{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:99a46ec5-44d4-5579-92d9-fac34a90c738",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/http",
      "purl": "pkg:npm/%40angular/http@5.2.11-tuxcare.20",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.20",
      "version": "5.2.11-tuxcare.20",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:3c1d6fa3-9033-5408-9ab0-daf5f8106230",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 5.2.11-tuxcare.20 of @angular/http."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:87d93b21-3a5f-52b1-aa98-eda58c8969e7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 5.2.11-tuxcare.20 of @angular/http."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:76f9f542-158a-5d5b-a681-523905a112a8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 5.2.11-tuxcare.20 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:fe09f519-06ab-5be2-965f-d055250ff55c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101895 affects version 5.2.11-tuxcare.20 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:d70bb6f4-4abc-5a01-9c53-a3eda37ed4eb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 5.2.11-tuxcare.20 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:c677f313-7f8a-5925-a386-f34aaa99d9f1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 5.2.11-tuxcare.20 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:30b6d83e-8abc-5ce3-b0d9-f3d8396923c4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 5.2.11-tuxcare.20 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:eb4368ad-a0dc-578b-ad4d-0e3e1edefea0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 5.2.11-tuxcare.20 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:8e3fcc2b-773b-5449-9443-16369fc42e5e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 5.2.11-tuxcare.20 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:83ac59e2-1519-579b-bbb3-0597b535dbcf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 5.2.11-tuxcare.20 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:fd955c2d-d38b-570e-9ab7-15d4aa1662a1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 5.2.11-tuxcare.20 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:6303a3ab-113c-5253-b742-e0bf308b1085",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 5.2.11-tuxcare.20 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:21dbf989-43db-52b1-aee0-892c2c02a40b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 5.2.11-tuxcare.20 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:a51e5088-816d-539f-9a7d-41b241b97e53",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 5.2.11-tuxcare.20 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:093cfb2d-07a4-541f-995e-7cf312f6b286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 5.2.11-tuxcare.20 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:ecd22c27-1c3b-5a4d-9710-419b92d7d7cd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 5.2.11-tuxcare.20 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:ed6fa885-7aac-5eb5-85b9-f569f31d9d8a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 5.2.11-tuxcare.20 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:74d05925-8991-547f-9c60-2c85e81a2871",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 5.2.11-tuxcare.20 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:becddedb-c000-5527-94da-084b6d0598ac",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 5.2.11-tuxcare.20 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:57c59a98-f4d0-501d-948f-b95df1a642e4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 5.2.11-tuxcare.20 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:638d25c7-58a4-55db-ab80-1d9ea301d335",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 5.2.11-tuxcare.20 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:63986274-12f4-5ba3-9528-d37ec0ef51fa",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 5.2.11-tuxcare.20 of @angular/http. not_affected \u2014 Angular 5.2.11 is NOT affected by CVE-2026-68945. The vulnerable component `HttpTransferCache` does not exist in this version. This feature was introduced in Angular v16 as part of the modern SSR hydration system. Angular 5.2.11 only has the basic `TransferState` API (a generic key-value store for manual state transfer), not the automatic HTTP request caching interceptor that contains the vulne...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:f5496d5b-be54-5799-bbfa-eb51b9da78c4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 5.2.11-tuxcare.20 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:728755b8-7d7b-52aa-b8bb-8eedd9c83bb7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 5.2.11-tuxcare.20 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:b8beb358-9979-5542-b6b4-9a28f3cb4d21",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 5.2.11-tuxcare.20 of @angular/http. not_affected \u2014 Angular 5.2.11-tuxcare.19 does not contain the vulnerable URL resolution code pattern described in CVE-2026-88056. The vulnerability requires the url.ts file with parseUrl function calling String.prototype.trim() and the relativeUrlsTransformerInterceptorFn HTTP interceptor, both introduced in later Angular versions (post-June 2026). The target version uses a fundamentally different architectur...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:447bcc77-b2cd-581a-b573-7aa312060ce9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 5.2.11-tuxcare.20 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:c6494531-2005-51f1-b709-532018274cb0",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88058 does not affect version 5.2.11-tuxcare.20 of @angular/http. not_affected \u2014 CVE-2026-88058 affects the domino library's HTML serialization (XSS via ancestor fallback raw-content tag injection in comments/processing instructions during SSR). The target Angular 5.2.11-tuxcare.19 repository declares domino 2.1.2 as a dependency but does NOT vendor its source code. The vulnerable code (NodeUtils.js serializeOne() function) lives in the domino npm package, not in Angular's ...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:40ee8f37-4f58-5bf8-9444-2a8d17d11df3",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 5.2.11-tuxcare.20 of @angular/http. not_affected \u2014 Angular 5.2.11 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache with hierarchical HttpClient delegation (withRequestsMadeViaParent()), features that were introduced in Angular v16. Angular 5.2.11 predates these features by approximately 6+ years and contains only a basic HTTP interceptor architecture with no automatic response caching mechanism. While TransferStat...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.20"
        }
      ],
      "bom-ref": "urn:uuid:00fe7cc2-852f-5b71-918b-4b0455ab94e2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 5.2.11-tuxcare.20 of @angular/http."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.20"
    }
  ]
}