{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:88f66b3c-9fb3-5ef8-b23f-8a413a1908dd",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/upgrade@15.0.3-tuxcare.3",
      "type": "library",
      "name": "@angular/upgrade",
      "version": "15.0.3-tuxcare.3",
      "purl": "pkg:npm/%40angular/upgrade@15.0.3-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:0dda7466-78b3-594d-9184-83e6d3575e98",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 15.0.3-tuxcare.3 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5f26c16-6fc2-535f-b745-da957c94047e",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 15.0.3-tuxcare.3 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3253d0e6-a868-59f0-9ee9-7b585d18b263",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 15.0.3-tuxcare.3 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:312d4a90-ef10-5f78-87e2-9e66b30760af",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 15.0.3-tuxcare.3 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:406187cf-6019-55db-90bd-e79a64b1c4c4",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 15.0.3-tuxcare.3 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:decc2b4f-fa8e-53a1-a8d3-4168705570d5",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 15.0.3-tuxcare.3 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8efe343f-ac61-518b-828e-1c2d3ab5487d",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 15.0.3-tuxcare.3 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e3a34ae-2445-5d2b-9f3f-1897e0a59ee8",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 15.0.3-tuxcare.3 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f26f1d8-2273-512d-9572-e078ffa07b6f",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50170 does not affect version 15.0.3-tuxcare.3 of @angular/upgrade. not_affected \u2014 Angular 15.0.3-tuxcare.1 is NOT affected by CVE-2026-50170. The HTTP TransferCache feature that is vulnerable in later Angular versions (v16+) does not exist in this version. The vulnerable code (transfer_cache.ts, hasAuthHeaders(), shouldCacheRequest(), withHttpTransferCache, provideClientHydration) is absent from Angular 15.0.3."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c11a935f-9c58-5695-aa09-2db36d3ffe6e",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 15.0.3-tuxcare.3 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:badb4099-1080-5bd6-a333-b687ebf30b75",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 15.0.3-tuxcare.3 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e70b8f23-781b-50d5-8c92-8bb62a52012c",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 15.0.3-tuxcare.3 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1cc7bfb8-4dda-5caf-8077-b41f60916dde",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 15.0.3-tuxcare.3 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7352ff6a-bedd-5e58-b4a0-fd7c0f6de794",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 15.0.3-tuxcare.3 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e19e80da-d847-528d-b0a2-5f28ddbe6c3b",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 15.0.3-tuxcare.3 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2f6b570-0cb0-595a-b29b-e9dfe86ca5a4",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 15.0.3-tuxcare.3 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b567f094-53cd-5823-8e83-6f6de0bec602",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 15.0.3-tuxcare.3 of @angular/upgrade. not_affected \u2014 Angular 15.0.3 is NOT AFFECTED by CVE-2026-54265. This version uses a different compiler architecture where two-way bindings desugar through the same code path as one-way bindings, both receiving identical security context resolution and sanitizer assignment. The vulnerable code (Ivy template pipeline with separate TwoWayProperty operation type) does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49ff79b9-182c-5dad-a36d-9c6aca7f93d1",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54266 does not affect version 15.0.3-tuxcare.3 of @angular/upgrade. not_affected \u2014 Angular v15.0.3-tuxcare.1 is NOT affected by CVE-2026-54266. The vulnerable HttpTransferCache feature with weak DJB2 hash-based cache keys does not exist in this version. This feature was introduced in Angular v16+. The target has no code path from HTTP request handling to the vulnerability's cache poisoning goal."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6af86ce-c06b-51b2-94cb-aa642625b365",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 15.0.3-tuxcare.3 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9eb277de-4b87-5507-b485-ce0ccbde62f1",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 15.0.3-tuxcare.3 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1204972a-e86a-5020-b014-ad58d13a9ee6",
      "id": "CVE-2026-68945",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 15.0.3-tuxcare.3 of @angular/upgrade. not_affected \u2014 Angular 15.0.3 is not affected by CVE-2026-68945. The vulnerable HttpTransferCache feature for SSR HTTP request caching does not exist in this version. HttpTransferCache was introduced in Angular v16.0.0 (commit aff1512950, March 31, 2023) and the target version predates this feature entirely. Without HttpTransferCache, there is no cache key generation logic that could exhibit the comma-joining..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2980ae1c-93fa-5fb0-b25d-ce77eff75b50",
      "id": "CVE-2026-69149",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 15.0.3-tuxcare.3 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bb6c372-dedd-5f33-958b-27a92dc8a629",
      "id": "CVE-2026-69151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 15.0.3-tuxcare.3 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@15.0.3-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/upgrade@15.0.3-tuxcare.3"
    }
  ]
}