{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:2bc228f3-4062-5841-a050-e314277a13eb",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.15",
      "type": "library",
      "name": "@angular/platform-browser",
      "version": "5.2.11-tuxcare.15",
      "purl": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.15"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:0a9bdaa4-0a17-51eb-b730-169b594b32bc",
      "id": "CVE-2021-4231",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 5.2.11-tuxcare.15 of @angular/platform-browser."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30b2a9a9-6398-5c3e-898b-3af6b0c48ae4",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 5.2.11-tuxcare.15 of @angular/platform-browser."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5a98050-04a0-5a52-88ef-7aaf3167f57c",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 5.2.11-tuxcare.15 of @angular/platform-browser."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb36aee4-3d26-59df-870a-13522810b4b9",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 5.2.11-tuxcare.15 of @angular/platform-browser."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9c2427d-1edf-5541-8289-92b385814349",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 5.2.11-tuxcare.15 of @angular/platform-browser."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ad37c2c-93a1-5552-8e54-1b71ca6e6471",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 5.2.11-tuxcare.15 of @angular/platform-browser."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09243f6a-62d1-55c0-bb9e-d99f87dc2e53",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 5.2.11-tuxcare.15 of @angular/platform-browser."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d7d0af2-cd2d-5c24-a9d9-949045d4d25f",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 5.2.11-tuxcare.15 of @angular/platform-browser."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c646b79-30f2-5ced-a244-231ff0a383f6",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 5.2.11-tuxcare.15 of @angular/platform-browser."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd0de55d-e855-5231-ba98-83f86a61979a",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 5.2.11-tuxcare.15 of @angular/platform-browser."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:756ee3ff-b301-5965-acbd-5fa468702eac",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 5.2.11-tuxcare.15 of @angular/platform-browser."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec9fb2cb-d318-596d-90e0-67bf41cffc9c",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 5.2.11-tuxcare.15 of @angular/platform-browser."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5af14b31-d586-5873-b109-28f7fcae32e2",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 5.2.11-tuxcare.15 of @angular/platform-browser."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75351b31-24f9-5f19-8dc4-638560ef0a6a",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 5.2.11-tuxcare.15 of @angular/platform-browser."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:439bc9c0-4b39-52b8-a5d6-1ddef6ac0fe6",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 5.2.11-tuxcare.15 of @angular/platform-browser."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab16b975-d6aa-5d53-bfd8-f01e2618ed2b",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 5.2.11-tuxcare.15 of @angular/platform-browser."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53f9cf26-bbdc-5d0f-8f99-0afe1f1051c2",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 5.2.11-tuxcare.15 of @angular/platform-browser."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aeec2496-149b-5049-896b-3ba2dcd94d1d",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 5.2.11-tuxcare.15 of @angular/platform-browser."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e78b812-2d12-5cf9-a013-a53ed7115eb6",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 5.2.11-tuxcare.15 of @angular/platform-browser."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0218fea5-d977-5a8b-8bbe-4f707604fd39",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 5.2.11-tuxcare.15 of @angular/platform-browser."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10694863-d5fe-5d8a-8647-c25be169a63a",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 5.2.11-tuxcare.15 of @angular/platform-browser."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3c18bee-e6b0-58a3-ac50-a952a9bca1e8",
      "id": "CVE-2026-68945",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 5.2.11-tuxcare.15 of @angular/platform-browser. not_affected \u2014 Angular 5.2.11 is NOT affected by CVE-2026-68945. The vulnerable component `HttpTransferCache` does not exist in this version. This feature was introduced in Angular v16 as part of the modern SSR hydration system. Angular 5.2.11 only has the basic `TransferState` API (a generic key-value store for manual state transfer), not the automatic HTTP request caching interceptor that contains the vulne..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ed840fc-0934-5f68-9836-a9911c50009c",
      "id": "CVE-2026-69149",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 5.2.11-tuxcare.15 of @angular/platform-browser."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6f40b31-b207-5265-81de-806ab53428fd",
      "id": "CVE-2026-69151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 5.2.11-tuxcare.15 of @angular/platform-browser."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80036224-70b2-530b-9d23-56b7630a38dc",
      "id": "CVE-2026-88056",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 5.2.11-tuxcare.15 of @angular/platform-browser. not_affected \u2014 Angular 5.2.11-tuxcare.19 does not contain the vulnerable URL resolution code pattern described in CVE-2026-88056. The vulnerability requires the url.ts file with parseUrl function calling String.prototype.trim() and the relativeUrlsTransformerInterceptorFn HTTP interceptor, both introduced in later Angular versions (post-June 2026). The target version uses a fundamentally different architectur..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e50739a5-5b2c-5879-ba5a-ec243480eafb",
      "id": "CVE-2026-88057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 5.2.11-tuxcare.15 of @angular/platform-browser."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f3fdb64-361f-589c-b656-a23c6116f2b5",
      "id": "CVE-2026-88059",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 5.2.11-tuxcare.15 of @angular/platform-browser. not_affected \u2014 Angular 5.2.11 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache with hierarchical HttpClient delegation (withRequestsMadeViaParent()), features that were introduced in Angular v16. Angular 5.2.11 predates these features by approximately 6+ years and contains only a basic HTTP interceptor architecture with no automatic response caching mechanism. While TransferStat..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa0f38bc-6707-5361-9340-9ca6e09a2774",
      "id": "CVE-2026-88060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 5.2.11-tuxcare.15 of @angular/platform-browser."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.15"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.15"
    }
  ]
}