{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4a11ff66-6a07-5425-a938-e1d7c3ff1e82",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/core@15.0.3",
      "type": "library",
      "name": "@angular/core",
      "version": "15.0.3",
      "purl": "pkg:npm/%40angular/core@15.0.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:952adfec-83f6-58c1-a72a-daff424e1711",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50170 does not affect version 15.0.3 of @angular/core. not_affected \u2014 Angular 15.0.3-tuxcare.1 is NOT affected by CVE-2026-50170. The HTTP TransferCache feature that is vulnerable in later Angular versions (v16+) does not exist in this version. The vulnerable code (transfer_cache.ts, hasAuthHeaders(), shouldCacheRequest(), withHttpTransferCache, provideClientHydration) is absent from Angular 15.0.3."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@15.0.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d986b7f5-fb1c-5d33-ae8c-1c6039504f85",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 15.0.3 of @angular/core. not_affected \u2014 Angular 15.0.3 is NOT AFFECTED by CVE-2026-54265. This version uses a different compiler architecture where two-way bindings desugar through the same code path as one-way bindings, both receiving identical security context resolution and sanitizer assignment. The vulnerable code (Ivy template pipeline with separate TwoWayProperty operation type) does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@15.0.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7251b856-ac3c-5f5f-b291-0aff2f7836ec",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54266 does not affect version 15.0.3 of @angular/core. not_affected \u2014 Angular v15.0.3-tuxcare.1 is NOT affected by CVE-2026-54266. The vulnerable HttpTransferCache feature with weak DJB2 hash-based cache keys does not exist in this version. This feature was introduced in Angular v16+. The target has no code path from HTTP request handling to the vulnerability's cache poisoning goal."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@15.0.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aec8822c-ef51-5005-bcda-edecef660dc8",
      "id": "CVE-2026-68945",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 15.0.3 of @angular/core. not_affected \u2014 Angular 15.0.3 is not affected by CVE-2026-68945. The vulnerable HttpTransferCache feature for SSR HTTP request caching does not exist in this version. HttpTransferCache was introduced in Angular v16.0.0 (commit aff1512950, March 31, 2023) and the target version predates this feature entirely. Without HttpTransferCache, there is no cache key generation logic that could exhibit the comma-joining..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@15.0.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d92c9bc4-b291-5adb-81d3-b8fef6cdef5c",
      "id": "CVE-2026-88056",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 15.0.3 of @angular/core. not_affected \u2014 Angular v15.0.3-tuxcare.4 is NOT affected by CVE-2026-88056. The vulnerability requires Unicode whitespace stripping via String.prototype.trim() in URL resolution utilities, which creates a discrepancy between WHATWG URL validation and Angular's URL resolution. This vulnerable code pattern was introduced in Angular v19+ refactoring (commit 6e71049021) and fixed in v20.3.29+. Version 15.0.3 uses..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@15.0.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5837da2-c706-5dab-8604-da0cc68fabd7",
      "id": "CVE-2026-88057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 15.0.3 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@15.0.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74961cd9-474d-5767-9118-ddae6dc3e92a",
      "id": "CVE-2026-88059",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 15.0.3 of @angular/core. not_affected \u2014 Angular 15.0.3 is NOT AFFECTED by CVE-2026-88059. The vulnerability exists in the HttpTransferCache utility when used with SSR hydration and hierarchical HttpClient delegation (withRequestsMadeViaParent). However, HttpTransferCache was not introduced until Angular 16.0.0 (March 31, 2023), approximately 4 months after Angular 15.0.3's release. The vulnerable component does not exist in this vers..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@15.0.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f753227-768c-55ad-b2b5-5b316b400717",
      "id": "CVE-2026-88060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 15.0.3 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@15.0.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/core@15.0.3"
    }
  ]
}