{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:585caf8c-81a6-58cf-b8b4-b73a3176484d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/http@6.1.10-tuxcare.11",
      "type": "library",
      "name": "@angular/http",
      "version": "6.1.10-tuxcare.11",
      "purl": "pkg:npm/%40angular/http@6.1.10-tuxcare.11"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:96fbc85a-2f8d-54af-9a50-97168020096d",
      "id": "CVE-2021-4231",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 6.1.10-tuxcare.11 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@6.1.10-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc7e30fa-a377-503d-9726-be25b98a5d81",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 6.1.10-tuxcare.11 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@6.1.10-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54e3828d-8e99-5ef9-ab0c-460fab9c81f8",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 6.1.10-tuxcare.11 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@6.1.10-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4fe37b8-2174-59d5-b6a6-20e8384f8cdf",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 6.1.10-tuxcare.11 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@6.1.10-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:849f04d2-4800-5710-a2df-ceb8111341d2",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 6.1.10-tuxcare.11 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@6.1.10-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c74fab8-fb60-54fb-b2cb-ea4405c76dfd",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 6.1.10-tuxcare.11 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@6.1.10-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7fcee70f-799f-5494-99f0-a003e3b6cac8",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 6.1.10-tuxcare.11 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@6.1.10-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9ae40b0-1b8a-5a4c-bfd4-30183aba0d34",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 6.1.10-tuxcare.11 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@6.1.10-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4852c8c3-3388-55db-b493-fa4e0f32712b",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 6.1.10-tuxcare.11 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@6.1.10-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5765f191-8d6c-56d1-b9b3-8348fa20794a",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 6.1.10-tuxcare.11 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@6.1.10-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1e7020c-d4f3-5e0c-a8b9-f34b6ea5edbc",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 6.1.10-tuxcare.11 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@6.1.10-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d036a7d1-7b16-5e87-a304-48863901126f",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 6.1.10-tuxcare.11 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@6.1.10-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4a7e031-3aca-500e-a4cb-636c3e2916fd",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 6.1.10-tuxcare.11 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@6.1.10-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc97b19c-e3c9-5780-9962-fa23a563fadc",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 6.1.10-tuxcare.11 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@6.1.10-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac65d355-dfa4-54af-a4ac-b5f898b276fa",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 6.1.10-tuxcare.11 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@6.1.10-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07984830-aee2-5714-aad2-2b94debd4d20",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 6.1.10-tuxcare.11 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@6.1.10-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ed9bb9c-dd98-508a-9278-9bbd3e43cd70",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 6.1.10-tuxcare.11 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@6.1.10-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c846567-3ff9-52f9-b5e9-7ca090c7fa9b",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 6.1.10-tuxcare.11 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@6.1.10-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4dead1a4-ae71-50a2-8d3c-1256c704fcb6",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 6.1.10-tuxcare.11 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@6.1.10-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50b8f428-b07f-5e52-9340-735fdb6d2698",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 6.1.10-tuxcare.11 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@6.1.10-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a9abb7d-c992-542f-91b8-f91d5c28b8e3",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 6.1.10-tuxcare.11 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@6.1.10-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88504d4c-e19f-5459-aeca-2f2badb42e24",
      "id": "CVE-2026-68945",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 6.1.10-tuxcare.11 of @angular/http. not_affected \u2014 Angular 6.1.10 is NOT AFFECTED by CVE-2026-68945. The vulnerable HttpTransferCache feature does not exist in this version \u2014 it was introduced in Angular 16.0.0 (April 2023), more than 5 years after Angular 6.1.10 (2018). The vulnerable file `packages/common/http/src/transfer_cache.ts` and all related APIs (`provideClientHydration`, `withNoHttpTransferCache`, `sortAndConcatParams`) are completel..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@6.1.10-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de782bb2-fd20-5709-b2f3-54422025c964",
      "id": "CVE-2026-69149",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 6.1.10-tuxcare.11 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@6.1.10-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:002033aa-6c00-5fc2-98d2-c6527e52c3d8",
      "id": "CVE-2026-69151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 6.1.10-tuxcare.11 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@6.1.10-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3945b3a7-ab73-5af9-9d02-bb443fb93867",
      "id": "CVE-2026-88056",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 6.1.10-tuxcare.11 of @angular/http. not_affected \u2014 Angular version 6.1.10 is not affected by CVE-2026-88056. The vulnerable code pattern (url.ts with parseUrl using String.prototype.trim() and relativeUrlsTransformerInterceptorFn interceptor) does not exist in this version. These components were introduced in later Angular versions (post-6.1.10) and subsequently fixed in August 2026. Version 6.1.10 predates the vulnerable SSR URL resolution arc..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@6.1.10-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bbe3ad3-53ef-58c0-802a-81f16c3efe59",
      "id": "CVE-2026-88057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 6.1.10-tuxcare.11 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@6.1.10-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f57ca840-8ef2-5284-9dbc-893ee8718ea9",
      "id": "CVE-2026-88059",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 6.1.10-tuxcare.11 of @angular/http. not_affected \u2014 Angular 6.1.10 is not affected by CVE-2026-88059. The vulnerable HttpTransferCache feature, withRequestsMadeViaParent() delegation API, and modern hydration system (provideClientHydration()) do not exist in this version. These components were introduced in Angular 16+ (circa 2023), while the target version is from Angular 6 (2018). The vulnerability requires automatic HTTP response caching duri..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@6.1.10-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1cffe85e-2370-5113-9d67-110e1a558b88",
      "id": "CVE-2026-88060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 6.1.10-tuxcare.11 of @angular/http."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@6.1.10-tuxcare.11"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/http@6.1.10-tuxcare.11"
    }
  ]
}