{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a5ba5d42-2017-518b-a86f-867ee00edc54",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/compiler-cli@14.2.12-tuxcare.1",
      "type": "library",
      "name": "@angular/compiler-cli",
      "version": "14.2.12-tuxcare.1",
      "purl": "pkg:npm/%40angular/compiler-cli@14.2.12-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:363348ff-e723-5eb6-a41b-5cbb74052225",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 14.2.12-tuxcare.1 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@14.2.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7000d0aa-9a74-5fa0-9c71-a575b01a8372",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66412 affects version 14.2.12-tuxcare.1 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@14.2.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ae4e3af-860b-588e-83db-da986e1c316f",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22610 affects version 14.2.12-tuxcare.1 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@14.2.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce553c2e-35cd-5e97-8d0a-ca50230d6712",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 14.2.12-tuxcare.1 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@14.2.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ea6fac4-efcc-59b9-be10-df39f4e356a2",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41423 affects version 14.2.12-tuxcare.1 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@14.2.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12d5c890-da35-568f-9d48-c6e05e0a1197",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 14.2.12-tuxcare.1 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@14.2.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a1014ce-d242-54eb-b088-bae8dabf7204",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 14.2.12-tuxcare.1 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@14.2.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f63a475b-dc89-5601-9c5c-f96f306349a5",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 14.2.12-tuxcare.1 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@14.2.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78c8521e-b235-5ca0-9926-fc8e846fb246",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50170 does not affect version 14.2.12-tuxcare.1 of @angular/compiler-cli. not_affected \u2014 Angular v14.2.12-tuxcare.1 is not affected by CVE-2026-50170. The HTTP TransferCache feature and client hydration mechanism that contain the vulnerability were introduced in Angular v16+. This version predates that feature introduction and does not have the vulnerable code path."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@14.2.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1757d62-76f1-5dfb-a787-55cd0c996817",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 14.2.12-tuxcare.1 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@14.2.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:589d1788-e8fe-5e3e-a32b-21c3c3028730",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 14.2.12-tuxcare.1 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@14.2.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3a785bd-17fc-51d4-bb9d-0c6a83359f24",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 14.2.12-tuxcare.1 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@14.2.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aed7b527-b979-569f-bd59-9225b9e37045",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 14.2.12-tuxcare.1 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@14.2.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d34280ca-89be-5893-97a2-547ef6cb56f5",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 14.2.12-tuxcare.1 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@14.2.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:293ccd71-06b3-5e43-be71-d870e1d3ff06",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 14.2.12-tuxcare.1 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@14.2.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c266399a-4130-50fd-af1c-ba611127dd37",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 14.2.12-tuxcare.1 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@14.2.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:065fe020-2af7-5c76-9951-07386608a486",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 14.2.12-tuxcare.1 of @angular/compiler-cli. not_affected \u2014 Angular 14.2.12-tuxcare.1 is not affected by CVE-2026-54265. This version uses the pre-pipeline compiler architecture where two-way bindings are desugared into separate property and event bindings, both of which go through proper sanitization. The vulnerability only exists in Angular 17.3.0+ where the template pipeline with TwoWayProperty IR operation was introduced."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@14.2.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1a66aea-fe6d-5246-ac5a-f189f80a1f3d",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54266 does not affect version 14.2.12-tuxcare.1 of @angular/compiler-cli. not_affected \u2014 Angular 14.2.12 is not affected by CVE-2026-54266. The vulnerable HttpTransferCache feature does not exist in this version - it was introduced in Angular v16+. The target has no code path that generates cache keys from HTTP request parameters, and therefore cannot experience cache key collisions."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@14.2.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d77e8084-96c3-5de7-b772-1043e96019f2",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 14.2.12-tuxcare.1 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@14.2.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:245cbf8c-b5a7-55e2-b951-f3fe630b79ae",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 14.2.12-tuxcare.1 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@14.2.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bf3cceb-1824-5ba8-87e5-fcc8631d578a",
      "id": "CVE-2026-68945",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 14.2.12-tuxcare.1 of @angular/compiler-cli. not_affected \u2014 Angular v14.2.12 is NOT AFFECTED by CVE-2026-68945. The vulnerable component, HttpTransferCache, was introduced in Angular v16.0.0 (commit aff1512950, March 2023) and does not exist in this version. While HttpParams (the input type) exists, there is no code path that uses it to generate cache keys for SSR HTTP request caching, breaking the required chain from input to the vulnerability goal. Th..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@14.2.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3e67dde-d13b-5610-8f8a-6d89dfd107fd",
      "id": "CVE-2026-69149",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 14.2.12-tuxcare.1 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@14.2.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68c89d44-2206-5e9f-bb4f-814c40ee5c57",
      "id": "CVE-2026-69151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 14.2.12-tuxcare.1 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@14.2.12-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/compiler-cli@14.2.12-tuxcare.1"
    }
  ]
}