{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:340e9bf7-a814-5694-9fa2-88aff4aa9808",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.14",
      "type": "library",
      "name": "@angular/platform-webworker",
      "version": "5.2.11-tuxcare.14",
      "purl": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.14"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:e3a9cb0b-43a4-5504-bacb-37c82481ef36",
      "id": "CVE-2021-4231",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 5.2.11-tuxcare.14 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f7f9ae7-9ba1-53f5-9ca6-e236e284d1d5",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 5.2.11-tuxcare.14 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a7f77da-5127-550d-a41c-ff23d3736793",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 5.2.11-tuxcare.14 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2539610-4b21-5b48-a9cf-69a750755353",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 5.2.11-tuxcare.14 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d76ece2-a17e-5d1b-8deb-06505e28d785",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 5.2.11-tuxcare.14 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b266c48a-7ac0-53a5-a309-27e30e77f669",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 5.2.11-tuxcare.14 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b3d5955-c61b-5873-9a01-6665bd07b052",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 5.2.11-tuxcare.14 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbf5e8ea-a1ad-5cbe-bbb2-da3b18458774",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 5.2.11-tuxcare.14 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b69b70a-4675-5650-befe-31159f230eb7",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 5.2.11-tuxcare.14 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58f2930d-17ed-50b3-a2e8-6ede4b33075b",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 5.2.11-tuxcare.14 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbe77e71-5673-5f3f-a669-2b5a766074d9",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 5.2.11-tuxcare.14 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90f2ee89-95e6-5efb-996c-1ee7a69a1723",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 5.2.11-tuxcare.14 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e82a3195-533e-5990-b910-7bdcebe01829",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 5.2.11-tuxcare.14 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e802018-d5f9-5dd3-af31-f5c5ff902ed0",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 5.2.11-tuxcare.14 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47f86e47-b95e-5f06-bb91-00475d6e9624",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 5.2.11-tuxcare.14 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f25bca4-75d0-5926-8bf7-52b31a961536",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 5.2.11-tuxcare.14 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ca22254-9476-5785-ae8c-9fe23f8f5d5d",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 5.2.11-tuxcare.14 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4429cf98-6130-5f04-b297-ab3871879b5c",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 5.2.11-tuxcare.14 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f23dc39d-c0ce-51bf-a91b-f641dc10e426",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 5.2.11-tuxcare.14 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb3ade42-c16b-5782-9955-2a2535264746",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 5.2.11-tuxcare.14 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a3fef80-b91c-5856-b6a2-938eb1d99f2e",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 5.2.11-tuxcare.14 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07e87ac4-746c-5cf7-85eb-080128406d23",
      "id": "CVE-2026-68945",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 5.2.11-tuxcare.14 of @angular/platform-webworker. not_affected \u2014 Angular 5.2.11 is NOT affected by CVE-2026-68945. The vulnerable component `HttpTransferCache` does not exist in this version. This feature was introduced in Angular v16 as part of the modern SSR hydration system. Angular 5.2.11 only has the basic `TransferState` API (a generic key-value store for manual state transfer), not the automatic HTTP request caching interceptor that contains the vulne..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd03864e-ec06-5e53-8878-efb0f8e901a6",
      "id": "CVE-2026-69149",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 5.2.11-tuxcare.14 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76b5839b-cb6a-5995-b4f1-d1aafa6f065d",
      "id": "CVE-2026-69151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 5.2.11-tuxcare.14 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80b61f70-3331-510e-833f-5331ebc3c1df",
      "id": "CVE-2026-88056",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 5.2.11-tuxcare.14 of @angular/platform-webworker. not_affected \u2014 Angular 5.2.11-tuxcare.19 does not contain the vulnerable URL resolution code pattern described in CVE-2026-88056. The vulnerability requires the url.ts file with parseUrl function calling String.prototype.trim() and the relativeUrlsTransformerInterceptorFn HTTP interceptor, both introduced in later Angular versions (post-June 2026). The target version uses a fundamentally different architectur..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b2e7a69-fa8c-5129-adbe-a8528b040a93",
      "id": "CVE-2026-88057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 5.2.11-tuxcare.14 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6699a475-a778-5cf3-9af8-6782991dd456",
      "id": "CVE-2026-88059",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 5.2.11-tuxcare.14 of @angular/platform-webworker. not_affected \u2014 Angular 5.2.11 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache with hierarchical HttpClient delegation (withRequestsMadeViaParent()), features that were introduced in Angular v16. Angular 5.2.11 predates these features by approximately 6+ years and contains only a basic HTTP interceptor architecture with no automatic response caching mechanism. While TransferStat..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.14"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16499e89-b91d-509b-b8d0-3aca73e5ae00",
      "id": "CVE-2026-88060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 5.2.11-tuxcare.14 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.14"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.14"
    }
  ]
}