{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a523c63f-7925-5fcf-80b4-c3288127a072",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/bazel@5.2.7-tuxcare.4",
      "type": "library",
      "name": "@angular/bazel",
      "version": "5.2.7-tuxcare.4",
      "purl": "pkg:npm/%40angular/bazel@5.2.7-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:c73f914c-d5e1-59a2-9fe6-20a38e8f801c",
      "id": "CVE-2021-4231",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 5.2.7-tuxcare.4 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10b6b140-cd10-5199-977b-97b5bd0dd542",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 5.2.7-tuxcare.4 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:097a182b-d5d6-5b1a-a587-2c08c5cb572a",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 5.2.7-tuxcare.4 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70b14844-7c51-524e-abe6-a69fd8b69fd1",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 5.2.7-tuxcare.4 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25cdfb6d-7866-5368-9979-6c1a32d62ade",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 5.2.7-tuxcare.4 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0d13100-d6aa-5493-a6ab-fcd9791eb95f",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41423 does not affect version 5.2.7-tuxcare.4 of @angular/bazel. not_affected \u2014 Angular version 5.2.7 is not affected by CVE-2026-41423. The vulnerability exists in later Angular versions (9+) that use the WHATWG URL API with hostname tracking. Version 5.2.7 uses Node's legacy url.parse() API and only tracks pathname/search/hash components, making the SSRF attack vector via hostname override impossible."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f388e97-c930-5729-bfb0-a95aaaa79ef9",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 5.2.7-tuxcare.4 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7b2de67-aabd-5c61-b250-2245646361c3",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 5.2.7-tuxcare.4 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0a753aa-a4c0-55fc-b68f-f36518f46cd5",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 5.2.7-tuxcare.4 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a80ecc4-8811-53d3-bdb1-da70329615ec",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50170 does not affect version 5.2.7-tuxcare.4 of @angular/bazel. not_affected \u2014 Angular 5.2.7 is not affected by CVE-2026-50170. The HTTP transfer cache feature that contains the vulnerability does not exist in this version. The transfer cache mechanism was introduced in Angular v16+, and Angular 5.2.7 predates this feature by many major versions."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69b03964-ef05-547d-9f69-81404ae43214",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 5.2.7-tuxcare.4 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb05f11f-433f-50e1-bec7-37f671d2c1fa",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 5.2.7-tuxcare.4 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e083bcb-bf72-5bae-9f71-47a49f1db4f8",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 5.2.7-tuxcare.4 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0460778d-0b4b-59fb-a639-6aee177e9849",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 5.2.7-tuxcare.4 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3b24dff-a520-522e-b572-d4243a3f008d",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 5.2.7-tuxcare.4 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bda0d262-7fd9-59ca-a215-693d77ba224a",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 5.2.7-tuxcare.4 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9c00c14-3972-59ad-b508-4a7550b0dfd8",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54264 does not affect version 5.2.7-tuxcare.4 of @angular/bazel. not_affected \u2014 Angular v5.2.7 is NOT affected by CVE-2026-54264. The service worker's asset-group request reconstruction uses URL-only rebuilding via adapter.newRequest(req.url), which creates fresh Request objects with no headers from the original request. Since headers are never forwarded in the first place, there is no opportunity for sensitive headers to leak on cross-origin redirects. The vulnerable code..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c1596e9-efa5-5048-8f3f-b6f1acc4e50b",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 5.2.7-tuxcare.4 of @angular/bazel. not_affected \u2014 Angular 5.2.7-tuxcare.2 uses the View Engine compiler architecture, which does not have the vulnerable TwoWayProperty operation present in Ivy. Two-way bindings desugar through the same parsePropertyBinding() code path as one-way bindings and receive identical schema-derived sanitization. The vulnerability requires the Ivy template compiler pipeline with resolve_sanitizers.ts missing the TwoWay..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7062df4-eae3-5154-8b86-2ff4155bbb18",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54266 does not affect version 5.2.7-tuxcare.4 of @angular/bazel. not_affected \u2014 Angular 5.2.7 is NOT affected by CVE-2026-54266. The vulnerable HttpTransferCache feature does not exist in this version (introduced in Angular v16+). No code path processes HTTP requests for automatic transfer cache key generation."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6261a92-adf1-52f8-a852-d6cde24c9897",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 5.2.7-tuxcare.4 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d9c0906-abd1-591a-8d55-a05a5ffa6c86",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 5.2.7-tuxcare.4 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a28991c8-bd18-569c-81f2-fd6a1488c849",
      "id": "CVE-2026-68945",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 5.2.7-tuxcare.4 of @angular/bazel. not_affected \u2014 Angular 5.2.7 is not affected by CVE-2026-68945. The vulnerable component HttpTransferCache does not exist in this version\u2014it was introduced in Angular v16. Angular 5.2.7 has only a generic TransferState key-value store with no automatic HTTP request caching or cache-key generation from HttpParams. The CVE-described vulnerability (cache-key collision when repeated parameter values are joined wi..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1f9a6e2-18a8-5b68-aee5-595649fd9351",
      "id": "CVE-2026-69149",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 5.2.7-tuxcare.4 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.7-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:966c0a9a-9645-5ea2-923c-deaec5c61934",
      "id": "CVE-2026-69151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 5.2.7-tuxcare.4 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.7-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/bazel@5.2.7-tuxcare.4"
    }
  ]
}