{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:cffd61ab-8c68-56ad-8033-0fa9b80a1f2f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.14",
      "type": "library",
      "name": "@angular/compiler",
      "version": "5.2.11-tuxcare.14",
      "purl": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.14"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:b8450333-2cbd-5bb5-b4cd-2d9a7e390e30",
      "id": "CVE-2021-4231",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 5.2.11-tuxcare.14 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b4ddc96-52fe-5591-ba2e-f2287c561777",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 5.2.11-tuxcare.14 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5187344c-86de-5eb1-a910-c5ff70d59514",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 5.2.11-tuxcare.14 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb08a51d-ec41-5e08-b1e8-be185e8011d9",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 5.2.11-tuxcare.14 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99119c4e-afa9-5896-b5c9-5a752c804f7f",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 5.2.11-tuxcare.14 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d7a1b62-3faf-5cac-96fb-2c3334ef2591",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 5.2.11-tuxcare.14 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d0e7711-b468-56a1-972a-6f1cb7f9d29d",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 5.2.11-tuxcare.14 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04a5575f-f32e-54a6-b279-7224d17c3767",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 5.2.11-tuxcare.14 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc56ef7a-8727-5634-a27f-104142a762cf",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 5.2.11-tuxcare.14 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c20d651-6081-593d-a4d7-a103a7bd1334",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 5.2.11-tuxcare.14 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1361629-c9e3-529e-bfc9-5f4b23268f86",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 5.2.11-tuxcare.14 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:539ef0b7-1336-5468-9227-23a4548549ae",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 5.2.11-tuxcare.14 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bac0ba47-732b-5e88-a278-450f2025829f",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 5.2.11-tuxcare.14 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c05cdeeb-77d6-5aaf-8819-f184d5da384b",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 5.2.11-tuxcare.14 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a016a30-095e-51c6-829c-fcd51434c337",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 5.2.11-tuxcare.14 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00a934e4-0cf7-505f-917e-b97e514a79f9",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 5.2.11-tuxcare.14 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e84be72-56db-595f-bbf8-f3784b0d67bd",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 5.2.11-tuxcare.14 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9aad9208-0f8d-5c83-8590-0e122e74205c",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 5.2.11-tuxcare.14 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac2887db-7d3d-5b6f-ac24-b8e9595d2adf",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 5.2.11-tuxcare.14 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5edbccf9-ea74-5727-9128-5a3174646db7",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 5.2.11-tuxcare.14 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c728f146-9300-5ac8-ad39-e73a3791e39d",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 5.2.11-tuxcare.14 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46b133b4-4d37-506a-81f4-474b0a130b17",
      "id": "CVE-2026-68945",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 5.2.11-tuxcare.14 of @angular/compiler. not_affected \u2014 Angular 5.2.11 is NOT affected by CVE-2026-68945. The vulnerable component `HttpTransferCache` does not exist in this version. This feature was introduced in Angular v16 as part of the modern SSR hydration system. Angular 5.2.11 only has the basic `TransferState` API (a generic key-value store for manual state transfer), not the automatic HTTP request caching interceptor that contains the vulne..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04d74eb6-d047-5f34-a254-fea27226ee46",
      "id": "CVE-2026-69149",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 5.2.11-tuxcare.14 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8c84b93-6f91-5854-9537-3583c5e32780",
      "id": "CVE-2026-69151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 5.2.11-tuxcare.14 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41b6f195-d71a-5790-a97b-a51612cfab91",
      "id": "CVE-2026-88056",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 5.2.11-tuxcare.14 of @angular/compiler. not_affected \u2014 Angular 5.2.11-tuxcare.19 does not contain the vulnerable URL resolution code pattern described in CVE-2026-88056. The vulnerability requires the url.ts file with parseUrl function calling String.prototype.trim() and the relativeUrlsTransformerInterceptorFn HTTP interceptor, both introduced in later Angular versions (post-June 2026). The target version uses a fundamentally different architectur..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8a34e65-623c-51e6-8392-c3acb312b15f",
      "id": "CVE-2026-88057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 5.2.11-tuxcare.14 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22992252-fa35-5a18-b4bb-0a18d7a369b7",
      "id": "CVE-2026-88059",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 5.2.11-tuxcare.14 of @angular/compiler. not_affected \u2014 Angular 5.2.11 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache with hierarchical HttpClient delegation (withRequestsMadeViaParent()), features that were introduced in Angular v16. Angular 5.2.11 predates these features by approximately 6+ years and contains only a basic HTTP interceptor architecture with no automatic response caching mechanism. While TransferStat..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd785f51-75ef-53ef-a778-85bae2cc37ca",
      "id": "CVE-2026-88060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 5.2.11-tuxcare.14 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.14"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.14"
    }
  ]
}