{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:30d0f09b-51d5-5634-b7f8-64b14ab34cb6",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/http",
      "purl": "pkg:npm/%40angular/http@5.2.11-tuxcare.21",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.21",
      "version": "5.2.11-tuxcare.21",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:222e804a-8d1f-501f-a893-da1268a82340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 5.2.11-tuxcare.21 of @angular/http."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:5a776541-ece1-57b0-90b4-738c0d4b603c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 5.2.11-tuxcare.21 of @angular/http."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:941d4ec4-318e-51ea-91a9-43fb55380fb6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 5.2.11-tuxcare.21 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:b53c3e31-eedd-5323-8514-940dc76ea0c9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101895 affects version 5.2.11-tuxcare.21 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:58ac67d5-7b3f-5937-81c6-bb07615e3bb1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 5.2.11-tuxcare.21 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:7ec97b0a-92b4-5c00-b102-ddd823e5dc7b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 5.2.11-tuxcare.21 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:0df230fe-770a-52e2-8f71-20ba42c4a17a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 5.2.11-tuxcare.21 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:bafadaec-a911-5cdd-bcf7-463fc99fc5ef",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 5.2.11-tuxcare.21 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:164afb35-3eba-5e11-b03a-50429256669d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 5.2.11-tuxcare.21 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:f0514735-6f9e-5b58-bba2-d26ba6953645",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 5.2.11-tuxcare.21 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:07df58a9-cd5a-531d-a579-831495dc37f5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 5.2.11-tuxcare.21 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:8fa602d1-1ff4-51b2-9812-c0a45813c80d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 5.2.11-tuxcare.21 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:e69e5a76-d13c-5f3a-a846-21370b9c99b5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 5.2.11-tuxcare.21 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:9d0ed671-f8a9-58ae-85a5-731d87c1a091",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 5.2.11-tuxcare.21 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:250860b0-3362-572b-abb6-58ff58657024",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 5.2.11-tuxcare.21 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:fa276b7c-7c31-5e9d-bdbf-9d2db3076540",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 5.2.11-tuxcare.21 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:7cb9052b-9169-54c2-bfb6-0a90c373bed5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 5.2.11-tuxcare.21 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:484ac285-d41b-5c3a-b092-4c9c4fa3d606",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 5.2.11-tuxcare.21 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:200ec6d1-7068-5db0-84b6-79785081177c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 5.2.11-tuxcare.21 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:7936d5bc-58b5-53af-a7a0-6ac54c3f7d5e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 5.2.11-tuxcare.21 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:713408b4-cef4-5d24-b23c-de1753ee5c65",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 5.2.11-tuxcare.21 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:f70dfa73-e3a1-5abd-9128-295dbfd1d0d3",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 5.2.11-tuxcare.21 of @angular/http. not_affected \u2014 Angular 5.2.11 is NOT affected by CVE-2026-68945. The vulnerable component `HttpTransferCache` does not exist in this version. This feature was introduced in Angular v16 as part of the modern SSR hydration system. Angular 5.2.11 only has the basic `TransferState` API (a generic key-value store for manual state transfer), not the automatic HTTP request caching interceptor that contains the vulne...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:5df8d728-2028-5c0c-86db-a4d642ab420a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 5.2.11-tuxcare.21 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:6e3b5359-083e-5ba8-a5fd-69c4cfdc201a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 5.2.11-tuxcare.21 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:7feb3b2c-8565-512c-a90b-27800a58fb0b",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 5.2.11-tuxcare.21 of @angular/http. not_affected \u2014 Angular 5.2.11-tuxcare.19 does not contain the vulnerable URL resolution code pattern described in CVE-2026-88056. The vulnerability requires the url.ts file with parseUrl function calling String.prototype.trim() and the relativeUrlsTransformerInterceptorFn HTTP interceptor, both introduced in later Angular versions (post-June 2026). The target version uses a fundamentally different architectur...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:def225d6-b4c3-512a-82f8-0b8b98a53399",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 5.2.11-tuxcare.21 of @angular/http."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:fef88d18-b46b-5f28-96ca-c25e2e5cfac7",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88058 does not affect version 5.2.11-tuxcare.21 of @angular/http. not_affected \u2014 CVE-2026-88058 affects the domino library's HTML serialization (XSS via ancestor fallback raw-content tag injection in comments/processing instructions during SSR). The target Angular 5.2.11-tuxcare.19 repository declares domino 2.1.2 as a dependency but does NOT vendor its source code. The vulnerable code (NodeUtils.js serializeOne() function) lives in the domino npm package, not in Angular's ...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:fc5ed0e5-8fe8-5a74-85f2-fbd7a14cc10f",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 5.2.11-tuxcare.21 of @angular/http. not_affected \u2014 Angular 5.2.11 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache with hierarchical HttpClient delegation (withRequestsMadeViaParent()), features that were introduced in Angular v16. Angular 5.2.11 predates these features by approximately 6+ years and contains only a basic HTTP interceptor architecture with no automatic response caching mechanism. While TransferStat...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:b004cd68-0c7e-53d7-bce6-8ae486fd0196",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 5.2.11-tuxcare.21 of @angular/http."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/http@5.2.11-tuxcare.21"
    }
  ]
}