{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:eb7b74ec-13d8-563e-b2b8-89db4605d82b",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/compiler",
      "purl": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.20",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.20",
      "version": "5.2.11-tuxcare.20",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:28d4b3f9-e185-5a20-b0e0-dc55e2f7f230",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 5.2.11-tuxcare.20 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:498dac0e-9861-50de-9e5e-f3a1331c47cd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 5.2.11-tuxcare.20 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:e077669c-68bf-5f55-b507-cde252dbf0c0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 5.2.11-tuxcare.20 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:e48b67f6-ab0c-5ce8-8fbc-fad07803bd38",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101895 affects version 5.2.11-tuxcare.20 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:4c7d9fa1-9d81-5f41-80ea-98c56f660cb9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 5.2.11-tuxcare.20 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:09737e8e-cf8d-5a98-9cef-1bdcacdaef39",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 5.2.11-tuxcare.20 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:aad8b403-d7d5-5e84-8c40-0845de8e020c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 5.2.11-tuxcare.20 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:f7e4aa2c-10fd-537a-9393-4830f261bff9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 5.2.11-tuxcare.20 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:114f3eb2-73fe-5b12-9f44-b4e6d819d5be",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 5.2.11-tuxcare.20 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:c44120b9-048c-5991-a389-709fd2405195",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 5.2.11-tuxcare.20 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:21a3dc19-68c0-5be9-af8e-d5c7bb0c4a4d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 5.2.11-tuxcare.20 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:cb2b5586-26ee-5c79-8fdc-eaf6bf2d8339",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 5.2.11-tuxcare.20 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:0f7f6333-e6e4-58ab-98b3-94ad27ef8055",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 5.2.11-tuxcare.20 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:7e9bb4b8-bad8-53cb-b625-8f600fa05ef1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 5.2.11-tuxcare.20 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:da25d14a-e2f3-5723-8bff-228a17780277",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 5.2.11-tuxcare.20 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:c7535796-a19e-5e33-9121-b98a200c2226",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 5.2.11-tuxcare.20 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:1d858d36-337b-56f3-8511-66a2db931dd2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 5.2.11-tuxcare.20 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:78baa601-48c2-50ac-b0c2-02d6f9741070",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 5.2.11-tuxcare.20 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:c4429f5b-dd90-5446-a8c2-dd8c2ab6a011",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 5.2.11-tuxcare.20 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:dee0f32f-226c-532b-9130-9747eb8345a7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 5.2.11-tuxcare.20 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:fad9a655-b0ba-52ae-9f7b-1c96faa01fc9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 5.2.11-tuxcare.20 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:8e1aef25-87e0-5704-acb9-cc4bdb4bb577",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 5.2.11-tuxcare.20 of @angular/compiler. not_affected \u2014 Angular 5.2.11 is NOT affected by CVE-2026-68945. The vulnerable component `HttpTransferCache` does not exist in this version. This feature was introduced in Angular v16 as part of the modern SSR hydration system. Angular 5.2.11 only has the basic `TransferState` API (a generic key-value store for manual state transfer), not the automatic HTTP request caching interceptor that contains the vulne...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:bab38d3b-9c51-5b84-af3e-6fc2070d0f58",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 5.2.11-tuxcare.20 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:b95ad63d-6314-5e17-a5c7-ad639c375d3a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 5.2.11-tuxcare.20 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:efcfd287-71f3-5040-b53a-2ad2b0cb6b83",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 5.2.11-tuxcare.20 of @angular/compiler. not_affected \u2014 Angular 5.2.11-tuxcare.19 does not contain the vulnerable URL resolution code pattern described in CVE-2026-88056. The vulnerability requires the url.ts file with parseUrl function calling String.prototype.trim() and the relativeUrlsTransformerInterceptorFn HTTP interceptor, both introduced in later Angular versions (post-June 2026). The target version uses a fundamentally different architectur...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:9db19238-e514-57b0-85b8-5c1f78f08093",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 5.2.11-tuxcare.20 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:8e991795-2360-5a8e-83fe-94928afef4a5",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88058 does not affect version 5.2.11-tuxcare.20 of @angular/compiler. not_affected \u2014 CVE-2026-88058 affects the domino library's HTML serialization (XSS via ancestor fallback raw-content tag injection in comments/processing instructions during SSR). The target Angular 5.2.11-tuxcare.19 repository declares domino 2.1.2 as a dependency but does NOT vendor its source code. The vulnerable code (NodeUtils.js serializeOne() function) lives in the domino npm package, not in Angular's ...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:bf558c78-3e96-5c94-9d2e-f7f6f8105ece",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 5.2.11-tuxcare.20 of @angular/compiler. not_affected \u2014 Angular 5.2.11 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache with hierarchical HttpClient delegation (withRequestsMadeViaParent()), features that were introduced in Angular v16. Angular 5.2.11 predates these features by approximately 6+ years and contains only a basic HTTP interceptor architecture with no automatic response caching mechanism. While TransferStat...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:b506e1db-c25c-58a6-95c5-7e54ac9125d1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 5.2.11-tuxcare.20 of @angular/compiler."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.20"
    }
  ]
}