{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4e68d47d-743d-5a68-b703-ac71205f48d8",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/core",
      "purl": "pkg:npm/%40angular/core@5.2.11-tuxcare.1",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.1",
      "version": "5.2.11-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c5f58bcc-b794-5bea-98a5-2fb9e32692fa",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-4231 affects version 5.2.11-tuxcare.1 of @angular/core, and is fixed in 5.2.11-tuxcare.4."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d08ac195-e31c-5956-9413-6a0d4f4fb315",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 5.2.11-tuxcare.1 of @angular/core, and is fixed in 5.2.11-tuxcare.9."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9e49cb5b-6d81-52ab-9b54-895c6aa73ad6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66412 affects version 5.2.11-tuxcare.1 of @angular/core, and is fixed in 5.2.11-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:50b946c5-6eca-5d06-9dc5-cc5ad3a027be",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22610 affects version 5.2.11-tuxcare.1 of @angular/core, and is fixed in 5.2.11-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:80884ecf-b04b-560e-9b5b-c070d048d4fd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 5.2.11-tuxcare.1 of @angular/core, and is fixed in 5.2.11-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ef8bcf6d-2179-5c02-83e0-ecf67edc5797",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 5.2.11-tuxcare.1 of @angular/core, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c4271c19-3f27-50f8-b9fb-67dba8f23f79",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 5.2.11-tuxcare.1 of @angular/core, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6bc4c160-c49a-5aa8-9dfa-e9c76e63d339",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 5.2.11-tuxcare.1 of @angular/core, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e6ec8c74-d395-550b-a37e-d3b8fcbe8ef2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 5.2.11-tuxcare.1 of @angular/core, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2630fc2c-d3f5-5c60-b43b-9837bdca7643",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 5.2.11-tuxcare.1 of @angular/core, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9a9c22b4-2c04-5776-ab4c-bb1af0f4c413",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 5.2.11-tuxcare.1 of @angular/core, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d983b535-72d0-592e-8674-73edb596a159",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 5.2.11-tuxcare.1 of @angular/core, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:bf816272-58cf-51a3-a313-c55ad3d000fa",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 5.2.11-tuxcare.1 of @angular/core, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4ee58308-255d-5be9-b4b5-424740b6a219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 5.2.11-tuxcare.1 of @angular/core, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9dac3ccb-9d17-5e48-9a95-faa280a874f5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 5.2.11-tuxcare.1 of @angular/core, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:631c75a1-53b7-56d7-9e4a-838276fea188",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 5.2.11-tuxcare.1 of @angular/core, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:dfc2aeaf-ee9f-5789-9608-9ae554e5d6eb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 5.2.11-tuxcare.1 of @angular/core, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4aff9dbe-a993-561b-8478-20a471fda4e6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 5.2.11-tuxcare.1 of @angular/core, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:73a90757-de4a-5e62-b21d-2bba10dabfbe",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 5.2.11-tuxcare.1 of @angular/core, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:049286f6-45b0-574a-ae7a-22fb205fa340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 5.2.11-tuxcare.1 of @angular/core, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:363bb7e3-69e6-5fe7-942e-26ce7831c921",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 5.2.11-tuxcare.1 of @angular/core. not_affected \u2014 Angular 5.2.11 is NOT affected by CVE-2026-68945. The vulnerable component `HttpTransferCache` does not exist in this version. This feature was introduced in Angular v16 as part of the modern SSR hydration system. Angular 5.2.11 only has the basic `TransferState` API (a generic key-value store for manual state transfer), not the automatic HTTP request caching interceptor that contains the vulne...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c3574d00-23ed-5c09-afa3-77bbe8878e3f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 5.2.11-tuxcare.1 of @angular/core, and is fixed in 5.2.11-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7aae4ea7-c342-5fe0-8376-46d5213a04eb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 5.2.11-tuxcare.1 of @angular/core, and is fixed in 5.2.11-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d653ffb5-a1dc-5963-beb8-cd460f19ef94",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 5.2.11-tuxcare.1 of @angular/core. not_affected \u2014 Angular 5.2.11-tuxcare.19 does not contain the vulnerable URL resolution code pattern described in CVE-2026-88056. The vulnerability requires the url.ts file with parseUrl function calling String.prototype.trim() and the relativeUrlsTransformerInterceptorFn HTTP interceptor, both introduced in later Angular versions (post-June 2026). The target version uses a fundamentally different architectur...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:bfade659-359e-5252-9baa-15fd620424c9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 5.2.11-tuxcare.1 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:51d17c3c-577f-502b-81e8-8524374dcdab",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 5.2.11-tuxcare.1 of @angular/core. not_affected \u2014 Angular 5.2.11 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache with hierarchical HttpClient delegation (withRequestsMadeViaParent()), features that were introduced in Angular v16. Angular 5.2.11 predates these features by approximately 6+ years and contains only a basic HTTP interceptor architecture with no automatic response caching mechanism. While TransferStat...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:071fb1fd-f270-5f77-a087-b7cd9d467ba4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 5.2.11-tuxcare.1 of @angular/core."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.1"
    }
  ]
}