{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e705b697-4a2b-5786-b4d6-3929ef2e49e0",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/service-worker@5.2.11-tuxcare.15",
      "type": "library",
      "name": "@angular/service-worker",
      "version": "5.2.11-tuxcare.15",
      "purl": "pkg:npm/%40angular/service-worker@5.2.11-tuxcare.15"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:fe44b879-8dca-576b-a7eb-d4dc55ecf3b6",
      "id": "CVE-2021-4231",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 5.2.11-tuxcare.15 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69476f54-5fe3-5f8b-960d-601da201e64f",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 5.2.11-tuxcare.15 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a124dc21-c01b-5220-873c-6b3909c95cee",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 5.2.11-tuxcare.15 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0bac39d2-f511-5ceb-aec2-bff5ccbcf798",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 5.2.11-tuxcare.15 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e469802b-bab1-53a4-96ef-78846f3273e8",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 5.2.11-tuxcare.15 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a21b9bf-f7d6-5c0e-8b4b-47cd992918a5",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 5.2.11-tuxcare.15 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe282bd9-471f-51aa-80e1-0da9f13147f5",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 5.2.11-tuxcare.15 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32896c0a-10ea-5260-aa31-fe65f8db97da",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 5.2.11-tuxcare.15 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c48be0c-d2d1-5840-88b6-5f7032b88f1f",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 5.2.11-tuxcare.15 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f41ca4d2-f381-53e6-99bf-e1bfd1d1b7e5",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 5.2.11-tuxcare.15 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b19446a4-c102-5b03-82b2-8991ec1b6281",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 5.2.11-tuxcare.15 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2d6ff2b-1597-577c-a61b-5747b5f98c75",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 5.2.11-tuxcare.15 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16f31c3d-1303-57fd-9e25-99a326b92942",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 5.2.11-tuxcare.15 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a105727-386b-5c35-98b2-ee59a6a366cf",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 5.2.11-tuxcare.15 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd5238f3-adb4-5769-a153-caab1653e197",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 5.2.11-tuxcare.15 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:acfdb266-3143-5611-8778-421bc3a65a3b",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 5.2.11-tuxcare.15 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ff3904c-ce3d-5fd1-91b7-239d054f7b5f",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 5.2.11-tuxcare.15 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c393120f-1054-5f72-8a55-cd2bd754b00a",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 5.2.11-tuxcare.15 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2791613a-0964-5c4c-aea7-1b15de0172e5",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 5.2.11-tuxcare.15 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a6b86f0-971b-5f26-8914-8286cc2a37c8",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 5.2.11-tuxcare.15 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:adfff51d-ad19-54eb-acaf-d8ffa27dd2a0",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 5.2.11-tuxcare.15 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:653b8ac0-ed0c-5b97-93e1-93f8fee526bf",
      "id": "CVE-2026-68945",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 5.2.11-tuxcare.15 of @angular/service-worker. not_affected \u2014 Angular 5.2.11 is NOT affected by CVE-2026-68945. The vulnerable component `HttpTransferCache` does not exist in this version. This feature was introduced in Angular v16 as part of the modern SSR hydration system. Angular 5.2.11 only has the basic `TransferState` API (a generic key-value store for manual state transfer), not the automatic HTTP request caching interceptor that contains the vulne..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d51407aa-b81a-5c60-87b3-54348e73e819",
      "id": "CVE-2026-69149",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 5.2.11-tuxcare.15 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9074735-958d-5ae3-ab4c-1b05e4368aa6",
      "id": "CVE-2026-69151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 5.2.11-tuxcare.15 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef99f1ca-afc6-52ba-a684-728e365c0455",
      "id": "CVE-2026-88056",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 5.2.11-tuxcare.15 of @angular/service-worker. not_affected \u2014 Angular 5.2.11-tuxcare.19 does not contain the vulnerable URL resolution code pattern described in CVE-2026-88056. The vulnerability requires the url.ts file with parseUrl function calling String.prototype.trim() and the relativeUrlsTransformerInterceptorFn HTTP interceptor, both introduced in later Angular versions (post-June 2026). The target version uses a fundamentally different architectur..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e8b3919-9793-5ba5-ba95-52baca2d3270",
      "id": "CVE-2026-88057",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 5.2.11-tuxcare.15 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3533eb03-75e4-5c30-bed7-29e788e4c7ae",
      "id": "CVE-2026-88059",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 5.2.11-tuxcare.15 of @angular/service-worker. not_affected \u2014 Angular 5.2.11 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache with hierarchical HttpClient delegation (withRequestsMadeViaParent()), features that were introduced in Angular v16. Angular 5.2.11 predates these features by approximately 6+ years and contains only a basic HTTP interceptor architecture with no automatic response caching mechanism. While TransferStat..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@5.2.11-tuxcare.15"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a96f0801-b82e-5383-91f7-5e2e908d268a",
      "id": "CVE-2026-88060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 5.2.11-tuxcare.15 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@5.2.11-tuxcare.15"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/service-worker@5.2.11-tuxcare.15"
    }
  ]
}