the attack vector described in the CVE. The vulnerability was introduced and fixed..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@13.4.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd21ca58-5066-5dce-966b-1810dd45e2d4",
      "id": "CVE-2026-88057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 13.4.0-tuxcare.9 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@13.4.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e381a67e-1afa-5752-b1bd-49cf1f0ff9dc",
      "id": "CVE-2026-88059",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 13.4.0-tuxcare.9 of @angular/benchpress. not_affected \u2014 Angular 13.4.0 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache and hierarchical HttpClient delegation (withRequestsMadeViaParent()), features that were introduced in Angular 16.0.0. These features do not exist in Angular 13.4.0, making the attack vector impossible. This assessment is consistent with the repository's own documentation of related CVE-2026-50170, wh..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@13.4.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4997142-baae-5935-a9e3-174f963ff515",
      "id": "CVE-2026-88060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 13.4.0-tuxcare.9 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@13.4.0-tuxcare.9"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/benchpress@13.4.0-tuxcare.9"
    }
  ]
}