{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:64381de9-7a8b-5065-9596-dccfe0561ad2",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/compiler@5.1.2-tuxcare.4",
      "type": "library",
      "name": "@angular/compiler",
      "version": "5.1.2-tuxcare.4",
      "purl": "pkg:npm/%40angular/compiler@5.1.2-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:07d850c3-cf9c-56e7-8d26-076cd68cac8f",
      "id": "CVE-2021-4231",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 5.1.2-tuxcare.4 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3bf78b0a-c761-52d1-ba10-c06757528c81",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 5.1.2-tuxcare.4 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e08b666-8f68-5a25-a922-1ff1fc7de8e5",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 5.1.2-tuxcare.4 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9a4c9b0-97ec-53f3-9f24-e29c7ebf32ba",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 5.1.2-tuxcare.4 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ced47b1c-8b47-55b3-b2be-667cd6eeaef9",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 5.1.2-tuxcare.4 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fbeab81-413b-5c94-baab-bda372582704",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41423 does not affect version 5.1.2-tuxcare.4 of @angular/compiler. not_affected \u2014 Angular version 5.1.2 is not affected by CVE-2026-41423. The vulnerability requires the WHATWG URL API which exhibits hostname override behavior with protocol-relative URLs. The target uses Node.js's legacy url.parse() API which does not have this behavior."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18f99a45-6b12-5162-850c-593431fe8dc1",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 5.1.2-tuxcare.4 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd78a210-1bcd-51de-bad3-03056eee2b6f",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 5.1.2-tuxcare.4 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:524deeef-5c2a-5796-92e0-7e4e8fd58ffe",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 5.1.2-tuxcare.4 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43a6737e-689a-5d40-8079-a04e01b0b9ec",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50170 does not affect version 5.1.2-tuxcare.4 of @angular/compiler. not_affected \u2014 no evidence captured"
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17f5fa6c-aa40-5e57-a18d-ba42cb8385a5",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 5.1.2-tuxcare.4 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2894cd8e-77b3-59c6-9217-720e7d9f5fe0",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 5.1.2-tuxcare.4 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:181a50ca-ea92-5a50-a474-3a3cf5c1aa84",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 5.1.2-tuxcare.4 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:006a4054-239f-5864-b5d4-332116cd3370",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 5.1.2-tuxcare.4 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:687eadeb-434d-560f-88b5-0307c538d1de",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 5.1.2-tuxcare.4 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f6cf77c-6224-5aa6-bdeb-8d554401786f",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 5.1.2-tuxcare.4 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:924bbfa4-daac-529d-b986-d49d0c851606",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54264 does not affect version 5.1.2-tuxcare.4 of @angular/compiler. not_affected \u2014 Angular v5.1.2-tuxcare.1 is NOT affected by CVE-2026-54264. The vulnerability requires a `newRequestWithMetadata` function that copies request headers, which does not exist in this version. The service worker reconstructs asset requests from URLs only using bare `adapter.newRequest(url)` calls, never copying or forwarding request headers. Therefore, credential headers cannot be leaked on cross-..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c4fa34c-585c-559b-bebe-8879003ccb66",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 5.1.2-tuxcare.4 of @angular/compiler. not_affected \u2014 Angular 5.1.2 uses the View Engine compiler architecture, which does not have the TwoWayProperty operation kind that is vulnerable in the Ivy compiler. In View Engine, two-way bindings desugar through the same parsePropertyBinding() code path as one-way bindings, ensuring both receive identical security context resolution and sanitization. The vulnerability pattern described in CVE-2026-54265 c..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb83795c-326c-5418-b1eb-7b93a26c83ab",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54266 does not affect version 5.1.2-tuxcare.4 of @angular/compiler. not_affected \u2014 Angular 5.1.2 is not affected by CVE-2026-54266. The vulnerable HttpTransferCache feature that generates cache keys using a weak 32-bit DJB2 hash does not exist in this version. This feature was introduced in Angular v16+, while the target is v5.1.2. Although TransferState exists in this version for basic state transfer, there is no integration with HttpClient for automatic response caching, no..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36eccb55-7379-59fa-91c2-9a8c98c26d6b",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 5.1.2-tuxcare.4 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d9cad2b-aa62-5ccd-8599-01318976d776",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 5.1.2-tuxcare.4 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14a0be8c-01e3-5b77-b401-40c3a72f0afb",
      "id": "CVE-2026-68945",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 5.1.2-tuxcare.4 of @angular/compiler. not_affected \u2014 Angular 5.1.2 is not affected by CVE-2026-68945. The vulnerable component HttpTransferCache does not exist in this version. HttpTransferCache was introduced in Angular v16 (circa 2022), while this target is Angular 5.1.2 (2017-2018 era). Although Angular 5.1.2 has TransferState for basic SSR state transfer and HttpClient with HttpParams, it lacks the HTTP response caching mechanism during SSR t..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:210a5a65-b160-5504-a790-2c277c39ac7f",
      "id": "CVE-2026-69149",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 5.1.2-tuxcare.4 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4012f8f0-4c30-5637-8aff-7765fe7722f8",
      "id": "CVE-2026-69151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 5.1.2-tuxcare.4 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cafb343f-ff45-5e42-8685-419a3f175d87",
      "id": "CVE-2026-88056",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 5.1.2-tuxcare.4 of @angular/compiler. not_affected \u2014 Angular 5.1.2 is not affected by CVE-2026-88056. The vulnerability requires a URL resolution utility in @angular/platform-server that strips Unicode whitespace during SSR HTTP request processing, causing same-origin URLs like `http://trusted/%C2%A0//attacker.example` to become cross-origin requests. Angular 5.1.2 lacks this mechanism entirely: (1) The vulnerable code (url.ts with parseUrl calli..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efecfa54-db3e-57c2-a5bd-91e837e6a3ce",
      "id": "CVE-2026-88057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 5.1.2-tuxcare.4 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ea53add-6ebb-51e6-9f89-f5dd5e353940",
      "id": "CVE-2026-88059",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 5.1.2-tuxcare.4 of @angular/compiler. not_affected \u2014 CVE-2026-88059 affects Angular's HttpTransferCache utility when used with hierarchical HttpClient configuration (withRequestsMadeViaParent()) during SSR and hydration. These features were introduced in Angular v16. The target version (5.1.2) does not contain HttpTransferCache, withRequestsMadeViaParent(), or the hydration features required for this vulnerability. TuxCare's own patch analyses fo..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.1.2-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80c65036-9b41-53f6-8232-3d8fe4dfc533",
      "id": "CVE-2026-88060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 5.1.2-tuxcare.4 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.1.2-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/compiler@5.1.2-tuxcare.4"
    }
  ]
}