{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:7847cfc8-7bc3-5a66-9d2b-1da2bc4667eb",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/http",
      "purl": "pkg:npm/%40angular/http@5.2.11-tuxcare.7",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.7",
      "version": "5.2.11-tuxcare.7",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:cefe1410-61dd-59c8-a215-c44f7574793b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 5.2.11-tuxcare.7 of @angular/http."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:557fe892-ae96-541b-8eee-c8e79fdb1327",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 5.2.11-tuxcare.7 of @angular/http, and is fixed in 5.2.11-tuxcare.9."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:e4cdf02f-82d7-507f-a608-6ff9a81eaafc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 5.2.11-tuxcare.7 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:bc6eb3ae-961d-5c65-800a-24fbc292bd51",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 5.2.11-tuxcare.7 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:eda32143-aade-58cf-aca6-37fbf90e93ed",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 5.2.11-tuxcare.7 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:ef37baeb-18d6-55e6-a33f-969a3a30d896",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 5.2.11-tuxcare.7 of @angular/http, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:a1005e43-8ebe-5f2c-8cb1-242e4005c756",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 5.2.11-tuxcare.7 of @angular/http, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:c79e0713-4197-5924-a590-09786094cc7b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 5.2.11-tuxcare.7 of @angular/http, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:89efbb7e-5032-5094-b883-7117e8b731c9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 5.2.11-tuxcare.7 of @angular/http, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:570521bb-f152-5c2e-a0e9-746c80f95ecd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 5.2.11-tuxcare.7 of @angular/http, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:0e3f1223-7b48-5097-a626-2df96be3bfc0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 5.2.11-tuxcare.7 of @angular/http, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:2b5034cf-8618-5991-93be-a86629c11abc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 5.2.11-tuxcare.7 of @angular/http, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:0486ffa6-ea46-5564-aad7-75aa75a3c7f7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 5.2.11-tuxcare.7 of @angular/http, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:1ce70821-321b-5f77-9d4c-97991e03d034",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 5.2.11-tuxcare.7 of @angular/http, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:c34e4c61-dd75-5407-80a4-77b522641007",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 5.2.11-tuxcare.7 of @angular/http, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:f577e402-934d-5594-ab50-0add16014d1d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 5.2.11-tuxcare.7 of @angular/http, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:8d38a603-c69e-5f25-a5cb-bd5263da364d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 5.2.11-tuxcare.7 of @angular/http, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:63555bc8-d376-5c33-9249-32c96926096e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 5.2.11-tuxcare.7 of @angular/http, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:3def9839-93ed-5279-8cf1-966a29e89322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 5.2.11-tuxcare.7 of @angular/http, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:ddab4e5b-8702-5c62-9fd5-c60ece5d2af4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 5.2.11-tuxcare.7 of @angular/http, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:ebf18857-811b-56ec-9d27-6786d441a8ee",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 5.2.11-tuxcare.7 of @angular/http. not_affected \u2014 Angular 5.2.11 is NOT affected by CVE-2026-68945. The vulnerable component `HttpTransferCache` does not exist in this version. This feature was introduced in Angular v16 as part of the modern SSR hydration system. Angular 5.2.11 only has the basic `TransferState` API (a generic key-value store for manual state transfer), not the automatic HTTP request caching interceptor that contains the vulne...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:ff348c5d-b75e-53d8-9c9c-7bfde885975e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 5.2.11-tuxcare.7 of @angular/http, and is fixed in 5.2.11-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:6b0a5238-1937-53c3-b4e1-066745814f61",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 5.2.11-tuxcare.7 of @angular/http, and is fixed in 5.2.11-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:2e2578bc-3780-5b39-a62b-11d1d9cba444",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 5.2.11-tuxcare.7 of @angular/http. not_affected \u2014 Angular 5.2.11-tuxcare.19 does not contain the vulnerable URL resolution code pattern described in CVE-2026-88056. The vulnerability requires the url.ts file with parseUrl function calling String.prototype.trim() and the relativeUrlsTransformerInterceptorFn HTTP interceptor, both introduced in later Angular versions (post-June 2026). The target version uses a fundamentally different architectur...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:28867d1a-414c-5965-b13e-5eaba067f24f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 5.2.11-tuxcare.7 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:730618ad-e2c1-5db8-99d1-760ea804b1e0",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 5.2.11-tuxcare.7 of @angular/http. not_affected \u2014 Angular 5.2.11 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache with hierarchical HttpClient delegation (withRequestsMadeViaParent()), features that were introduced in Angular v16. Angular 5.2.11 predates these features by approximately 6+ years and contains only a basic HTTP interceptor architecture with no automatic response caching mechanism. While TransferStat...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:b13449e9-47cd-59c6-b1ca-5a053c5b21f5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 5.2.11-tuxcare.7 of @angular/http."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.7"
    }
  ]
}