{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:9f62c090-5762-599d-81d7-c3f735d49302",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/benchpress@4.4.7-tuxcare.10",
      "type": "library",
      "name": "@angular/benchpress",
      "version": "4.4.7-tuxcare.10",
      "purl": "pkg:npm/%40angular/benchpress@4.4.7-tuxcare.10"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:72d6dde2-0fac-53a9-be2f-00b14b9afb3f",
      "id": "CVE-2021-4231",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 4.4.7-tuxcare.10 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@4.4.7-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4b49720-9bc4-55ce-90b9-9a6a520b0ee3",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 4.4.7-tuxcare.10 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@4.4.7-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8269fac6-29c5-55c6-abbd-1e872d27f509",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 4.4.7-tuxcare.10 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@4.4.7-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2f7e929-8277-5e43-be8f-fdae5438e1c9",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 4.4.7-tuxcare.10 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@4.4.7-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:edd1c86e-ec9a-502b-86e9-b1dfc595e5b8",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 4.4.7-tuxcare.10 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@4.4.7-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52f5503c-57ec-5249-a9be-66e3b93491fb",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 4.4.7-tuxcare.10 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@4.4.7-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa805dfe-d199-54cc-849d-80330621e383",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 4.4.7-tuxcare.10 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@4.4.7-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e897efcc-678b-53ad-9adc-bec8c9ea9d18",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 4.4.7-tuxcare.10 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@4.4.7-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67c7ff6e-4331-50d1-88ad-eafa589f0044",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 4.4.7-tuxcare.10 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@4.4.7-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d956ede7-837d-5cad-851e-18bb5c6f945f",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 4.4.7-tuxcare.10 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@4.4.7-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b243bafa-1e6f-56e7-9add-e03ed3c45df4",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 4.4.7-tuxcare.10 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@4.4.7-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7fb6052-9280-55fc-a648-39b7634fb17d",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 4.4.7-tuxcare.10 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@4.4.7-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83b0ebc3-7f3c-55da-9e5b-2415102b7beb",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 4.4.7-tuxcare.10 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@4.4.7-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0bd16e27-a57e-513a-80b6-1a06787af6d3",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 4.4.7-tuxcare.10 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@4.4.7-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7123910f-279b-5e35-9b1d-3f6ad7adbcf3",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 4.4.7-tuxcare.10 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@4.4.7-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c827225-0df3-576d-aa39-2db7ea60f1e2",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 4.4.7-tuxcare.10 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@4.4.7-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02b4fe4d-5153-557c-9d4e-55682e130daf",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 4.4.7-tuxcare.10 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@4.4.7-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b874d32-e7b0-5b09-91b1-0bfd2780798e",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 4.4.7-tuxcare.10 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@4.4.7-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65f718db-cf69-55ef-899b-d0aee1dbf92c",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 4.4.7-tuxcare.10 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@4.4.7-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e92cbbb-27f8-503d-99fe-1421c16eee2a",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 4.4.7-tuxcare.10 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@4.4.7-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fafdf8d3-a136-52a3-8cfd-9d58a77b982e",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 4.4.7-tuxcare.10 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@4.4.7-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab169dc9-a345-5a0d-9157-0d1361f38e10",
      "id": "CVE-2026-68945",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 4.4.7-tuxcare.10 of @angular/benchpress. not_affected \u2014 Angular 4.4.7 is NOT AFFECTED by CVE-2026-68945. The vulnerable component (HttpTransferCache) does not exist in this version. HttpTransferCache was introduced in Angular v16 alongside the hydration feature, while this target is version 4.4.7 \u2014 predating the feature by 12+ major versions. Without HttpTransferCache, the cache key ambiguity vulnerability cannot manifest, as there is no SSR-to-clie..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@4.4.7-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48b1eaaa-b916-5058-a51d-a4d5dbd0cfae",
      "id": "CVE-2026-69149",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-69149 does not affect version 4.4.7-tuxcare.10 of @angular/benchpress. Angular 4.4.7 does not use domino for DOM emulation. The CVE specifically affects domino's serializer (lib/NodeUtils.js), which fails to escape text nodes in fallback raw-content elements (iframe, noembed, noframes, noscript). Angular 4.4.7 uses parse5 version 3.0.2 for HTML parsing and serialization instead. Domino was introduced to Angular approximately 6 years later in February 2023 (Angular 15+, commit 76731ae5c8). The vulnerable component (domino) is not present in this version, making it not affected by CVE-2026-69149."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@4.4.7-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8975f56c-3640-5a29-ac65-bd8d716f242b",
      "id": "CVE-2026-69151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 4.4.7-tuxcare.10 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@4.4.7-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc8559d2-fc33-548a-81bc-c45eaea64a68",
      "id": "CVE-2026-88056",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 4.4.7-tuxcare.10 of @angular/benchpress. not_affected \u2014 Angular 4.4.7-tuxcare.10 is not affected by CVE-2026-88056. The vulnerability requires a `urlStr.trim()` call in URL resolution that strips Unicode whitespace (U+00A0, U+FEFF), converting validated same-origin relative paths into cross-origin protocol-relative URLs. This vulnerable code pattern does not exist in Angular 4.4.7. The target version uses a simple `parseUrl()` function in `location...."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@4.4.7-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a179c4b-94e9-5cbc-b0d8-c60c0c99704d",
      "id": "CVE-2026-88057",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88057 does not affect version 4.4.7-tuxcare.10 of @angular/benchpress. not_affected \u2014 Angular 4.4.7 is not affected by CVE-2026-88057. This vulnerability specifically targets Angular's Ivy rendering engine (render3), which was introduced in Angular 8+ (2019). Angular 4.4.7 uses the older View Engine architecture. The vulnerable code path, including the template pipeline's resolve_sanitizers.ts and render3 component_ref.ts that were modified in the fix (commit 2f96c8020f), does n..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@4.4.7-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eee1355c-7554-5fa4-a32f-2ade6f9fce7b",
      "id": "CVE-2026-88059",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 4.4.7-tuxcare.10 of @angular/benchpress. not_affected \u2014 Angular 4.4.7 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, TransferState, hydration support, and hierarchical HttpClient configuration (withRequestsMadeViaParent()), none of which exist in this version. TransferState, the core mechanism for serializing HTTP responses into server-rendered HTML, was not introduced until a later Angular version (post-v4). The vu..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@4.4.7-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6015ce4-dc15-5edd-bbf3-dc4d878d2322",
      "id": "CVE-2026-88060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 4.4.7-tuxcare.10 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@4.4.7-tuxcare.10"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/benchpress@4.4.7-tuxcare.10"
    }
  ]
}