{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b3f5dc50-81d9-5057-959b-f3dfb49968f4",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/platform-webworker-dynamic",
      "purl": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.9",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.9",
      "version": "5.2.11-tuxcare.9",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:60aeefdf-c0d8-5e85-997f-7b052eca33aa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 5.2.11-tuxcare.9 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:64b7bac7-922d-55cb-bac3-535a4332f7d6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 5.2.11-tuxcare.9 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:f3c40a34-dad6-5ea4-9f54-e68c27337e70",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 5.2.11-tuxcare.9 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:bd8eae64-aed6-5089-85dc-47e834898ec1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 5.2.11-tuxcare.9 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:6bff5b73-4dcd-59b2-a7ed-208959d893e0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 5.2.11-tuxcare.9 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:1c45d97f-3978-5731-a86c-460f2000defd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 5.2.11-tuxcare.9 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:0f3a0cab-445c-53fa-a6fe-691d29c33ab7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 5.2.11-tuxcare.9 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:cf22af6a-96e9-5e7b-85d8-ef6e66ac56e0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 5.2.11-tuxcare.9 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:b77270d0-2cc4-5d38-b446-496dcd9ab4bc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 5.2.11-tuxcare.9 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:467945d0-31ae-5f75-8386-a79919debcf7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 5.2.11-tuxcare.9 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:3ecd1ffc-cc4d-5222-9203-9c0e9990ea3c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 5.2.11-tuxcare.9 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:e2691805-aa22-5bd0-b452-6a029bde2a21",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 5.2.11-tuxcare.9 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:41706aeb-f552-597a-b4c6-f17ee4d6e19a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 5.2.11-tuxcare.9 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:d1c7c1e0-d23b-54d4-bae9-0d4dae045202",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 5.2.11-tuxcare.9 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:789356c1-3b05-595a-b826-2eddbe900f97",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 5.2.11-tuxcare.9 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:e80834fc-5733-55af-b696-c5170c21023b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 5.2.11-tuxcare.9 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:a655d99f-b592-50b6-928f-f5a308797515",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 5.2.11-tuxcare.9 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:c12eaafc-6e58-50c4-ad08-780d775228d3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 5.2.11-tuxcare.9 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:58ffcefe-5fd6-58ce-9c97-057dc643c4d3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 5.2.11-tuxcare.9 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:21af02d7-c653-5a0a-b4fe-7e533ab67100",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 5.2.11-tuxcare.9 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:338118f3-dca7-5015-bc05-183c653872c2",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 5.2.11-tuxcare.9 of @angular/platform-webworker-dynamic. not_affected \u2014 Angular 5.2.11 is NOT affected by CVE-2026-68945. The vulnerable component `HttpTransferCache` does not exist in this version. This feature was introduced in Angular v16 as part of the modern SSR hydration system. Angular 5.2.11 only has the basic `TransferState` API (a generic key-value store for manual state transfer), not the automatic HTTP request caching interceptor that contains the vulne...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:9305ab6f-eed5-557d-9d82-1352c6e2750b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 5.2.11-tuxcare.9 of @angular/platform-webworker-dynamic, and is fixed in 5.2.11-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:2c23e373-5673-5f4a-b5cb-5c41ae5be721",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 5.2.11-tuxcare.9 of @angular/platform-webworker-dynamic, and is fixed in 5.2.11-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:2b2bd44c-c868-58a6-87b0-940a1416d382",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 5.2.11-tuxcare.9 of @angular/platform-webworker-dynamic. not_affected \u2014 Angular 5.2.11-tuxcare.19 does not contain the vulnerable URL resolution code pattern described in CVE-2026-88056. The vulnerability requires the url.ts file with parseUrl function calling String.prototype.trim() and the relativeUrlsTransformerInterceptorFn HTTP interceptor, both introduced in later Angular versions (post-June 2026). The target version uses a fundamentally different architectur...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:7bb31ea6-a293-59bc-bb03-6b7c8829a87f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 5.2.11-tuxcare.9 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:de0e5c3a-40ab-5ff0-a914-13035d0c2b20",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 5.2.11-tuxcare.9 of @angular/platform-webworker-dynamic. not_affected \u2014 Angular 5.2.11 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache with hierarchical HttpClient delegation (withRequestsMadeViaParent()), features that were introduced in Angular v16. Angular 5.2.11 predates these features by approximately 6+ years and contains only a basic HTTP interceptor architecture with no automatic response caching mechanism. While TransferStat...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:3b18629d-b765-5328-87cf-8fa9577f5d80",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 5.2.11-tuxcare.9 of @angular/platform-webworker-dynamic."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/platform-webworker-dynamic@5.2.11-tuxcare.9"
    }
  ]
}