{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:7b8d9b7d-520b-5c7f-b085-de6d1865549f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.17",
      "type": "library",
      "name": "@angular/language-service",
      "version": "5.2.11-tuxcare.17",
      "purl": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.17"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:6c9e2a6d-d768-5300-a9b3-cdb70cdb0e19",
      "id": "CVE-2021-4231",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 5.2.11-tuxcare.17 of @angular/language-service."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ae0ba22-5517-50a3-a262-baa0e1c16270",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 5.2.11-tuxcare.17 of @angular/language-service."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e37dfe9-7266-5a65-9e8f-7c901f4f99d5",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 5.2.11-tuxcare.17 of @angular/language-service."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27cbdf7e-f0bd-5a7a-a496-9ac0527c7aa4",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 5.2.11-tuxcare.17 of @angular/language-service."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4dcf5879-45b6-579d-a6c6-56969ab84273",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 5.2.11-tuxcare.17 of @angular/language-service."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:870cfbeb-2dcb-50d8-9c67-42c913d959a2",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 5.2.11-tuxcare.17 of @angular/language-service."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:552b512f-99d2-50d8-adb9-1fd7750735db",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 5.2.11-tuxcare.17 of @angular/language-service."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce617dcb-4ba6-5d37-91e5-d10d3cf4d0ff",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 5.2.11-tuxcare.17 of @angular/language-service."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99f711dd-d3db-5243-8e44-207feb5c3e9e",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 5.2.11-tuxcare.17 of @angular/language-service."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d91be15-b9da-5769-8dee-c0499134f60c",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 5.2.11-tuxcare.17 of @angular/language-service."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2af70730-7d99-51a3-9f00-f16195ddbc4a",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 5.2.11-tuxcare.17 of @angular/language-service."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99c9da53-c99d-5993-bfe0-2f1aa9ac0d67",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 5.2.11-tuxcare.17 of @angular/language-service."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82f6e67a-1dc8-5758-9e94-c7c54ec86005",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 5.2.11-tuxcare.17 of @angular/language-service."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7cabe176-7364-50c6-ab05-ff001f2c6133",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 5.2.11-tuxcare.17 of @angular/language-service."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e6934e9-07e2-5669-a7bc-d69721e0318b",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 5.2.11-tuxcare.17 of @angular/language-service."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94c4d399-a7dc-58fb-a44c-97655139e093",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 5.2.11-tuxcare.17 of @angular/language-service."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6ee0131-f66e-5c36-8561-87e2ca00cb93",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 5.2.11-tuxcare.17 of @angular/language-service."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71c1c44b-af6b-5f70-9b07-04a8241c2111",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 5.2.11-tuxcare.17 of @angular/language-service."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67b732f8-9db1-5c32-b422-09018da1c972",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 5.2.11-tuxcare.17 of @angular/language-service."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:363efce9-0e80-532d-b9ee-6a529822f4f0",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 5.2.11-tuxcare.17 of @angular/language-service."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7aeea984-3a45-526e-ac0c-d9f735aa0928",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 5.2.11-tuxcare.17 of @angular/language-service."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f06b335-caa6-5ad7-a186-f61c68ced734",
      "id": "CVE-2026-68945",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 5.2.11-tuxcare.17 of @angular/language-service. not_affected \u2014 Angular 5.2.11 is NOT affected by CVE-2026-68945. The vulnerable component `HttpTransferCache` does not exist in this version. This feature was introduced in Angular v16 as part of the modern SSR hydration system. Angular 5.2.11 only has the basic `TransferState` API (a generic key-value store for manual state transfer), not the automatic HTTP request caching interceptor that contains the vulne..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33563fa0-daa9-56ed-813c-cb316735d1a2",
      "id": "CVE-2026-69149",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 5.2.11-tuxcare.17 of @angular/language-service."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b08030a-39b8-5f5c-84dc-21cd17f030d1",
      "id": "CVE-2026-69151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 5.2.11-tuxcare.17 of @angular/language-service."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cae28fee-c8d6-5eb0-b516-b1680f1f91db",
      "id": "CVE-2026-88056",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 5.2.11-tuxcare.17 of @angular/language-service. not_affected \u2014 Angular 5.2.11-tuxcare.19 does not contain the vulnerable URL resolution code pattern described in CVE-2026-88056. The vulnerability requires the url.ts file with parseUrl function calling String.prototype.trim() and the relativeUrlsTransformerInterceptorFn HTTP interceptor, both introduced in later Angular versions (post-June 2026). The target version uses a fundamentally different architectur..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0d922e6-a912-54bc-b0bf-1b6761c29b63",
      "id": "CVE-2026-88057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 5.2.11-tuxcare.17 of @angular/language-service."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b2580df-ac62-5522-8961-4c62bff72648",
      "id": "CVE-2026-88059",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 5.2.11-tuxcare.17 of @angular/language-service. not_affected \u2014 Angular 5.2.11 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache with hierarchical HttpClient delegation (withRequestsMadeViaParent()), features that were introduced in Angular v16. Angular 5.2.11 predates these features by approximately 6+ years and contains only a basic HTTP interceptor architecture with no automatic response caching mechanism. While TransferStat..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.17"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbd640da-8868-5c71-8754-5e5fd334c24c",
      "id": "CVE-2026-88060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 5.2.11-tuxcare.17 of @angular/language-service."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.17"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.17"
    }
  ]
}