{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:0540e0ff-08b7-596c-a91b-266c1057ce63",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/http",
      "purl": "pkg:npm/%40angular/http@5.2.11-tuxcare.9",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.9",
      "version": "5.2.11-tuxcare.9",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:1ce0da66-792e-5f06-b2c8-ac1a4010d213",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 5.2.11-tuxcare.9 of @angular/http."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:9ccc031c-40ba-53bc-b4ed-eaa1baa47d72",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 5.2.11-tuxcare.9 of @angular/http."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:dd0e4771-ca99-543c-9e02-7955acc58931",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 5.2.11-tuxcare.9 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:44a7c880-f188-510e-b7cf-8688404265db",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 5.2.11-tuxcare.9 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:25700763-1ae2-593b-9497-697f5bab3a6d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 5.2.11-tuxcare.9 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:874c5a24-af52-5b52-b3b0-3e8fd9666ddd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 5.2.11-tuxcare.9 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:e6c2b937-a6cd-59ca-b8f3-ec15fbe5d647",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 5.2.11-tuxcare.9 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:0386da1d-6fd3-52e3-bbc7-e74e0ba1eaa0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 5.2.11-tuxcare.9 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:4b297dee-58f1-594e-9c53-ed214cf3f899",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 5.2.11-tuxcare.9 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:9caaa29e-78c4-53a0-9115-e9e1f6f5ad06",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 5.2.11-tuxcare.9 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:4a738352-7dbc-53c4-914e-f192b74a9bf8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 5.2.11-tuxcare.9 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:318ebe1a-8525-59c8-87ca-775486ac7be6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 5.2.11-tuxcare.9 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:cbf9dfdd-a60c-571a-8aa0-ac7a830188f4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 5.2.11-tuxcare.9 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:4ed58dfb-5f1c-5d80-af6c-d5b1b41089a5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 5.2.11-tuxcare.9 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:b6a5a009-e3d5-5715-af44-b496fca28a34",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 5.2.11-tuxcare.9 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:9697cf37-7c96-5476-9220-046047e6e57b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 5.2.11-tuxcare.9 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:003ad33c-21cf-5a29-a10e-e0958cd3bb51",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 5.2.11-tuxcare.9 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:d68990c1-a41b-5d0a-8be7-64762f7ff466",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 5.2.11-tuxcare.9 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:c31fbb85-42cd-5da7-8baf-b53269907d8b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 5.2.11-tuxcare.9 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:31fa5fe3-f1f3-5ffd-b75d-e26b54a57a5f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 5.2.11-tuxcare.9 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:03f613eb-eccc-5bd2-b764-b6a4d06fc0de",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 5.2.11-tuxcare.9 of @angular/http. not_affected \u2014 Angular 5.2.11 is NOT affected by CVE-2026-68945. The vulnerable component `HttpTransferCache` does not exist in this version. This feature was introduced in Angular v16 as part of the modern SSR hydration system. Angular 5.2.11 only has the basic `TransferState` API (a generic key-value store for manual state transfer), not the automatic HTTP request caching interceptor that contains the vulne...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:ea8fe27a-5a24-58e6-8389-24617a1a466c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 5.2.11-tuxcare.9 of @angular/http, and is fixed in 5.2.11-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:6bac1feb-380c-598f-beec-f039396d2773",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 5.2.11-tuxcare.9 of @angular/http, and is fixed in 5.2.11-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:1a8ad21c-afec-506a-bbc9-4efd3bb983ec",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 5.2.11-tuxcare.9 of @angular/http. not_affected \u2014 Angular 5.2.11-tuxcare.19 does not contain the vulnerable URL resolution code pattern described in CVE-2026-88056. The vulnerability requires the url.ts file with parseUrl function calling String.prototype.trim() and the relativeUrlsTransformerInterceptorFn HTTP interceptor, both introduced in later Angular versions (post-June 2026). The target version uses a fundamentally different architectur...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:b4c1352b-cfcf-57c6-b31e-aa3769ee01c2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 5.2.11-tuxcare.9 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:55d9af27-290e-564c-b926-61e1b26b9efa",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 5.2.11-tuxcare.9 of @angular/http. not_affected \u2014 Angular 5.2.11 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache with hierarchical HttpClient delegation (withRequestsMadeViaParent()), features that were introduced in Angular v16. Angular 5.2.11 predates these features by approximately 6+ years and contains only a basic HTTP interceptor architecture with no automatic response caching mechanism. While TransferStat...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:111d9930-83a4-58e4-8123-9bf13a65ee4d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 5.2.11-tuxcare.9 of @angular/http."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.9"
    }
  ]
}