{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3d1a2dda-4d15-531d-b773-086c2332625c",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/animations",
      "purl": "pkg:npm/%40angular/animations@5.2.11-tuxcare.1",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.1",
      "version": "5.2.11-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:39967733-5620-56d4-a816-a8ae9b99360d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-4231 affects version 5.2.11-tuxcare.1 of @angular/animations, and is fixed in 5.2.11-tuxcare.4."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2670374b-48ae-57e8-a22d-4d41c6d13094",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 5.2.11-tuxcare.1 of @angular/animations, and is fixed in 5.2.11-tuxcare.9."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cbc7a078-9b30-51a6-bd41-015e781aadf4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66412 affects version 5.2.11-tuxcare.1 of @angular/animations, and is fixed in 5.2.11-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6139303a-5b4a-5c2c-b094-635ee9cd7fbd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22610 affects version 5.2.11-tuxcare.1 of @angular/animations, and is fixed in 5.2.11-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:64f6c91b-8dc7-5fcd-8d19-e794b77090dd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 5.2.11-tuxcare.1 of @angular/animations, and is fixed in 5.2.11-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:82ee9adb-5ff3-53a1-b6a4-f93daae3e1c5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 5.2.11-tuxcare.1 of @angular/animations, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0ae19200-e8ba-575d-8501-0558ab1c49ad",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 5.2.11-tuxcare.1 of @angular/animations, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7cc21b2a-fa30-5c51-8e6a-446918fae28b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 5.2.11-tuxcare.1 of @angular/animations, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d134db59-edd2-5060-ad92-1b32d764cd8f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 5.2.11-tuxcare.1 of @angular/animations, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:aba874d2-c12d-5b25-b5dc-e81859d47c87",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 5.2.11-tuxcare.1 of @angular/animations, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:40daa545-ffb7-5bba-b881-e3ffee6c633d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 5.2.11-tuxcare.1 of @angular/animations, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:05650ac2-e471-558a-b1fc-ed903795aeaa",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 5.2.11-tuxcare.1 of @angular/animations, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8d07cc21-1602-5280-ab27-cc2b4063d598",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 5.2.11-tuxcare.1 of @angular/animations, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ba8053fd-240c-5851-be6b-a61b8cc00da7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 5.2.11-tuxcare.1 of @angular/animations, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0c60144b-b612-5048-aa97-596dcce148da",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 5.2.11-tuxcare.1 of @angular/animations, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f420e051-d194-55e2-b338-0e59ce868f01",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 5.2.11-tuxcare.1 of @angular/animations, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:85551621-73e2-5e58-b194-c10ddb3d26dd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 5.2.11-tuxcare.1 of @angular/animations, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:33ff206d-3c6b-57c4-b2a2-236f99e7904b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 5.2.11-tuxcare.1 of @angular/animations, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:16d73b97-60e9-5345-b20b-020b77d9e9cd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 5.2.11-tuxcare.1 of @angular/animations, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:eafbb7b4-d23d-5dda-905e-dbd7fc9a7704",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 5.2.11-tuxcare.1 of @angular/animations, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:60a687bb-e139-522f-bca1-1fc608b5fbe1",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 5.2.11-tuxcare.1 of @angular/animations. not_affected \u2014 Angular 5.2.11 is NOT affected by CVE-2026-68945. The vulnerable component `HttpTransferCache` does not exist in this version. This feature was introduced in Angular v16 as part of the modern SSR hydration system. Angular 5.2.11 only has the basic `TransferState` API (a generic key-value store for manual state transfer), not the automatic HTTP request caching interceptor that contains the vulne...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ac8dd135-f0be-5952-afa7-40507bcbc370",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 5.2.11-tuxcare.1 of @angular/animations, and is fixed in 5.2.11-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d2c22585-25af-562d-b141-b39b600f40ca",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 5.2.11-tuxcare.1 of @angular/animations, and is fixed in 5.2.11-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ea78aeaf-bca0-56c1-bdb5-bd9b444aa5e9",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 5.2.11-tuxcare.1 of @angular/animations. not_affected \u2014 Angular 5.2.11-tuxcare.19 does not contain the vulnerable URL resolution code pattern described in CVE-2026-88056. The vulnerability requires the url.ts file with parseUrl function calling String.prototype.trim() and the relativeUrlsTransformerInterceptorFn HTTP interceptor, both introduced in later Angular versions (post-June 2026). The target version uses a fundamentally different architectur...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:769820ba-72e8-5f9a-8f86-fde8b40b6fa8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 5.2.11-tuxcare.1 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f64a6c1a-f12d-56fc-af40-ce76a2158e98",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 5.2.11-tuxcare.1 of @angular/animations. not_affected \u2014 Angular 5.2.11 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache with hierarchical HttpClient delegation (withRequestsMadeViaParent()), features that were introduced in Angular v16. Angular 5.2.11 predates these features by approximately 6+ years and contains only a basic HTTP interceptor architecture with no automatic response caching mechanism. While TransferStat...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:feee8422-c14f-5fa2-9bf6-c240592bda24",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 5.2.11-tuxcare.1 of @angular/animations."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/animations@5.2.11-tuxcare.1"
    }
  ]
}