{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:28cbfd35-2511-5453-ba62-0639136ce708",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/elements@8.0.0-tuxcare.4",
      "type": "library",
      "name": "@angular/elements",
      "version": "8.0.0-tuxcare.4",
      "purl": "pkg:npm/%40angular/elements@8.0.0-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:2b962bf6-f28f-5386-bbc0-698d452fdd24",
      "id": "CVE-2021-4231",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 8.0.0-tuxcare.4 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d3714d9-bf16-5618-aec5-146d305f55eb",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 8.0.0-tuxcare.4 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2f6724f-d278-5e57-93b7-cebbd6d7095b",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 8.0.0-tuxcare.4 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60ba26e2-8b0d-5495-86e1-3f529f312203",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 8.0.0-tuxcare.4 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d864153d-e96b-5547-8d22-08bbfcc876c3",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 8.0.0-tuxcare.4 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3db30492-98af-51d8-b152-ae42c48f7307",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41423 does not affect version 8.0.0-tuxcare.4 of @angular/elements. not_affected \u2014 The target Angular 8.0.0 is not affected by CVE-2026-41423. The vulnerability exists only in newer Angular versions (17+) that use the WHATWG URL API. The target uses Node.js url.parse() which does not interpret protocol-relative URLs (//evil.com) as hostname overrides when used without a base URL parameter."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c73c821b-c778-59f9-91e8-59a159e0fa16",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 8.0.0-tuxcare.4 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c782e6a4-4fd5-5458-91bb-3a953a0c421c",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 8.0.0-tuxcare.4 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af07e73c-1edc-527a-843d-36a4d6839baa",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 8.0.0-tuxcare.4 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7eca6b5-ac4a-5582-a788-842a76103311",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50170 does not affect version 8.0.0-tuxcare.4 of @angular/elements. not_affected \u2014 Angular v8.0.0 is not affected by CVE-2026-50170. The vulnerability requires the HTTP TransferCache feature (automatic caching of HTTP responses during SSR with client hydration), which was introduced in Angular v16+. Version 8.0.0 lacks the vulnerable code path entirely: no transfer_cache.ts, no transferCacheInterceptorFn, no shouldCacheRequest() function, and no automatic HTTP response cachin..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9066220f-779b-5e40-b27a-bd022beb41bc",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 8.0.0-tuxcare.4 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11ba5fff-0b95-5f87-9b45-5e57c4f82f25",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 8.0.0-tuxcare.4 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19ecfffe-2a75-5396-b7fc-58f62ff6e36d",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 8.0.0-tuxcare.4 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b9ae239-398c-5314-8204-f60d4db50b60",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 8.0.0-tuxcare.4 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df72f643-8ffc-5cbc-bbfa-ecfde4ec598d",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 8.0.0-tuxcare.4 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0409dd9-9d3a-5a7c-959a-8c787e9eb610",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 8.0.0-tuxcare.4 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b34a9c49-a8ad-50bf-9007-1c24e93a074e",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54264 does not affect version 8.0.0-tuxcare.4 of @angular/elements. not_affected \u2014 Target version 8.0.0-tuxcare.2 is NOT AFFECTED by CVE-2026-54264. The Service Worker implementation strips ALL request headers (including Authorization, Proxy-Authorization, and Cookie) when reconstructing network requests for asset fetches. This architectural design prevents sensitive headers from being forwarded to any destination, including cross-origin redirect targets."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ecfda19b-45b1-5661-89c8-66cdac7d3abb",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 8.0.0-tuxcare.4 of @angular/elements. not_affected \u2014 Angular 8.0.0-tuxcare.2 is NOT affected by CVE-2026-54265. This vulnerability is specific to the Ivy template compiler pipeline introduced in Angular 9+. Angular 8.0.0 uses View Engine, which desugars two-way bindings through the same parsePropertyBinding() code path as one-way bindings, inherently applying schema-derived sanitization. The vulnerable TwoWayProperty operation and resolve_sanitiz..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8b89e9b-8c4a-5371-94e4-f3a9ed022a22",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54266 does not affect version 8.0.0-tuxcare.4 of @angular/elements. not_affected \u2014 Angular 8.0.0 does not contain the vulnerable HttpTransferCache feature. The CVE-2026-54266 vulnerability affects HttpTransferCache, which was introduced in Angular 9+. While this version has the underlying TransferState mechanism, it lacks the automatic HTTP request caching feature with the vulnerable DJB2 hash-based cache key generation."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44d06334-1090-5cbd-8a76-2e748ab165e3",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 8.0.0-tuxcare.4 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6580671b-1789-5b5f-8a6e-ac46b39d0f2e",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 8.0.0-tuxcare.4 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0575e9a-93b4-5702-b783-2c8e59f617bc",
      "id": "CVE-2026-68945",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 8.0.0-tuxcare.4 of @angular/elements. not_affected \u2014 Angular v8.0.0 is NOT AFFECTED by CVE-2026-68945. The vulnerability concerns HttpTransferCache's cache-key generation creating collisions when HTTP request parameters use repeated keys vs scalar comma-separated values. However, HttpTransferCache does not exist in v8.0.0 \u2014 it was introduced in Angular v16. This version only has the manual TransferState API (a simple key-value store), with no aut..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1470cc2d-739a-5ff0-9641-190f2b7e6156",
      "id": "CVE-2026-69149",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 8.0.0-tuxcare.4 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c0ea818-97d0-5dd8-a1ce-dcc0c3c9bbf9",
      "id": "CVE-2026-69151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 8.0.0-tuxcare.4 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b0a6cb5-d2f2-5ba8-913f-a0fdb5dd5659",
      "id": "CVE-2026-88056",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 8.0.0-tuxcare.4 of @angular/elements. not_affected \u2014 Angular 8.0.0 is NOT AFFECTED by CVE-2026-88056. The vulnerable code patterns described in the CVE do not exist in this version. The CVE affects newer Angular versions (v18-22+) that include server-side URL transformation features (relativeUrlsTransformerInterceptorFn interceptor and url.ts with trim() call) which were introduced years after Angular 8.0.0's 2019 release. The chain from maliciou..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc0a369c-8ede-512f-ae3f-dc4c4e82ed99",
      "id": "CVE-2026-88057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 8.0.0-tuxcare.4 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6307818d-833b-558a-962e-c795a17f4ebf",
      "id": "CVE-2026-88059",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 8.0.0-tuxcare.4 of @angular/elements. not_affected \u2014 Angular 8.0.0-tuxcare.4 is NOT affected by CVE-2026-88059. The vulnerability requires HttpTransferCache (automatic HTTP response caching during SSR hydration), hierarchical HttpClient with withRequestsMadeViaParent() delegation, and the standalone API provideHttpClient() \u2014 all features introduced in Angular 16 or later. Angular 8 predates these features by approximately 7 years. While Angular 8..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.0.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:935eb29d-f2dc-52d0-973b-edb5396377a1",
      "id": "CVE-2026-88060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 8.0.0-tuxcare.4 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.0.0-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/elements@8.0.0-tuxcare.4"
    }
  ]
}