{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3419401e-8fea-507c-81ac-a3cfeb1b8b87",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.17",
      "type": "library",
      "name": "@angular/core",
      "version": "5.2.11-tuxcare.17",
      "purl": "pkg:npm/%40angular/core@5.2.11-tuxcare.17"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:b6202e93-64ed-5e2d-88b0-06a6ddaccac7",
      "id": "CVE-2021-4231",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 5.2.11-tuxcare.17 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31786ecd-852b-5585-b7be-a924914354cb",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 5.2.11-tuxcare.17 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7fe18ac1-cac8-52dd-b0f8-beab7cca4c3f",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 5.2.11-tuxcare.17 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:031a001a-37b1-5b69-9c5f-538850575417",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 5.2.11-tuxcare.17 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77b76566-8dac-5da6-9b17-9b6b55bd0c71",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 5.2.11-tuxcare.17 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a568b454-a3b1-5321-a9c0-38bc79ba078e",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 5.2.11-tuxcare.17 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42b2be04-2c78-554d-92ce-069287308f19",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 5.2.11-tuxcare.17 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d1159c7-03be-5488-bf90-a06369867870",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 5.2.11-tuxcare.17 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afdc6ed0-9a73-54b7-ab7a-fe735c321793",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 5.2.11-tuxcare.17 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3a844f3-17c9-567e-a5f3-0920a67800cd",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 5.2.11-tuxcare.17 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfbb7d15-f0b8-5e62-8d3c-8fb44d083997",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 5.2.11-tuxcare.17 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c039c522-64d7-570a-89b8-71aa604c058d",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 5.2.11-tuxcare.17 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5de4c89-dd00-5ed9-a132-6065c4c29de1",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 5.2.11-tuxcare.17 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d9eee01-1063-5a49-9917-d811977a596c",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 5.2.11-tuxcare.17 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1face951-0ab6-553a-8fb8-21be0f7ed0a7",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 5.2.11-tuxcare.17 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6c1f390-5797-5e7f-9c9c-a04f5fe1eab1",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 5.2.11-tuxcare.17 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1069ff42-0cf1-535c-8cd4-1f2a82a3ffa5",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 5.2.11-tuxcare.17 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef002ca5-94b2-5d75-9aff-e46ba2469b12",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 5.2.11-tuxcare.17 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59d42da4-863f-561d-a7b7-f2b5e8354b08",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 5.2.11-tuxcare.17 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bf25130-2ff8-5244-8e2c-c39d8698794d",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 5.2.11-tuxcare.17 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5cb01c6d-f233-5c0e-8cd5-f2667ea68f68",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 5.2.11-tuxcare.17 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3d4f648-0a48-54a4-b9eb-9ff489d7032f",
      "id": "CVE-2026-68945",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 5.2.11-tuxcare.17 of @angular/core. not_affected \u2014 Angular 5.2.11 is NOT affected by CVE-2026-68945. The vulnerable component `HttpTransferCache` does not exist in this version. This feature was introduced in Angular v16 as part of the modern SSR hydration system. Angular 5.2.11 only has the basic `TransferState` API (a generic key-value store for manual state transfer), not the automatic HTTP request caching interceptor that contains the vulne..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2186650-1022-5785-9e40-eaec213fe9f3",
      "id": "CVE-2026-69149",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 5.2.11-tuxcare.17 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a334abad-2981-51d9-b097-4cea9c603d57",
      "id": "CVE-2026-69151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 5.2.11-tuxcare.17 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5bf6f2da-a85e-5b3e-9384-41cda9e7e6ba",
      "id": "CVE-2026-88056",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 5.2.11-tuxcare.17 of @angular/core. not_affected \u2014 Angular 5.2.11-tuxcare.19 does not contain the vulnerable URL resolution code pattern described in CVE-2026-88056. The vulnerability requires the url.ts file with parseUrl function calling String.prototype.trim() and the relativeUrlsTransformerInterceptorFn HTTP interceptor, both introduced in later Angular versions (post-June 2026). The target version uses a fundamentally different architectur..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d57f3f3e-f041-55ec-b44d-e486cf00033a",
      "id": "CVE-2026-88057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 5.2.11-tuxcare.17 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:616835b6-31a8-5fb5-806c-3782c519ac6d",
      "id": "CVE-2026-88059",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 5.2.11-tuxcare.17 of @angular/core. not_affected \u2014 Angular 5.2.11 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache with hierarchical HttpClient delegation (withRequestsMadeViaParent()), features that were introduced in Angular v16. Angular 5.2.11 predates these features by approximately 6+ years and contains only a basic HTTP interceptor architecture with no automatic response caching mechanism. While TransferStat..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7319805c-9876-5921-aa84-4646f627809d",
      "id": "CVE-2026-88060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 5.2.11-tuxcare.17 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.17"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.17"
    }
  ]
}