{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:fe9a2ee2-d699-52ed-9ddb-aa39abd69f31",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.19",
      "type": "library",
      "name": "@angular/http",
      "version": "5.2.11-tuxcare.19",
      "purl": "pkg:npm/%40angular/http@5.2.11-tuxcare.19"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:9fcac892-1510-51c3-806c-455f5bb6acf7",
      "id": "CVE-2021-4231",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 5.2.11-tuxcare.19 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6bb3e54-f1bb-5f7a-bc0b-9fcea788e7d8",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 5.2.11-tuxcare.19 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74596e68-134f-55b2-b65c-1ffe90cdd92b",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 5.2.11-tuxcare.19 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77efcb5c-b7b2-5527-b00d-92547ebd5435",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 5.2.11-tuxcare.19 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f87b8d6-967b-571f-8f51-e89cf1e59fde",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 5.2.11-tuxcare.19 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:caf2294a-e378-5c04-9703-8aea0363ef4e",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 5.2.11-tuxcare.19 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04b01950-f548-5cb0-a623-42df63a716bf",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 5.2.11-tuxcare.19 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8729cba3-7c6f-5fe7-9a2c-8d3f7e45ccc2",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 5.2.11-tuxcare.19 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c7d7413-53fa-5837-bff8-4f345e5e6283",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 5.2.11-tuxcare.19 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3cf41f4-c2d9-5815-ab52-0a9f1cafe8c9",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 5.2.11-tuxcare.19 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf50d159-3ee2-5d67-96ef-a5c1363cd497",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 5.2.11-tuxcare.19 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:062f8396-0c50-5ca3-a543-548808abe4a2",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 5.2.11-tuxcare.19 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4714fe5-1c12-5fae-8204-d52e3925d00b",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 5.2.11-tuxcare.19 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f36d745-11f1-5949-8939-9b841fb4df8f",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 5.2.11-tuxcare.19 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5aad2798-28c8-514b-9ee2-3f970f053704",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 5.2.11-tuxcare.19 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49f40bd4-748f-58c0-8de5-4fa30073e809",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 5.2.11-tuxcare.19 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a9f77c8-ae07-5564-9063-fecab321bb14",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 5.2.11-tuxcare.19 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0bc61e78-c112-59c1-9158-2e9e7821f4f2",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 5.2.11-tuxcare.19 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eda65310-ff12-5903-9226-ee4d21d8744a",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 5.2.11-tuxcare.19 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43981822-7255-5d7a-ac99-8a233e9ef3fa",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 5.2.11-tuxcare.19 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c95e53a-23a5-5ab0-b824-c8944bc794a4",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 5.2.11-tuxcare.19 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55016704-0dd6-5909-8be1-f0857da2611b",
      "id": "CVE-2026-68945",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 5.2.11-tuxcare.19 of @angular/http. not_affected \u2014 Angular 5.2.11 is NOT affected by CVE-2026-68945. The vulnerable component `HttpTransferCache` does not exist in this version. This feature was introduced in Angular v16 as part of the modern SSR hydration system. Angular 5.2.11 only has the basic `TransferState` API (a generic key-value store for manual state transfer), not the automatic HTTP request caching interceptor that contains the vulne..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4e06980-22bb-5109-9033-85e306dc7ccb",
      "id": "CVE-2026-69149",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 5.2.11-tuxcare.19 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99025ebe-693f-5cc8-8468-18331c180894",
      "id": "CVE-2026-69151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 5.2.11-tuxcare.19 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3ae394e-b68a-5265-8584-4d4b8cc8ea38",
      "id": "CVE-2026-88056",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 5.2.11-tuxcare.19 of @angular/http. not_affected \u2014 Angular 5.2.11-tuxcare.19 does not contain the vulnerable URL resolution code pattern described in CVE-2026-88056. The vulnerability requires the url.ts file with parseUrl function calling String.prototype.trim() and the relativeUrlsTransformerInterceptorFn HTTP interceptor, both introduced in later Angular versions (post-June 2026). The target version uses a fundamentally different architectur..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:755e6e34-c2de-5447-a725-0b433f8b4d13",
      "id": "CVE-2026-88057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 5.2.11-tuxcare.19 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6407e672-df01-5aec-8078-45c294d500e4",
      "id": "CVE-2026-88059",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 5.2.11-tuxcare.19 of @angular/http. not_affected \u2014 Angular 5.2.11 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache with hierarchical HttpClient delegation (withRequestsMadeViaParent()), features that were introduced in Angular v16. Angular 5.2.11 predates these features by approximately 6+ years and contains only a basic HTTP interceptor architecture with no automatic response caching mechanism. While TransferStat..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.19"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36e1f3c2-5d6c-5597-9f8c-8f71d942cd94",
      "id": "CVE-2026-88060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 5.2.11-tuxcare.19 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.19"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.19"
    }
  ]
}