{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:592d600f-d8d7-588d-b33d-5bdfa4f9cd90",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/benchpress@5.2.11-tuxcare.14",
      "type": "library",
      "name": "@angular/benchpress",
      "version": "5.2.11-tuxcare.14",
      "purl": "pkg:npm/%40angular/benchpress@5.2.11-tuxcare.14"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:bef554ad-177a-5b90-9671-f0e57411e716",
      "id": "CVE-2021-4231",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 5.2.11-tuxcare.14 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61d0a607-9942-54d2-94e4-9a89b7e75f1b",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 5.2.11-tuxcare.14 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf3fae3b-256e-57cf-aff5-7429fa27ca23",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 5.2.11-tuxcare.14 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b590ed4f-07b0-593c-8895-6c896f36b0bf",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 5.2.11-tuxcare.14 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1960cc8e-421c-5296-afa7-aa0374e811d5",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 5.2.11-tuxcare.14 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a92c8ac-3412-5978-937c-302c6b387eb2",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 5.2.11-tuxcare.14 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81a24009-b8ca-57a3-a4b6-62f1eab10744",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 5.2.11-tuxcare.14 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1f934f8-637a-5304-927c-6efd70b08fe5",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 5.2.11-tuxcare.14 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2acafb3c-61eb-5393-8a69-bdf7ca4dd7fc",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 5.2.11-tuxcare.14 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ddd3bde-7e1f-5286-bdc0-4cdbba540b58",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 5.2.11-tuxcare.14 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55959947-eeb6-5824-bc9d-6c814863ef23",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 5.2.11-tuxcare.14 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4766677c-9e5e-5305-8e7e-bbb7660ac59b",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 5.2.11-tuxcare.14 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09e8b9a4-cead-5826-bee6-2ec6fdb3c3b9",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 5.2.11-tuxcare.14 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a984901-ba0c-5a89-b11b-3efdb25e50f9",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 5.2.11-tuxcare.14 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d13fa2e-c1ba-5ed8-bd5a-697f0dd34923",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 5.2.11-tuxcare.14 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a561505-3df0-5277-aa46-fcfa39b98c01",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 5.2.11-tuxcare.14 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5eb8de88-c3ee-5e74-b442-ac6dc97d4cad",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 5.2.11-tuxcare.14 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8cfad742-c7e2-5e21-8209-d965e372a9e8",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 5.2.11-tuxcare.14 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f19fda6f-e517-505d-9865-2909fc5e8038",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 5.2.11-tuxcare.14 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c694da61-b1df-56e7-9289-9226cf7fd0a7",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 5.2.11-tuxcare.14 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0903a276-8fb6-509c-87c1-a662c5423c30",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 5.2.11-tuxcare.14 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc2c6588-4000-59f6-bf32-6a593b391450",
      "id": "CVE-2026-68945",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 5.2.11-tuxcare.14 of @angular/benchpress. not_affected \u2014 Angular 5.2.11 is NOT affected by CVE-2026-68945. The vulnerable component `HttpTransferCache` does not exist in this version. This feature was introduced in Angular v16 as part of the modern SSR hydration system. Angular 5.2.11 only has the basic `TransferState` API (a generic key-value store for manual state transfer), not the automatic HTTP request caching interceptor that contains the vulne..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:039dddf1-a6d1-5638-8a9e-190e19d7ff7a",
      "id": "CVE-2026-69149",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 5.2.11-tuxcare.14 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0bd9cc27-31ff-5773-ad23-58c81c59935b",
      "id": "CVE-2026-69151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 5.2.11-tuxcare.14 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da75b35c-a39a-5d17-a1d8-54ce332d9886",
      "id": "CVE-2026-88056",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 5.2.11-tuxcare.14 of @angular/benchpress. not_affected \u2014 Angular 5.2.11-tuxcare.19 does not contain the vulnerable URL resolution code pattern described in CVE-2026-88056. The vulnerability requires the url.ts file with parseUrl function calling String.prototype.trim() and the relativeUrlsTransformerInterceptorFn HTTP interceptor, both introduced in later Angular versions (post-June 2026). The target version uses a fundamentally different architectur..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85e81fd1-2075-5c00-b504-cb866475bae1",
      "id": "CVE-2026-88057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 5.2.11-tuxcare.14 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56f9191f-0fc3-537a-a8c3-df2bbe69430f",
      "id": "CVE-2026-88059",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 5.2.11-tuxcare.14 of @angular/benchpress. not_affected \u2014 Angular 5.2.11 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache with hierarchical HttpClient delegation (withRequestsMadeViaParent()), features that were introduced in Angular v16. Angular 5.2.11 predates these features by approximately 6+ years and contains only a basic HTTP interceptor architecture with no automatic response caching mechanism. While TransferStat..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e8d6dda-f27c-56cc-b596-a0cebae17982",
      "id": "CVE-2026-88060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 5.2.11-tuxcare.14 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@5.2.11-tuxcare.14"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/benchpress@5.2.11-tuxcare.14"
    }
  ]
}