{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:724b137c-fcad-5295-a965-998a5fd52fa8",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/platform-webworker",
      "purl": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.2",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.2",
      "version": "5.2.11-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:cd8ea09c-3ff7-55eb-9216-7852178bff5a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-4231 affects version 5.2.11-tuxcare.2 of @angular/platform-webworker, and is fixed in 5.2.11-tuxcare.4."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:49e9ef29-a926-52a8-9f27-f7fad36b2f65",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 5.2.11-tuxcare.2 of @angular/platform-webworker, and is fixed in 5.2.11-tuxcare.9."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:bd154293-9d10-5700-a05b-976176800786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66412 affects version 5.2.11-tuxcare.2 of @angular/platform-webworker, and is fixed in 5.2.11-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6eb857ad-0364-534a-b0d3-10364b3d8308",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22610 affects version 5.2.11-tuxcare.2 of @angular/platform-webworker, and is fixed in 5.2.11-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:853aef6f-601f-5934-a527-6e86f55225e0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 5.2.11-tuxcare.2 of @angular/platform-webworker, and is fixed in 5.2.11-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ca906749-d678-5aef-baf3-dd8aa0f18e1d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 5.2.11-tuxcare.2 of @angular/platform-webworker, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d1027756-dbb1-5620-8022-f27aee25a8f9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 5.2.11-tuxcare.2 of @angular/platform-webworker, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3d0c76b8-0521-5e13-b645-280ad34be584",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 5.2.11-tuxcare.2 of @angular/platform-webworker, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c010aae7-821c-5b81-a540-cf187e5ec741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 5.2.11-tuxcare.2 of @angular/platform-webworker, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:38d5b39c-5f9b-5c36-9499-eab0c68b7104",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 5.2.11-tuxcare.2 of @angular/platform-webworker, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1b7970ba-d9b9-501d-ba0f-f5efb91203e4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 5.2.11-tuxcare.2 of @angular/platform-webworker, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5030167a-638e-5b3b-a265-0abc9bc50b3d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 5.2.11-tuxcare.2 of @angular/platform-webworker, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2f176f76-61a5-5116-815a-ccd9c79ff71f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 5.2.11-tuxcare.2 of @angular/platform-webworker, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9d7e5d87-9ffa-5c93-b9b9-afbbbe557a44",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 5.2.11-tuxcare.2 of @angular/platform-webworker, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2db7710f-b597-52e8-b602-066fd6a124f6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 5.2.11-tuxcare.2 of @angular/platform-webworker, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:cef57517-12e9-5c3c-94e5-47d025254760",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 5.2.11-tuxcare.2 of @angular/platform-webworker, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4843a772-f4fd-5b17-9998-ad421d6524a4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 5.2.11-tuxcare.2 of @angular/platform-webworker, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9bf616e6-1773-55e2-bfae-c9468dd47ba2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 5.2.11-tuxcare.2 of @angular/platform-webworker, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:dcb61cd5-db93-5faa-9926-05d2105d196a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 5.2.11-tuxcare.2 of @angular/platform-webworker, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:17652f77-18e7-58a3-9d26-6c9d5417a851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 5.2.11-tuxcare.2 of @angular/platform-webworker, and is fixed in 5.2.11-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:66e9da25-ac3a-5916-a32b-fb560b7c1f9d",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 5.2.11-tuxcare.2 of @angular/platform-webworker. not_affected \u2014 Angular 5.2.11 is NOT affected by CVE-2026-68945. The vulnerable component `HttpTransferCache` does not exist in this version. This feature was introduced in Angular v16 as part of the modern SSR hydration system. Angular 5.2.11 only has the basic `TransferState` API (a generic key-value store for manual state transfer), not the automatic HTTP request caching interceptor that contains the vulne...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:890fac01-abe7-5725-8343-2c7fd8332958",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 5.2.11-tuxcare.2 of @angular/platform-webworker, and is fixed in 5.2.11-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:bd3b5f49-1e07-5a74-95c4-d589e74d2138",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 5.2.11-tuxcare.2 of @angular/platform-webworker, and is fixed in 5.2.11-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:578c3e4c-83bc-506c-9554-a3fad3119458",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 5.2.11-tuxcare.2 of @angular/platform-webworker. not_affected \u2014 Angular 5.2.11-tuxcare.19 does not contain the vulnerable URL resolution code pattern described in CVE-2026-88056. The vulnerability requires the url.ts file with parseUrl function calling String.prototype.trim() and the relativeUrlsTransformerInterceptorFn HTTP interceptor, both introduced in later Angular versions (post-June 2026). The target version uses a fundamentally different architectur...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:60bcf0f8-7e94-5e05-adcc-f25971bf3856",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 5.2.11-tuxcare.2 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6f439b17-f3e7-587f-b288-024abde73c6a",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 5.2.11-tuxcare.2 of @angular/platform-webworker. not_affected \u2014 Angular 5.2.11 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache with hierarchical HttpClient delegation (withRequestsMadeViaParent()), features that were introduced in Angular v16. Angular 5.2.11 predates these features by approximately 6+ years and contains only a basic HTTP interceptor architecture with no automatic response caching mechanism. While TransferStat...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:73442d2d-4ec6-5af1-92e8-685154665f0e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 5.2.11-tuxcare.2 of @angular/platform-webworker."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.2"
    }
  ]
}