{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:cf8a2a30-86e5-5796-946d-c086cc80bd57",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/core@14.3.0-tuxcare.9",
      "type": "library",
      "name": "@angular/core",
      "version": "14.3.0-tuxcare.9",
      "purl": "pkg:npm/%40angular/core@14.3.0-tuxcare.9"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:7f84ed06-36e9-5b77-9093-05e1eb29ff45",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 14.3.0-tuxcare.9 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@14.3.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d212ecf0-a0f1-5341-8fa7-5af99f15251d",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 14.3.0-tuxcare.9 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@14.3.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44ae2cc2-29dc-5265-9e44-f9561d6c0a47",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 14.3.0-tuxcare.9 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@14.3.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82ac5c4d-aebb-59ac-815b-a5fc8cb62899",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 14.3.0-tuxcare.9 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@14.3.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:febf6b99-7b93-510f-bb21-665d865b1dc2",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 14.3.0-tuxcare.9 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@14.3.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ce3c6b5-4013-5cc5-8e5e-fddd6e5764de",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 14.3.0-tuxcare.9 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@14.3.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb200320-18fd-58e7-af37-52d24acbf1ee",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 14.3.0-tuxcare.9 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@14.3.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:314a6382-0725-5270-8b0f-04b6adeee56d",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 14.3.0-tuxcare.9 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@14.3.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0c64a92-919e-5919-8386-01efb969829e",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 14.3.0-tuxcare.9 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@14.3.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8eab012c-0e13-501d-b068-51afc7aaa29b",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 14.3.0-tuxcare.9 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@14.3.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a61538d3-5ecf-5873-ab0d-bd966ccccf6c",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 14.3.0-tuxcare.9 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@14.3.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1a76559-4cf0-5222-a20e-e7d5d13b76cc",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 14.3.0-tuxcare.9 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@14.3.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cdd5fa30-f2ae-5c5f-beb7-9eca2b3f0072",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 14.3.0-tuxcare.9 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@14.3.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b4f9bcb-58b9-5adb-968d-c5c8435e788d",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 14.3.0-tuxcare.9 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@14.3.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e584211-9338-57a8-af7b-69c5f8dcaddd",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 14.3.0-tuxcare.9 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@14.3.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41ddc7a9-da36-57b2-ab51-58d72b55160b",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 14.3.0-tuxcare.9 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@14.3.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7190384-4c49-59cc-a4bd-876505cfcadd",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 14.3.0-tuxcare.9 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@14.3.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:478e4300-dbed-59e0-be21-481ad78d90b6",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 14.3.0-tuxcare.9 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@14.3.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:169178cb-3a4a-5e68-b8e8-0137c96760c3",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 14.3.0-tuxcare.9 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@14.3.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6754ec99-e74b-55a8-a650-0d10a741fb46",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 14.3.0-tuxcare.9 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@14.3.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5e6b6e8-ccb3-57af-b998-f9f3d0fe3774",
      "id": "CVE-2026-68945",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 14.3.0-tuxcare.9 of @angular/core. not_affected \u2014 Angular v14.3.0 is not affected by CVE-2026-68945. The vulnerable HttpTransferCache feature does not exist in this version\u2014it was introduced in Angular v16.0.0, two major versions later. Without HttpTransferCache, there is no code path that can generate ambiguous cache keys from repeated HTTP parameters. This finding is consistent with two prior TuxCare analyses (CVE-2026-54266, CVE-2026-50170)..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@14.3.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1825323a-1ecd-59db-b163-49b945177896",
      "id": "CVE-2026-69149",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 14.3.0-tuxcare.9 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@14.3.0-tuxcare.9"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e21e7a9-7f71-55c6-ad7f-f5265037349d",
      "id": "CVE-2026-69151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 14.3.0-tuxcare.9 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@14.3.0-tuxcare.9"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/core@14.3.0-tuxcare.9"
    }
  ]
}