{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:571afc66-f8d2-569d-9352-298754d4c0b9",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/common@13.3.11-tuxcare.3",
      "type": "library",
      "name": "@angular/common",
      "version": "13.3.11-tuxcare.3",
      "purl": "pkg:npm/%40angular/common@13.3.11-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:debd90e3-73de-572d-a4bb-1129cce3099e",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 13.3.11-tuxcare.3 of @angular/common."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@13.3.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e834051f-41e5-58f3-9458-46fd9cec37f2",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 13.3.11-tuxcare.3 of @angular/common."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@13.3.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9046f677-dc4a-5204-b354-24641c3f68f6",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 13.3.11-tuxcare.3 of @angular/common."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@13.3.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7684f537-abe6-5dd6-b9f3-bc26e4ae9ba4",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 13.3.11-tuxcare.3 of @angular/common."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@13.3.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b059a397-ddaf-53d2-a0ee-636a0c77f2ee",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 13.3.11-tuxcare.3 of @angular/common."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@13.3.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f20c4ae3-248f-5210-aa23-5f560c9cf946",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 13.3.11-tuxcare.3 of @angular/common."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@13.3.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:624aa4fa-b08c-506a-a368-54fcc903c1ab",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 13.3.11-tuxcare.3 of @angular/common."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@13.3.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e1f8211-b445-5331-8ba4-bdbcc273e0c6",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 13.3.11-tuxcare.3 of @angular/common."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@13.3.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:594a3938-080a-5b22-9dc6-f988410af017",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 13.3.11-tuxcare.3 of @angular/common."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@13.3.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:964c95a1-ca34-523c-b19f-81e207b00258",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 13.3.11-tuxcare.3 of @angular/common."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@13.3.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09b628fa-eca4-5d70-9030-4a3313b67c00",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 13.3.11-tuxcare.3 of @angular/common."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@13.3.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:485bd491-95fb-5a3f-a726-f8e80152b94d",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 13.3.11-tuxcare.3 of @angular/common."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@13.3.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d59b61ae-1c30-57e0-9e2e-5d9bde6d103f",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 13.3.11-tuxcare.3 of @angular/common."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@13.3.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96a7f67e-7201-5de4-9783-d1d654a5a23d",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 13.3.11-tuxcare.3 of @angular/common."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@13.3.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d92da5fa-101c-5364-bde4-5547b6de6ca3",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 13.3.11-tuxcare.3 of @angular/common."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@13.3.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ffe6d2c-8eda-5566-a851-75cdde8dddd7",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 13.3.11-tuxcare.3 of @angular/common."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@13.3.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a48bf2aa-b63b-5664-b590-ebdf5b147a60",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 13.3.11-tuxcare.3 of @angular/common."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@13.3.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cabbba75-4352-5c1e-83fe-7d06ac27b058",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 13.3.11-tuxcare.3 of @angular/common."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@13.3.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74ddb4e9-dc1a-5932-88b9-4e7c7d78a803",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 13.3.11-tuxcare.3 of @angular/common."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@13.3.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1283d31-17a4-5cfb-b35e-54390a427175",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 13.3.11-tuxcare.3 of @angular/common."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@13.3.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d32ad044-9018-52e8-8567-46b85b6addf4",
      "id": "CVE-2026-68945",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 13.3.11-tuxcare.3 of @angular/common. not_affected \u2014 Angular 13.3.11 is NOT affected by CVE-2026-68945. The vulnerable HttpTransferCache feature does not exist in this version. HttpTransferCache was introduced in Angular 16.0.0-next.0 (March 2023), approximately 3 years after Angular 13.3.11's release. The target version only contains the basic TransferState mechanism for generic state transfer, but lacks the automated HTTP request caching functi..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@13.3.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfad10a8-0c3e-516c-9566-7472dd19a936",
      "id": "CVE-2026-69149",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 13.3.11-tuxcare.3 of @angular/common."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@13.3.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33ea7dcf-9afe-51d1-8708-f423558edf2e",
      "id": "CVE-2026-69151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 13.3.11-tuxcare.3 of @angular/common."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@13.3.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7573b020-21eb-59a0-a59e-31251c1c0935",
      "id": "CVE-2026-88056",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 13.3.11-tuxcare.3 of @angular/common. not_affected \u2014 Angular 13.3.11 is not affected by CVE-2026-88056. The vulnerable code path (the `parseUrl`/`resolveUrl` functions in `packages/platform-server/src/url.ts` that executed `String.prototype.trim()`) did not exist in Angular 13.x. This file and the associated vulnerability were introduced in Angular 19.x+. TuxCare later backported a post-fix version of `url.ts` (without `trim()`) to address CVE-20..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@13.3.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2dd729d-76fd-5b7e-9a4d-edaf6d37290f",
      "id": "CVE-2026-88057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 13.3.11-tuxcare.3 of @angular/common."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@13.3.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbc6a2a6-5f0d-588f-baf5-1b38e792a5f0",
      "id": "CVE-2026-88059",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 13.3.11-tuxcare.3 of @angular/common. not_affected \u2014 Angular 13.3.11 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache (an automatic HTTP response caching interceptor for SSR hydration) and the functional provider API (provideHttpClient, withRequestsMadeViaParent, provideClientHydration), none of which exist in this version. These features were introduced in Angular v16.0.0, three major versions after 13.3.11. The ta..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@13.3.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ad8457e-09d3-5706-a3a2-c0bc3c8b3a02",
      "id": "CVE-2026-88060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 13.3.11-tuxcare.3 of @angular/common."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@13.3.11-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/common@13.3.11-tuxcare.3"
    }
  ]
}