{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f4cb5d27-e848-5607-9695-61eb3c8daa39",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.15",
      "type": "library",
      "name": "@angular/core",
      "version": "5.2.11-tuxcare.15",
      "purl": "pkg:npm/%40angular/core@5.2.11-tuxcare.15"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:2ca7c789-1ccb-5c9b-80aa-b991f7743ae3",
      "id": "CVE-2021-4231",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 5.2.11-tuxcare.15 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebb03258-6cc0-53e4-afdc-0355b9abd3b6",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 5.2.11-tuxcare.15 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f17af9ba-4e24-5f96-8ad6-09010cf8ee4e",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 5.2.11-tuxcare.15 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fddc422-8a29-5d4e-a370-e7d66bf9ba3b",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 5.2.11-tuxcare.15 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80907d9d-9761-5725-9280-de6f5a7b48e8",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 5.2.11-tuxcare.15 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7202ae55-86b4-57e8-84cd-23e77cad1c70",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 5.2.11-tuxcare.15 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af3fbf34-8d8a-5670-9d62-25efb3f77e1d",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 5.2.11-tuxcare.15 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c5bdef9-4e51-5062-9ecf-cdaf5a5339b4",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 5.2.11-tuxcare.15 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d5f7c00-4157-5d1a-859f-a1723c0aefbf",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 5.2.11-tuxcare.15 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17675900-c7c0-59dc-9dd2-eee69ffc67cc",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 5.2.11-tuxcare.15 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f3040f5-e0b0-5070-beb7-d7a9d089c6c2",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 5.2.11-tuxcare.15 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dacdb1ce-26fd-5036-b9b0-46514392d71c",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 5.2.11-tuxcare.15 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1c4f654-36a0-56ad-8ff9-eafc3bce66a5",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 5.2.11-tuxcare.15 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a10ff3f-ba99-53e8-b6ab-c55405fde2fb",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 5.2.11-tuxcare.15 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f7a6af3-ba36-5196-9f44-251a60de6b70",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 5.2.11-tuxcare.15 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbcdfe6c-4f36-50d0-816a-bfd6ce0ee5a3",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 5.2.11-tuxcare.15 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08a2cd62-7ab2-5c65-b182-7d8fe88377ba",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 5.2.11-tuxcare.15 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4749e575-1088-520d-b78f-1474bf104919",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 5.2.11-tuxcare.15 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69ce6fc5-ebaf-597b-be8d-203a41297920",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 5.2.11-tuxcare.15 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ff439c2-3b3d-5948-b47f-f1cc249509e0",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 5.2.11-tuxcare.15 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e60e1d0c-1ebf-561c-acaf-87b96ea261f4",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 5.2.11-tuxcare.15 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:744e802f-a412-5eee-95a7-0648466864df",
      "id": "CVE-2026-68945",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 5.2.11-tuxcare.15 of @angular/core. not_affected \u2014 Angular 5.2.11 is NOT affected by CVE-2026-68945. The vulnerable component `HttpTransferCache` does not exist in this version. This feature was introduced in Angular v16 as part of the modern SSR hydration system. Angular 5.2.11 only has the basic `TransferState` API (a generic key-value store for manual state transfer), not the automatic HTTP request caching interceptor that contains the vulne..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dffae42e-e5d3-5cf8-9d4a-d440d3140a84",
      "id": "CVE-2026-69149",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 5.2.11-tuxcare.15 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3199c50-59fd-5a8d-b33e-a520db74a338",
      "id": "CVE-2026-69151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 5.2.11-tuxcare.15 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:419d54c1-52f5-537b-ad76-b44854e61bc9",
      "id": "CVE-2026-88056",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 5.2.11-tuxcare.15 of @angular/core. not_affected \u2014 Angular 5.2.11-tuxcare.19 does not contain the vulnerable URL resolution code pattern described in CVE-2026-88056. The vulnerability requires the url.ts file with parseUrl function calling String.prototype.trim() and the relativeUrlsTransformerInterceptorFn HTTP interceptor, both introduced in later Angular versions (post-June 2026). The target version uses a fundamentally different architectur..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b767fc34-787c-5bec-a793-b4bc241c1d88",
      "id": "CVE-2026-88057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 5.2.11-tuxcare.15 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3cc4c5e5-51d2-55cc-867f-b695b5a99aa8",
      "id": "CVE-2026-88059",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 5.2.11-tuxcare.15 of @angular/core. not_affected \u2014 Angular 5.2.11 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache with hierarchical HttpClient delegation (withRequestsMadeViaParent()), features that were introduced in Angular v16. Angular 5.2.11 predates these features by approximately 6+ years and contains only a basic HTTP interceptor architecture with no automatic response caching mechanism. While TransferStat..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c53397ed-534d-5efd-a384-1a76be67e447",
      "id": "CVE-2026-88060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 5.2.11-tuxcare.15 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.15"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.15"
    }
  ]
}