{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4be9538c-e642-5a3d-8133-fb0ac8fe08c1",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.3",
      "type": "library",
      "name": "@angular/service-worker",
      "version": "15.2.2-tuxcare.3",
      "purl": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:fd2c66e7-8b0f-5c81-8083-f07536384f6b",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 15.2.2-tuxcare.3 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d3c7b81-77b8-5915-a343-f017af3d5151",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 15.2.2-tuxcare.3 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42db02a8-6f3d-5046-9143-dd34b537dff4",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 15.2.2-tuxcare.3 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81b93982-3c73-594b-894f-8756a9dee361",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 15.2.2-tuxcare.3 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:036b8eb0-0a73-597d-b3a9-d1d78330685c",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41423 does not affect version 15.2.2-tuxcare.3 of @angular/service-worker. not_affected \u2014 The target repository (Angular 15.2.2-tuxcare.1) is NOT affected by CVE-2026-41423. While the target lacks the specific fix from the upstream patch, it uses a fundamentally different URL parsing mechanism (Node.js legacy url.parse()) that does not exhibit the WHATWG URL specification behavior exploited in the vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8af939a2-7eaf-541c-80ee-e7140eb31588",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 15.2.2-tuxcare.3 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70ba4eff-26a6-502c-baac-c52c94552bbc",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 15.2.2-tuxcare.3 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a05768f5-1854-5c8e-b72b-2ae035465992",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 15.2.2-tuxcare.3 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf4ddc79-1e51-5da5-9baa-0dc9e41bba72",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50170 does not affect version 15.2.2-tuxcare.3 of @angular/service-worker. not_affected \u2014 Angular v15.2.2 is not affected by CVE-2026-50170. The HTTP TransferCache feature, which is the subject of the vulnerability, was introduced in Angular v16.0.0 (March 2023). The target repository version (15.2.2-tuxcare.1) predates this feature entirely and does not contain the vulnerable code path."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ea28402-8965-576f-a152-a2213423bc50",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 15.2.2-tuxcare.3 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17d5af65-0566-57d7-a026-272a7df98455",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 15.2.2-tuxcare.3 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:366f4a65-e364-5e83-9f02-d4643229ce49",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 15.2.2-tuxcare.3 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a82128c1-247b-527d-82e4-ec47813312d8",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 15.2.2-tuxcare.3 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abe027c3-f9d6-5c64-99be-91a11be236aa",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 15.2.2-tuxcare.3 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f27efa96-0464-56b2-a486-39f980afce64",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 15.2.2-tuxcare.3 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f50ae5c4-0a37-51a0-abb4-226dadda482a",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 15.2.2-tuxcare.3 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46a950b7-094c-5ff8-b7ae-bfa3cceffc7f",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 15.2.2-tuxcare.3 of @angular/service-worker. not_affected \u2014 Angular v15.2.2 does not contain the vulnerable code path. The CVE-2026-54265 vulnerability affects the template pipeline's resolve_sanitizers.ts (TwoWayProperty operation), which does not exist in v15.2.2. This version uses TemplateDefinitionBuilder where two-way bindings desugar to regular property bindings that receive identical sanitization as one-way bindings."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91d5b261-4d73-5788-be52-a6297bb38a0f",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54266 does not affect version 15.2.2-tuxcare.3 of @angular/service-worker. not_affected \u2014 Angular 15.2.2 is not affected by CVE-2026-54266. The vulnerable HttpTransferCache feature was introduced in Angular 16.0.0 (May 2023), after this version was released (March 2023). The target codebase does not contain the transfer_cache.ts module, HttpTransferCache API, or any HTTP response caching mechanism that uses hash-based cache keys."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5b8353c-654c-5550-8663-b2b30bdbddb5",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 15.2.2-tuxcare.3 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c838eb8-d16e-5a2a-8b43-93ca36af5a55",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 15.2.2-tuxcare.3 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61f5d4e6-d64c-5750-9ed4-dfbb2de830db",
      "id": "CVE-2026-68945",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 15.2.2-tuxcare.3 of @angular/service-worker. not_affected \u2014 Angular 15.2.2-tuxcare.2 is not affected by CVE-2026-68945. The vulnerable HttpTransferCache feature does not exist in this version\u2014it was introduced in Angular 16.0.0, after the target's release. Without HttpTransferCache, the cache-key collision vulnerability described in the CVE (where repeated HTTP parameters like `role=user&role=admin` collide with scalar-comma parameters like `role=user,a..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:acc2ead2-5377-52b9-b0d7-0cff52e546c0",
      "id": "CVE-2026-69149",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 15.2.2-tuxcare.3 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78304c27-b6ea-550a-86fc-f8d7a335459b",
      "id": "CVE-2026-69151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 15.2.2-tuxcare.3 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ffddfe3a-baf3-5b64-8e6d-554f2ad730b9",
      "id": "CVE-2026-88056",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 15.2.2-tuxcare.3 of @angular/service-worker. not_affected \u2014 CVE-2026-88056 describes a vulnerability where String.prototype.trim() in @angular/platform-server's URL resolution strips Unicode whitespace (U+00A0, U+FEFF), causing discrepancy with WHATWG URL parsing and enabling SSRF bypass. However, this vulnerability does NOT affect Angular version 15.2.2-tuxcare.3. Git history analysis reveals the vulnerable trim() call was introduced in Angular v20.x+/..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab2422d1-1cc7-5fbe-ba90-a9874203add5",
      "id": "CVE-2026-88057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 15.2.2-tuxcare.3 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8e46581-0e0b-5039-8283-cadb86a7a534",
      "id": "CVE-2026-88059",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 15.2.2-tuxcare.3 of @angular/service-worker. not_affected \u2014 Angular 15.2.2 is not affected by CVE-2026-88059. The vulnerability requires the HttpTransferCache feature, which was introduced in Angular v16.0.0. Angular 15.2.2 does not contain HttpTransferCache, provideClientHydration, withHttpTransferCacheOptions, or any SSR transfer cache infrastructure. While withRequestsMadeViaParent() exists in v15.2.2, it cannot trigger the vulnerability without the ..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f6ec788-f0f0-55d0-beab-1ee7ca843401",
      "id": "CVE-2026-88060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 15.2.2-tuxcare.3 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.3"
    }
  ]
}