{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:934c7293-e0ff-54b0-b0e6-a050e5ee51cb",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.11",
      "type": "library",
      "name": "@angular/benchpress",
      "version": "8.2.14-tuxcare.11",
      "purl": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.11"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:37141907-f0c1-5993-a8ae-2c4af4387c23",
      "id": "CVE-2021-4231",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 8.2.14-tuxcare.11 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:488becea-a0d4-5932-a293-90363aad1ab8",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 8.2.14-tuxcare.11 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a2ec6a2-30c2-5e29-9f6f-a15f1958712e",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 8.2.14-tuxcare.11 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bcba0db-5d63-5ced-ba3c-5c54ecbd7581",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 8.2.14-tuxcare.11 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d4f9a25-6339-5de9-b612-dc6d7d260323",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 8.2.14-tuxcare.11 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8a69390-0c15-5eea-bd2e-ff72f4cd77ca",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 8.2.14-tuxcare.11 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a5d9c1b-d2d5-5470-b638-5968114f5a30",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 8.2.14-tuxcare.11 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb23f341-9259-51bd-b7d5-a331864eae41",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 8.2.14-tuxcare.11 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fe9b540-d54d-53ae-89ca-8f77bd4c867c",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 8.2.14-tuxcare.11 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89426e7d-b53e-5863-93b6-4ec746b24abe",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 8.2.14-tuxcare.11 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:138bafa9-7ffd-507f-8b6a-9d0f000cae1c",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 8.2.14-tuxcare.11 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45725bde-8ff6-5f0d-9a59-7856c9a3a876",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 8.2.14-tuxcare.11 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8d03b3e-8112-5713-82b6-3fbaf9c2e2a4",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 8.2.14-tuxcare.11 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4ed85fc-a6d4-5acc-a183-6556e4b88794",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 8.2.14-tuxcare.11 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31a58c4c-be8e-5801-bf35-3294ecf1ffa9",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 8.2.14-tuxcare.11 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46841757-ea35-56b3-bba5-6f9ab047c8e4",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 8.2.14-tuxcare.11 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:837dec41-2f95-5160-a2e6-fe28e0260283",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 8.2.14-tuxcare.11 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0391fa93-8107-59fd-84fe-325e94d86102",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 8.2.14-tuxcare.11 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a072833-c097-56ad-a647-6bcb2d84dc75",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 8.2.14-tuxcare.11 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9594dd76-9af5-50cc-833b-d2e1a9cab4a6",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 8.2.14-tuxcare.11 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1dfe059d-1120-563c-8b30-15fb8aa6402e",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 8.2.14-tuxcare.11 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0751380c-e025-5c08-bdcf-e6bb971c580e",
      "id": "CVE-2026-68945",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 8.2.14-tuxcare.11 of @angular/benchpress. not_affected \u2014 Angular 8.2.14 is NOT affected by CVE-2026-68945. The vulnerability exists in HttpTransferCache, a feature that automatically caches HTTP requests during SSR for client hydration. HttpTransferCache was introduced in Angular v16+ and does not exist in version 8.2.14. This version has only a manual TransferState key-value store with no automatic HttpClient integration, and no HTTP caching mechani..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20ffbf2b-dd26-5d58-ac48-0c6d73e1b241",
      "id": "CVE-2026-69149",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 8.2.14-tuxcare.11 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afeb3c2f-f655-5018-9176-45d7e06ba912",
      "id": "CVE-2026-69151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 8.2.14-tuxcare.11 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73d9df7f-40c0-548b-bd93-4198c114f0e0",
      "id": "CVE-2026-88056",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 8.2.14-tuxcare.11 of @angular/benchpress. not_affected \u2014 Angular 8.2.14 is NOT AFFECTED by CVE-2026-88056. The vulnerability requires a sophisticated URL resolution utility (`parseUrl` in `packages/platform-server/src/url.ts`) that calls `String.prototype.trim()` to strip Unicode whitespace, creating a discrepancy with WHATWG URL validation. This architecture was introduced in Angular v12+ (circa 2026 as TuxCare backports). Angular 8.2.14 (released N..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9c7c465-b9b8-5e27-b356-2cae7e079e72",
      "id": "CVE-2026-88057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 8.2.14-tuxcare.11 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f29f2b3b-397f-565c-963f-55dd22960d5f",
      "id": "CVE-2026-88059",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 8.2.14-tuxcare.11 of @angular/benchpress. not_affected \u2014 Angular v8.2.14 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, provideClientHydration(), and withRequestsMadeViaParent() \u2014 all features that do not exist in this version. These features were introduced in Angular v16 (per patches/CVE-2026-50170.patch and patches/CVE-2026-54266.patch). The target uses the legacy NgModule-based HttpClientModule without automatic ..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c7b0ada-4149-5e33-8e16-0cdf17eef95e",
      "id": "CVE-2026-88060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 8.2.14-tuxcare.11 of @angular/benchpress."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.11"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/benchpress@8.2.14-tuxcare.11"
    }
  ]
}