{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:51f6122e-2fb2-5339-99b3-8e1e92f2e226",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/core",
      "purl": "pkg:npm/%40angular/core@5.2.11-tuxcare.21",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.21",
      "version": "5.2.11-tuxcare.21",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:cb2ecc4d-0990-5e7b-88ad-9e0941d9ca7b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 5.2.11-tuxcare.21 of @angular/core."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:2c8ca97c-1799-5453-9fae-d119a229a79e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 5.2.11-tuxcare.21 of @angular/core."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:381aae5e-1ff0-54c3-a809-fefa4dd3b8d8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 5.2.11-tuxcare.21 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:2146a20b-833b-5e4e-8ce9-fc947264080a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101895 affects version 5.2.11-tuxcare.21 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:9e4d886c-2438-5291-b9d7-b220138fb4fa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 5.2.11-tuxcare.21 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:ee193fbd-e0e5-5a13-973d-ce949e13a296",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 5.2.11-tuxcare.21 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:56be8982-d989-58be-943d-39032c8eae3f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 5.2.11-tuxcare.21 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:62886ed7-c9fb-5f56-9138-c6ea950e4e68",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 5.2.11-tuxcare.21 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:debf2f76-2f27-5a46-a64a-5740af86f16f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 5.2.11-tuxcare.21 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:660d1841-76b5-538c-899f-124ec131fa3e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 5.2.11-tuxcare.21 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:5b34abfe-8412-5250-b5ee-9114c2c587f3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 5.2.11-tuxcare.21 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:916a7c1b-a7d7-5259-8144-61c15e9663ab",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 5.2.11-tuxcare.21 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:a3a7b162-fb56-5f4d-9f60-d681e9c4b92b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 5.2.11-tuxcare.21 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:619c9a1a-4970-52a0-aca1-a0330f6ac609",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 5.2.11-tuxcare.21 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:a70fd86d-e9ae-5d51-b831-b26e89140bf6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 5.2.11-tuxcare.21 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:6eb0bc98-ab59-571e-a71e-5aedcb0eea9d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 5.2.11-tuxcare.21 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:03180ec6-a442-5c79-ba87-637fe100bf35",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 5.2.11-tuxcare.21 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:e5e6d7bc-37cf-55e4-8957-1f888b6211fa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 5.2.11-tuxcare.21 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:bb413c5f-f50f-503a-bb78-79d2f2eca763",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 5.2.11-tuxcare.21 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:d17f6707-db61-5b55-a692-a1bc579a96a5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 5.2.11-tuxcare.21 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:27f43506-73e8-54f3-95ac-718a8707e826",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 5.2.11-tuxcare.21 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:4586ff4f-50a6-5e5d-a108-1212bb27c451",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 5.2.11-tuxcare.21 of @angular/core. not_affected \u2014 Angular 5.2.11 is NOT affected by CVE-2026-68945. The vulnerable component `HttpTransferCache` does not exist in this version. This feature was introduced in Angular v16 as part of the modern SSR hydration system. Angular 5.2.11 only has the basic `TransferState` API (a generic key-value store for manual state transfer), not the automatic HTTP request caching interceptor that contains the vulne...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:83f61cc2-79f4-5d4e-a64f-9dd534d9f9a0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 5.2.11-tuxcare.21 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:1f4b4f44-7c49-5ee7-91df-10eb42e786ad",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 5.2.11-tuxcare.21 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:f6e05982-875d-549a-b4bd-315001b5bc24",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 5.2.11-tuxcare.21 of @angular/core. not_affected \u2014 Angular 5.2.11-tuxcare.19 does not contain the vulnerable URL resolution code pattern described in CVE-2026-88056. The vulnerability requires the url.ts file with parseUrl function calling String.prototype.trim() and the relativeUrlsTransformerInterceptorFn HTTP interceptor, both introduced in later Angular versions (post-June 2026). The target version uses a fundamentally different architectur...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:0f38b757-0147-57ea-a4b9-c45dd5239bf1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 5.2.11-tuxcare.21 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:6e5d2f35-2511-53bc-9456-2c5ff7975c47",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88058 does not affect version 5.2.11-tuxcare.21 of @angular/core. not_affected \u2014 CVE-2026-88058 affects the domino library's HTML serialization (XSS via ancestor fallback raw-content tag injection in comments/processing instructions during SSR). The target Angular 5.2.11-tuxcare.19 repository declares domino 2.1.2 as a dependency but does NOT vendor its source code. The vulnerable code (NodeUtils.js serializeOne() function) lives in the domino npm package, not in Angular's ...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:242a56d7-a516-5f59-ac34-c6b983300fcf",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 5.2.11-tuxcare.21 of @angular/core. not_affected \u2014 Angular 5.2.11 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache with hierarchical HttpClient delegation (withRequestsMadeViaParent()), features that were introduced in Angular v16. Angular 5.2.11 predates these features by approximately 6+ years and contains only a basic HTTP interceptor architecture with no automatic response caching mechanism. While TransferStat...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:77908091-7c5d-50ab-af1f-fafa9abd4863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 5.2.11-tuxcare.21 of @angular/core."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/core@5.2.11-tuxcare.21"
    }
  ]
}