{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:5240c0d9-9030-597e-8e81-b839ffc32a43",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/common",
      "purl": "pkg:npm/%40angular/common@5.2.11-tuxcare.8",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/common@5.2.11-tuxcare.8",
      "version": "5.2.11-tuxcare.8",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:e4003bd5-6522-5f21-b3bb-f00e4fe2ee77",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 5.2.11-tuxcare.8 of @angular/common."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:96366293-1739-54f7-9df9-75c547e57b7c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 5.2.11-tuxcare.8 of @angular/common, and is fixed in 5.2.11-tuxcare.9."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:e5871b55-b552-5f93-91c2-89d5a8f14bc4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 5.2.11-tuxcare.8 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:f6115d00-b872-578c-928a-ef0684443d94",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 5.2.11-tuxcare.8 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:08994fad-4a06-5614-ac70-b39ffa0687ee",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 5.2.11-tuxcare.8 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:f2961ab6-98cf-57fb-abca-583285f55813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 5.2.11-tuxcare.8 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:956d0a8b-34b0-56ee-be56-63968b9f52af",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 5.2.11-tuxcare.8 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:e3b01d41-2835-5d87-ac0e-039220a5623f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 5.2.11-tuxcare.8 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:eb80106d-2ec8-5ff1-8e52-1e56664eba66",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 5.2.11-tuxcare.8 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:a90c12e9-917c-55f3-af5f-40b3eca4dde2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 5.2.11-tuxcare.8 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:aa7d2350-41f7-5785-b12c-44eef2845eb3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 5.2.11-tuxcare.8 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:f5ea27b3-4d15-5168-99b5-97ecf1748a76",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 5.2.11-tuxcare.8 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:3c220ccc-fa6f-54ef-83da-59433fc88304",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 5.2.11-tuxcare.8 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:51538d0f-17e6-5bc5-8f7d-2f49a689dc05",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 5.2.11-tuxcare.8 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:25b72514-137b-544e-80ba-1fa5e5f31a67",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 5.2.11-tuxcare.8 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:e3acdca7-d270-5e53-b6c7-715824613f20",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 5.2.11-tuxcare.8 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:b964f79a-d0ae-5bb1-899f-c7c8ff4a20f1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 5.2.11-tuxcare.8 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:2d9fada9-60d4-5c2e-a573-f4a0ff97189d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 5.2.11-tuxcare.8 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:58401c7f-957c-57ee-bfa4-26aa0c5310bc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 5.2.11-tuxcare.8 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:7fc4ada9-b2e6-567d-984e-35bde0a0b176",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 5.2.11-tuxcare.8 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:bda34ac4-8206-5e5f-b60d-ba0c90bc57d0",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 5.2.11-tuxcare.8 of @angular/common. not_affected \u2014 Angular 5.2.11 is NOT affected by CVE-2026-68945. The vulnerable component `HttpTransferCache` does not exist in this version. This feature was introduced in Angular v16 as part of the modern SSR hydration system. Angular 5.2.11 only has the basic `TransferState` API (a generic key-value store for manual state transfer), not the automatic HTTP request caching interceptor that contains the vulne...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:99946105-2f7b-5fdb-902a-18d7c180fcc8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 5.2.11-tuxcare.8 of @angular/common, and is fixed in 5.2.11-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:a9603a84-03f4-53f6-b8da-3f7331694a73",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 5.2.11-tuxcare.8 of @angular/common, and is fixed in 5.2.11-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:6a1b7a61-7cac-55ac-ab89-f55bf41a0e83",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 5.2.11-tuxcare.8 of @angular/common. not_affected \u2014 Angular 5.2.11-tuxcare.19 does not contain the vulnerable URL resolution code pattern described in CVE-2026-88056. The vulnerability requires the url.ts file with parseUrl function calling String.prototype.trim() and the relativeUrlsTransformerInterceptorFn HTTP interceptor, both introduced in later Angular versions (post-June 2026). The target version uses a fundamentally different architectur...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:b4cdcfe9-dd9e-5318-b7c5-1705bf37155e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 5.2.11-tuxcare.8 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:57fd346d-2766-5ab3-a1a3-8dac98d8deef",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 5.2.11-tuxcare.8 of @angular/common. not_affected \u2014 Angular 5.2.11 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache with hierarchical HttpClient delegation (withRequestsMadeViaParent()), features that were introduced in Angular v16. Angular 5.2.11 predates these features by approximately 6+ years and contains only a basic HTTP interceptor architecture with no automatic response caching mechanism. While TransferStat...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:c432ac39-3499-5ea6-8f23-fc00df40c1a7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 5.2.11-tuxcare.8 of @angular/common."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/common@5.2.11-tuxcare.8"
    }
  ]
}