{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:47f03105-03fe-5072-960c-842c6bee1fc6",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/platform-webworker-dynamic",
      "purl": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.4",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.4",
      "version": "5.2.11-tuxcare.4",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:0d73a60e-8af7-54d1-9cbe-e330b151dc61",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 5.2.11-tuxcare.4 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:931088d6-040b-53af-8314-bf2fd8013d2a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 5.2.11-tuxcare.4 of @angular/platform-webworker-dynamic, and is fixed in 5.2.11-tuxcare.9."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:7d079c01-826f-541b-af27-ede01766d931",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 5.2.11-tuxcare.4 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:feed50b3-2e0b-5e9f-b534-7d5ac0dfb589",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 5.2.11-tuxcare.4 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:f5b86e52-2092-5fd2-b3d4-49fac7d52849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 5.2.11-tuxcare.4 of @angular/platform-webworker-dynamic, and is fixed in 5.2.11-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:087f61e2-cd2a-56ad-839b-38010a83f6ad",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 5.2.11-tuxcare.4 of @angular/platform-webworker-dynamic, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:c46b31a4-8513-5b26-b87b-8925c46ee7e5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 5.2.11-tuxcare.4 of @angular/platform-webworker-dynamic, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:efa2ef6d-3448-54d2-bb6c-4f96cde42ac5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 5.2.11-tuxcare.4 of @angular/platform-webworker-dynamic, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:95eb562e-237b-528f-b642-ab492ac7492a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 5.2.11-tuxcare.4 of @angular/platform-webworker-dynamic, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:5e8d8d97-c1e0-5822-9c0f-7a8398273175",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 5.2.11-tuxcare.4 of @angular/platform-webworker-dynamic, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e8850cc4-bbe4-5826-8d4d-b81820f064f2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 5.2.11-tuxcare.4 of @angular/platform-webworker-dynamic, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:51734449-785b-5b4c-b528-b4d5abc2ce57",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 5.2.11-tuxcare.4 of @angular/platform-webworker-dynamic, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:1b534a26-66c5-5e26-aeb9-4383ca98a70d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 5.2.11-tuxcare.4 of @angular/platform-webworker-dynamic, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a2b25203-892e-5e1c-9918-4255d4658fe7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 5.2.11-tuxcare.4 of @angular/platform-webworker-dynamic, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:04236550-69f8-59b1-87ab-e403964f0d31",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 5.2.11-tuxcare.4 of @angular/platform-webworker-dynamic, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e89bd257-fb85-58db-9528-0f8573571c1f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 5.2.11-tuxcare.4 of @angular/platform-webworker-dynamic, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:7fa59432-38e5-5de5-9a8d-903d40a944c6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 5.2.11-tuxcare.4 of @angular/platform-webworker-dynamic, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:2b33d04e-2de9-5d99-908c-935012ca3aca",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 5.2.11-tuxcare.4 of @angular/platform-webworker-dynamic, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:c03f8091-ee15-5cb5-be18-25248ead426f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 5.2.11-tuxcare.4 of @angular/platform-webworker-dynamic, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:6348ad77-7cf5-517e-b8d1-ed788edea1bc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 5.2.11-tuxcare.4 of @angular/platform-webworker-dynamic, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:182efea3-bc37-5bc8-bdae-e296257e0f02",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 5.2.11-tuxcare.4 of @angular/platform-webworker-dynamic. not_affected \u2014 Angular 5.2.11 is NOT affected by CVE-2026-68945. The vulnerable component `HttpTransferCache` does not exist in this version. This feature was introduced in Angular v16 as part of the modern SSR hydration system. Angular 5.2.11 only has the basic `TransferState` API (a generic key-value store for manual state transfer), not the automatic HTTP request caching interceptor that contains the vulne...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e8829d23-36b4-58f1-a36e-5e1404f35aa0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 5.2.11-tuxcare.4 of @angular/platform-webworker-dynamic, and is fixed in 5.2.11-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:5e8917cc-8dab-52d8-bb9d-4c35c1dd7b6f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 5.2.11-tuxcare.4 of @angular/platform-webworker-dynamic, and is fixed in 5.2.11-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:28254412-980a-52bc-b3c0-43a033884f3a",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 5.2.11-tuxcare.4 of @angular/platform-webworker-dynamic. not_affected \u2014 Angular 5.2.11-tuxcare.19 does not contain the vulnerable URL resolution code pattern described in CVE-2026-88056. The vulnerability requires the url.ts file with parseUrl function calling String.prototype.trim() and the relativeUrlsTransformerInterceptorFn HTTP interceptor, both introduced in later Angular versions (post-June 2026). The target version uses a fundamentally different architectur...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:ff34f757-9799-5aca-ae87-4123caf5b01a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 5.2.11-tuxcare.4 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:17a14e9d-17fe-5bcd-a5f3-43f64718e266",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 5.2.11-tuxcare.4 of @angular/platform-webworker-dynamic. not_affected \u2014 Angular 5.2.11 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache with hierarchical HttpClient delegation (withRequestsMadeViaParent()), features that were introduced in Angular v16. Angular 5.2.11 predates these features by approximately 6+ years and contains only a basic HTTP interceptor architecture with no automatic response caching mechanism. While TransferStat...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a0dab7a2-8673-5321-b03c-3929c19f9dee",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 5.2.11-tuxcare.4 of @angular/platform-webworker-dynamic."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.4"
    }
  ]
}