{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:faf3379a-a07d-555b-afe8-d7347152e8a1",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/platform-browser-dynamic",
      "purl": "pkg:npm/%40angular/platform-browser-dynamic@5.2.11-tuxcare.6",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/platform-browser-dynamic@5.2.11-tuxcare.6",
      "version": "5.2.11-tuxcare.6",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@5.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:5b6f04fd-ea4b-5913-93e5-b9b085962edd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 5.2.11-tuxcare.6 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@5.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:bfa89062-65d4-52ba-917d-2a2f6835af22",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 5.2.11-tuxcare.6 of @angular/platform-browser-dynamic, and is fixed in 5.2.11-tuxcare.9."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@5.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:892a21d0-23fd-556e-8508-81dd67ea52ec",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 5.2.11-tuxcare.6 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@5.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f6f0e96a-c5b9-5219-a04c-10d9e624dc23",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 5.2.11-tuxcare.6 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@5.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:9c54caef-b61f-5523-ab96-a0c5908636ad",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 5.2.11-tuxcare.6 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@5.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e9269ff9-6f0e-5dd9-bf2a-88223a945be7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 5.2.11-tuxcare.6 of @angular/platform-browser-dynamic, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@5.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:5d7c435b-30b4-50e1-8e68-b472df6a907a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 5.2.11-tuxcare.6 of @angular/platform-browser-dynamic, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@5.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:9e0c95d1-9228-573a-94b9-8f413873dbfa",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 5.2.11-tuxcare.6 of @angular/platform-browser-dynamic, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@5.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:668224f9-56f2-57f2-8532-1c42615cc4b8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 5.2.11-tuxcare.6 of @angular/platform-browser-dynamic, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@5.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:21d397f2-9ca6-55f4-92fe-88c4bb266993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 5.2.11-tuxcare.6 of @angular/platform-browser-dynamic, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@5.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:81e76b70-7a82-5290-a49f-25f62e2d5023",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 5.2.11-tuxcare.6 of @angular/platform-browser-dynamic, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@5.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2590c9b4-e49a-52b3-b2ad-7a75ef5f99bc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 5.2.11-tuxcare.6 of @angular/platform-browser-dynamic, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@5.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d2164c1c-34ef-5533-a450-19c4fbd55e53",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 5.2.11-tuxcare.6 of @angular/platform-browser-dynamic, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@5.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:dec4e7b0-f726-565c-837f-63684d650b39",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 5.2.11-tuxcare.6 of @angular/platform-browser-dynamic, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@5.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:914562cd-73af-5c36-8452-a3fde4cc8f68",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 5.2.11-tuxcare.6 of @angular/platform-browser-dynamic, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@5.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ee6076a3-6581-5075-b696-ff0ef43c74b8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 5.2.11-tuxcare.6 of @angular/platform-browser-dynamic, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@5.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a2108597-4647-5761-8692-61a6f74f91b7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 5.2.11-tuxcare.6 of @angular/platform-browser-dynamic, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@5.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2e64ce43-a50d-5eb4-96bb-b51cdf339682",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 5.2.11-tuxcare.6 of @angular/platform-browser-dynamic, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@5.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:3e3879ab-fd43-53f0-b431-fe6f88e11386",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 5.2.11-tuxcare.6 of @angular/platform-browser-dynamic, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@5.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:83172c7c-3537-5953-be74-60925c5da0d4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 5.2.11-tuxcare.6 of @angular/platform-browser-dynamic, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@5.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ec14f080-8b3f-5d31-9bfb-1909441f6de0",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 5.2.11-tuxcare.6 of @angular/platform-browser-dynamic. not_affected \u2014 Angular 5.2.11 is NOT affected by CVE-2026-68945. The vulnerable component `HttpTransferCache` does not exist in this version. This feature was introduced in Angular v16 as part of the modern SSR hydration system. Angular 5.2.11 only has the basic `TransferState` API (a generic key-value store for manual state transfer), not the automatic HTTP request caching interceptor that contains the vulne...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@5.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:19f8a816-51ad-5d5e-8806-64c735633dd1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 5.2.11-tuxcare.6 of @angular/platform-browser-dynamic, and is fixed in 5.2.11-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@5.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:038ef79a-88d7-5239-ab91-ca4ba5f89817",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 5.2.11-tuxcare.6 of @angular/platform-browser-dynamic, and is fixed in 5.2.11-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@5.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:34d24dd6-1774-571e-a03a-6bb355a59336",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 5.2.11-tuxcare.6 of @angular/platform-browser-dynamic. not_affected \u2014 Angular 5.2.11-tuxcare.19 does not contain the vulnerable URL resolution code pattern described in CVE-2026-88056. The vulnerability requires the url.ts file with parseUrl function calling String.prototype.trim() and the relativeUrlsTransformerInterceptorFn HTTP interceptor, both introduced in later Angular versions (post-June 2026). The target version uses a fundamentally different architectur...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@5.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c16ac997-c6cf-57f5-80b9-d80e274889e0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 5.2.11-tuxcare.6 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@5.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1d402cbf-41db-584d-8878-8ce47fd8688c",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 5.2.11-tuxcare.6 of @angular/platform-browser-dynamic. not_affected \u2014 Angular 5.2.11 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache with hierarchical HttpClient delegation (withRequestsMadeViaParent()), features that were introduced in Angular v16. Angular 5.2.11 predates these features by approximately 6+ years and contains only a basic HTTP interceptor architecture with no automatic response caching mechanism. While TransferStat...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@5.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6ce71c95-c50e-5b3a-8a23-81ceffea18b1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 5.2.11-tuxcare.6 of @angular/platform-browser-dynamic."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/platform-browser-dynamic@5.2.11-tuxcare.6"
    }
  ]
}