{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d2417d75-50ef-54bc-8b78-7db41535a3f1",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.19",
      "type": "library",
      "name": "@angular/compiler",
      "version": "5.2.11-tuxcare.19",
      "purl": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.19"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:c58541d1-31e7-5eb3-a08a-98998cfef763",
      "id": "CVE-2021-4231",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 5.2.11-tuxcare.19 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20b9ba8b-1eb1-5f5e-a99e-937023e59ea4",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 5.2.11-tuxcare.19 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98133f46-188f-52a6-bd90-af31f7f1b29e",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 5.2.11-tuxcare.19 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff9e4338-6e01-52e2-a12c-a520b427f89e",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 5.2.11-tuxcare.19 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:011e63b4-65c6-58e1-b7b1-cd01de658665",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 5.2.11-tuxcare.19 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e7c5add-83ec-5e81-9c48-f6bc661a18ad",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 5.2.11-tuxcare.19 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7db9ad2a-d800-55ae-a475-17ceebc21102",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 5.2.11-tuxcare.19 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84624edc-dcfa-519d-8279-e167d2c52e12",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 5.2.11-tuxcare.19 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85d6e42e-825a-576b-b4a8-c6c16247ade7",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 5.2.11-tuxcare.19 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93101d49-13da-5f76-91ce-b6f68257288e",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 5.2.11-tuxcare.19 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8c5b279-a64d-5f66-b828-62487c1bcd01",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 5.2.11-tuxcare.19 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cca74ad3-57a4-5981-b5ca-0dc6dfe5bed7",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 5.2.11-tuxcare.19 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2eb68b99-351c-57b3-a505-9aeab281b49e",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 5.2.11-tuxcare.19 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6c91803-b2f6-5904-aa28-182e41f343a9",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 5.2.11-tuxcare.19 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ee4105b-8096-5c0f-b0c8-8db7927060da",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 5.2.11-tuxcare.19 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11df3721-d2e7-56cf-9e8f-6cfe42ac7873",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 5.2.11-tuxcare.19 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0324baf-df9c-5210-be90-249325b56361",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 5.2.11-tuxcare.19 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f19b0ae-3c37-5efb-b179-ba78adebb98f",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 5.2.11-tuxcare.19 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87f7c8b0-02bc-56d3-a70b-efa8ed9a2652",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 5.2.11-tuxcare.19 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75df5f6c-6a99-5bac-9e8d-23b9146b0d13",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 5.2.11-tuxcare.19 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c89f44d8-9ffd-5aee-94ef-cbabd3c58eaa",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 5.2.11-tuxcare.19 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:214d55dc-4219-5f56-9ea0-133172f92873",
      "id": "CVE-2026-68945",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 5.2.11-tuxcare.19 of @angular/compiler. not_affected \u2014 Angular 5.2.11 is NOT affected by CVE-2026-68945. The vulnerable component `HttpTransferCache` does not exist in this version. This feature was introduced in Angular v16 as part of the modern SSR hydration system. Angular 5.2.11 only has the basic `TransferState` API (a generic key-value store for manual state transfer), not the automatic HTTP request caching interceptor that contains the vulne..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f29b5753-5798-5e20-a0ea-5fc5ffaea20a",
      "id": "CVE-2026-69149",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 5.2.11-tuxcare.19 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f79c80e-3b6d-5d6a-9008-623dd8ffb92a",
      "id": "CVE-2026-69151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 5.2.11-tuxcare.19 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:debbef63-8ee4-53f7-9650-1c00b9a6dcf9",
      "id": "CVE-2026-88056",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 5.2.11-tuxcare.19 of @angular/compiler. not_affected \u2014 Angular 5.2.11-tuxcare.19 does not contain the vulnerable URL resolution code pattern described in CVE-2026-88056. The vulnerability requires the url.ts file with parseUrl function calling String.prototype.trim() and the relativeUrlsTransformerInterceptorFn HTTP interceptor, both introduced in later Angular versions (post-June 2026). The target version uses a fundamentally different architectur..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:092ed676-30a7-51d4-a1d9-4384849eca4e",
      "id": "CVE-2026-88057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 5.2.11-tuxcare.19 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b128724-9379-5084-b8a2-84c06051a69c",
      "id": "CVE-2026-88059",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 5.2.11-tuxcare.19 of @angular/compiler. not_affected \u2014 Angular 5.2.11 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache with hierarchical HttpClient delegation (withRequestsMadeViaParent()), features that were introduced in Angular v16. Angular 5.2.11 predates these features by approximately 6+ years and contains only a basic HTTP interceptor architecture with no automatic response caching mechanism. While TransferStat..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02cdada3-93f6-548d-8d67-064162893230",
      "id": "CVE-2026-88060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 5.2.11-tuxcare.19 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.19"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.19"
    }
  ]
}