{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:33df01c6-b333-5272-b59f-ce02b879e899",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/platform-webworker@9.1.13-tuxcare.12",
      "type": "library",
      "name": "@angular/platform-webworker",
      "version": "9.1.13-tuxcare.12",
      "purl": "pkg:npm/%40angular/platform-webworker@9.1.13-tuxcare.12"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:77a6da82-064a-5521-94f5-30bbf5562759",
      "id": "CVE-2021-4231",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 9.1.13-tuxcare.12 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:916d684e-fd8b-5df8-a1b8-5caef5bd51fd",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 9.1.13-tuxcare.12 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20f97836-5315-5ed7-88ce-c591db49b518",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 9.1.13-tuxcare.12 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c25daf7-cb72-5640-9182-04c3dcc85c23",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 9.1.13-tuxcare.12 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cac09642-eda4-56fa-a9fd-4a0e380555e6",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 9.1.13-tuxcare.12 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04d2936e-6fe1-5da8-b4e9-2f36f8e2c8e9",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 9.1.13-tuxcare.12 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed5a1f62-171b-5ed5-827b-a0337b80c88c",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 9.1.13-tuxcare.12 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1078c7fe-f4cf-5791-8d9b-09a8671d383e",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 9.1.13-tuxcare.12 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44880066-4860-5281-b0c0-656fd13c4d9d",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 9.1.13-tuxcare.12 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:064fddac-1a50-513d-ae6a-b9884e3cf381",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50170 does not affect version 9.1.13-tuxcare.12 of @angular/platform-webworker. not_affected \u2014 Angular v9.1.13 is not affected by CVE-2026-50170. The vulnerability exists in Angular's HttpTransferCache feature, which was introduced in Angular v16+. This feature does not exist in v9.1.13, making the vulnerability pattern impossible to manifest."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7277def4-04cd-5050-a94e-d39d824d1edb",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 9.1.13-tuxcare.12 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a10435d-4a8e-5734-aff8-2c353bb96b1c",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 9.1.13-tuxcare.12 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b354666f-784b-548f-ba5f-2f995b06ef42",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 9.1.13-tuxcare.12 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fdcee2db-c3a9-5538-a117-7b8d8fc76474",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 9.1.13-tuxcare.12 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:806fc0ed-6138-5e9e-a6a4-eb7e7c9bd2b2",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 9.1.13-tuxcare.12 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e38c6cd2-a7b4-5470-b01b-3984c1e41db5",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 9.1.13-tuxcare.12 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59782b7f-ba7a-5f45-99bf-18644e760aa6",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54264 does not affect version 9.1.13-tuxcare.12 of @angular/platform-webworker. not_affected \u2014 Angular 9.1.13 is not affected by CVE-2026-54264. The target repository uses a fundamentally different request reconstruction architecture than the vulnerable upstream versions (22.0+). The vulnerability requires the presence of header-copying logic during request reconstruction, which does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa2ca797-0adf-54ce-b145-90c45844cb72",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 9.1.13-tuxcare.12 of @angular/platform-webworker. not_affected \u2014 Angular 9.1.13-tuxcare.9 is NOT AFFECTED by CVE-2026-54265. The vulnerability exists in newer Ivy compiler's template/pipeline architecture where TwoWayProperty operations bypass sanitizer resolution. This version uses View Engine and early render3 (Ivy) implementations where two-way bindings desugar through the same parsePropertyBinding() path as one-way bindings, ensuring identical sanitizer ..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da9a939c-0a74-573c-a9c1-455c0a2a1ad5",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54266 does not affect version 9.1.13-tuxcare.12 of @angular/platform-webworker. not_affected \u2014 Angular 9.1.13-tuxcare.9 does not contain the HttpTransferCache feature. The vulnerability CVE-2026-54266 affects the hash generation in HttpTransferCache, a feature introduced in Angular v16+. The target version (9.1.13) predates this feature by many major versions. While TransferState (generic state serialization) exists in v9, there is no HTTP caching integration that uses it. The packages/c..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d65caed6-aedf-51f0-95b0-3d1327f2751a",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 9.1.13-tuxcare.12 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad18440c-266a-51ee-a183-5963a5ee28aa",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 9.1.13-tuxcare.12 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a84291b6-0a9d-5a59-b756-b8c422ac8a69",
      "id": "CVE-2026-68945",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 9.1.13-tuxcare.12 of @angular/platform-webworker. not_affected \u2014 Angular v9.1.13 is not affected by CVE-2026-68945. The vulnerable HttpTransferCache feature was introduced in Angular v16.0.0 (March 2023), approximately 7 major versions after v9.1.13. The target version does not contain the HttpTransferCache code, the transfer_cache.ts file, or any automatic HTTP request caching mechanism that could exhibit the cache-key ambiguity vulnerability. While v9 does..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd174996-e602-54a0-919d-13a78237a8b8",
      "id": "CVE-2026-69149",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 9.1.13-tuxcare.12 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:779ac9e1-12c2-5404-91f2-1ddb6e8f7ca7",
      "id": "CVE-2026-69151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 9.1.13-tuxcare.12 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec89b789-b525-5b1c-987f-a9d3e9962949",
      "id": "CVE-2026-88056",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 9.1.13-tuxcare.12 of @angular/platform-webworker. not_affected \u2014 Angular 9.1.13 is not affected by CVE-2026-88056. The vulnerability requires String.prototype.trim() to be called on URLs during server-side rendering, which strips Unicode whitespace and transforms same-origin relative paths into cross-origin protocol-relative URLs. This vulnerable pattern was introduced in Angular v22.0.0-rc.2 (May 2026, commit 6e71049021) as part of a URL resolution refactor..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11d4d99a-5733-50bb-8c68-98a7b311f4da",
      "id": "CVE-2026-88057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 9.1.13-tuxcare.12 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9dcbeba-84e7-51e0-aab4-dee039861005",
      "id": "CVE-2026-88059",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 9.1.13-tuxcare.12 of @angular/platform-webworker. not_affected \u2014 Angular 9.1.13 is not affected by CVE-2026-88059. The vulnerability targets HttpTransferCache's cache eligibility evaluation in hierarchical HttpClient configurations using withRequestsMadeViaParent(). These features (HttpTransferCache, provideClientHydration, withRequestsMadeViaParent, provideHttpClient) were introduced in Angular 16 and do not exist in Angular 9.1.13, which uses the older NgM..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c5f2137-d469-500a-ba1c-588f46d83cfa",
      "id": "CVE-2026-88060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 9.1.13-tuxcare.12 of @angular/platform-webworker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@9.1.13-tuxcare.12"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/platform-webworker@9.1.13-tuxcare.12"
    }
  ]
}