{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:869d74a8-9f2e-5b02-9943-a665a9f3d488",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.15",
      "type": "library",
      "name": "@angular/http",
      "version": "5.2.11-tuxcare.15",
      "purl": "pkg:npm/%40angular/http@5.2.11-tuxcare.15"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:f16572fe-e593-5889-9f49-1f836c5d70f6",
      "id": "CVE-2021-4231",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 5.2.11-tuxcare.15 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1cb122ac-be62-5452-beba-309dc6d45807",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 5.2.11-tuxcare.15 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:324e553e-cb4d-5055-97b2-e61c5bd767f0",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 5.2.11-tuxcare.15 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba953b9f-9909-5f84-87f5-0199879cdde7",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 5.2.11-tuxcare.15 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ad227c6-3ef5-5893-9586-a5ca0f6509b3",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 5.2.11-tuxcare.15 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abded525-fe40-5b80-9975-93cc2041a29f",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 5.2.11-tuxcare.15 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c3d2ac0-b298-5ed4-95fa-123ca6821fe5",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 5.2.11-tuxcare.15 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2a4eada-daa8-5085-894c-124a4f7f723b",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 5.2.11-tuxcare.15 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54077291-bb96-5417-bbf8-0b105432d7ef",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 5.2.11-tuxcare.15 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93e93681-5eb2-5bc6-8863-aea4dd4a6b81",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 5.2.11-tuxcare.15 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5d4b753-2d55-51d6-9c82-bd442bedddb5",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 5.2.11-tuxcare.15 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7bdcd93-5f68-5327-a474-b51010b9b00d",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 5.2.11-tuxcare.15 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47ee9159-4227-5cd6-9877-7911f7f8ac85",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 5.2.11-tuxcare.15 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec429d48-cf74-5581-beb4-fcaef970ab01",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 5.2.11-tuxcare.15 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73c98c71-13d8-54f8-b09c-7e9b372bb78a",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 5.2.11-tuxcare.15 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26e236af-2cf6-5b0c-98f2-2bd772df641d",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 5.2.11-tuxcare.15 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6caaa758-d880-54e7-9ac9-3ded6c29d881",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 5.2.11-tuxcare.15 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95817cf7-ae7e-5291-a11d-ec2d503dbf52",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 5.2.11-tuxcare.15 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aefeab3e-834f-5a18-9431-1f98e7b24f91",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 5.2.11-tuxcare.15 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b3b6a3e-2a3a-590f-8c7b-9d4d051001c2",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 5.2.11-tuxcare.15 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2539039-91bf-5377-8ea3-ab74d6a05ce1",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 5.2.11-tuxcare.15 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:422e8df2-8768-5971-870f-faf02015bae3",
      "id": "CVE-2026-68945",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 5.2.11-tuxcare.15 of @angular/http. not_affected \u2014 Angular 5.2.11 is NOT affected by CVE-2026-68945. The vulnerable component `HttpTransferCache` does not exist in this version. This feature was introduced in Angular v16 as part of the modern SSR hydration system. Angular 5.2.11 only has the basic `TransferState` API (a generic key-value store for manual state transfer), not the automatic HTTP request caching interceptor that contains the vulne..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b160738a-7e6a-5356-8c1c-f6d8b1a613c5",
      "id": "CVE-2026-69149",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 5.2.11-tuxcare.15 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d85defed-5fcf-5ca7-8fca-23117bd7ccc0",
      "id": "CVE-2026-69151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 5.2.11-tuxcare.15 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a51ac91-6881-549f-9221-ae96409d943c",
      "id": "CVE-2026-88056",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 5.2.11-tuxcare.15 of @angular/http. not_affected \u2014 Angular 5.2.11-tuxcare.19 does not contain the vulnerable URL resolution code pattern described in CVE-2026-88056. The vulnerability requires the url.ts file with parseUrl function calling String.prototype.trim() and the relativeUrlsTransformerInterceptorFn HTTP interceptor, both introduced in later Angular versions (post-June 2026). The target version uses a fundamentally different architectur..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e1966b3-9b8d-52bd-8691-403a510e1e49",
      "id": "CVE-2026-88057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 5.2.11-tuxcare.15 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3d242c7-e0d1-568e-a3c5-154c3d4a362a",
      "id": "CVE-2026-88059",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 5.2.11-tuxcare.15 of @angular/http. not_affected \u2014 Angular 5.2.11 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache with hierarchical HttpClient delegation (withRequestsMadeViaParent()), features that were introduced in Angular v16. Angular 5.2.11 predates these features by approximately 6+ years and contains only a basic HTTP interceptor architecture with no automatic response caching mechanism. While TransferStat..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bef5265-1806-584d-95dd-79d2573f54da",
      "id": "CVE-2026-88060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 5.2.11-tuxcare.15 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.15"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.15"
    }
  ]
}