{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:18238281-7759-5027-b264-ddc773cc70f6",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/platform-webworker",
      "purl": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.8",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.8",
      "version": "5.2.11-tuxcare.8",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:b77cc9f9-8150-558e-b2fb-02c5e2c04e7d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 5.2.11-tuxcare.8 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:e99dedf3-ec6d-57ff-9314-4b13a6f42943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 5.2.11-tuxcare.8 of @angular/platform-webworker, and is fixed in 5.2.11-tuxcare.9."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:8aa77c5e-9856-57ca-b059-896a04e63b0c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 5.2.11-tuxcare.8 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:b6515eaa-8569-5829-9f52-1210655bd6b9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 5.2.11-tuxcare.8 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:1122a580-0efd-541a-bbf2-4ab6b4192950",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 5.2.11-tuxcare.8 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:fcb7c67a-7851-5cdc-aca2-bf68e60026ad",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 5.2.11-tuxcare.8 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:f09af489-0eb2-5f36-a31b-5886245d0c52",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 5.2.11-tuxcare.8 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:24e94f8d-149c-53af-b019-378fc9ed581c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 5.2.11-tuxcare.8 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:76549904-f35f-5fc6-9807-52430f92b6b6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 5.2.11-tuxcare.8 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:2b907955-8015-552a-97d9-17738d4df13c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 5.2.11-tuxcare.8 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:07141ac1-2db0-56f7-9b2a-af40fe085d70",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 5.2.11-tuxcare.8 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:f2d57800-5938-5678-a5c7-ef92552bb8e0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 5.2.11-tuxcare.8 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:606e9644-e440-5f00-a750-a4893a98d926",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 5.2.11-tuxcare.8 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:4c3ce813-67d1-5eff-828b-099307bd38e4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 5.2.11-tuxcare.8 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:ce578566-5d47-5a04-9043-b6cd4af4799b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 5.2.11-tuxcare.8 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:63b88a55-134a-5de9-b978-23cd639aaccd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 5.2.11-tuxcare.8 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:9e3607fb-76be-5839-84b0-851484c5be5e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 5.2.11-tuxcare.8 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:14d32c18-3c1b-5847-a2fa-9920b532f96f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 5.2.11-tuxcare.8 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:b4eb636e-f10b-51f4-91f8-38c869351e54",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 5.2.11-tuxcare.8 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:1518513c-1daf-5abd-89a9-dd50533cc863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 5.2.11-tuxcare.8 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:597451f0-b196-54db-a4bd-29bdda6ffcd5",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 5.2.11-tuxcare.8 of @angular/platform-webworker. not_affected \u2014 Angular 5.2.11 is NOT affected by CVE-2026-68945. The vulnerable component `HttpTransferCache` does not exist in this version. This feature was introduced in Angular v16 as part of the modern SSR hydration system. Angular 5.2.11 only has the basic `TransferState` API (a generic key-value store for manual state transfer), not the automatic HTTP request caching interceptor that contains the vulne...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:c5dfa9d1-70cd-5021-ac5c-400f8052fbd0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 5.2.11-tuxcare.8 of @angular/platform-webworker, and is fixed in 5.2.11-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:f81ec5b3-e025-5f7c-8de8-c882302dc23b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 5.2.11-tuxcare.8 of @angular/platform-webworker, and is fixed in 5.2.11-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:8476119b-bc7c-5097-96b3-08aec1b40fd6",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 5.2.11-tuxcare.8 of @angular/platform-webworker. not_affected \u2014 Angular 5.2.11-tuxcare.19 does not contain the vulnerable URL resolution code pattern described in CVE-2026-88056. The vulnerability requires the url.ts file with parseUrl function calling String.prototype.trim() and the relativeUrlsTransformerInterceptorFn HTTP interceptor, both introduced in later Angular versions (post-June 2026). The target version uses a fundamentally different architectur...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:fdcfcfa4-8bbb-515c-aade-53a0d94b3068",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 5.2.11-tuxcare.8 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:8574eaef-0a06-5c06-a93e-800478196093",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 5.2.11-tuxcare.8 of @angular/platform-webworker. not_affected \u2014 Angular 5.2.11 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache with hierarchical HttpClient delegation (withRequestsMadeViaParent()), features that were introduced in Angular v16. Angular 5.2.11 predates these features by approximately 6+ years and contains only a basic HTTP interceptor architecture with no automatic response caching mechanism. While TransferStat...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:5b226632-9f08-5359-a4ea-5dc2cdf6ab1c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 5.2.11-tuxcare.8 of @angular/platform-webworker."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/platform-webworker@5.2.11-tuxcare.8"
    }
  ]
}