{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:8e5f5956-5490-50b2-8717-57655d581377",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/bazel@13.3.12-tuxcare.4",
      "type": "library",
      "name": "@angular/bazel",
      "version": "13.3.12-tuxcare.4",
      "purl": "pkg:npm/%40angular/bazel@13.3.12-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:202fc4cc-9457-550e-b496-465841b19139",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 13.3.12-tuxcare.4 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@13.3.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f0045d0-ad17-5e07-80f4-2f17a2ba3d14",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 13.3.12-tuxcare.4 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@13.3.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c845133-a15e-53f4-ac96-a0040c118750",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 13.3.12-tuxcare.4 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@13.3.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a867498b-6d86-5150-a876-7b9d8e59085c",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 13.3.12-tuxcare.4 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@13.3.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d53abbb2-557e-5c8c-9b4d-6524d9076f97",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 13.3.12-tuxcare.4 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@13.3.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:870d3649-eb27-5efe-a3ed-2a9b57dc7693",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 13.3.12-tuxcare.4 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@13.3.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8cafcf32-5546-5b80-8e01-5fc198eebb34",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 13.3.12-tuxcare.4 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@13.3.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:610cc828-1dbc-5645-9f84-f250cf4196a1",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 13.3.12-tuxcare.4 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@13.3.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d8c6fc4-e777-559e-9cbf-8bfb7e41125d",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50170 does not affect version 13.3.12-tuxcare.4 of @angular/bazel. not_affected \u2014 Angular v13.3.12 is NOT AFFECTED by CVE-2026-50170. The HttpTransferCache feature that contains the vulnerability was introduced in Angular v16.0.0 (March 2023) and does not exist in this earlier version."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@13.3.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59a01fc0-3a35-5c11-9274-5fb82ea63973",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 13.3.12-tuxcare.4 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@13.3.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ba553da-4be6-5400-a1a3-24f205828273",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 13.3.12-tuxcare.4 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@13.3.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b2bb03d-69f4-5112-b870-2ca3f7971e00",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 13.3.12-tuxcare.4 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@13.3.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e724f71-650a-5047-ac01-1fa75f13679d",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 13.3.12-tuxcare.4 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@13.3.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d92ff541-9a58-56af-9e82-6a3ddb5cfb9c",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 13.3.12-tuxcare.4 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@13.3.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c8f6195-e42e-5a65-988c-a7d2f9641893",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 13.3.12-tuxcare.4 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@13.3.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27d8e510-6dc7-5e66-8d69-1e2cacd5ef7d",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54264 does not affect version 13.3.12-tuxcare.4 of @angular/bazel. not_affected \u2014 Version 13.3.12 does not have the vulnerable code pattern. The vulnerability exists in versions 20.x+ where the Service Worker's newRequestWithMetadata function preserves request headers but fails to strip sensitive headers on cross-origin redirects. Version 13.3.12 lacks this function entirely and creates fresh requests with URL-only when handling redirects, preventing header leakage."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@13.3.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2288c65a-4ef5-565f-8ae4-4fa26f2c3cf5",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 13.3.12-tuxcare.4 of @angular/bazel. not_affected \u2014 Angular v13.3.12-tuxcare.1 is not affected by CVE-2026-54265. The vulnerability is specific to the Ivy template pipeline architecture (TwoWayProperty operation) introduced in Angular v17+. This version uses an older Ivy architecture where two-way bindings desugar through the same sanitized property binding path as one-way bindings, preventing the sanitization bypass."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@13.3.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01b75d12-fabc-5258-9e50-f9977e1a777e",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54266 does not affect version 13.3.12-tuxcare.4 of @angular/bazel. not_affected \u2014 Angular v13.3.12 is NOT AFFECTED by CVE-2026-54266. The vulnerable HttpTransferCache feature with weak DJB2 hash-based cache key generation was introduced in Angular v16.0.0-next.7 (March 2023), which is 3+ major versions newer than this target version. Exhaustive code analysis confirms the transfer_cache.ts module, HttpTransferCache class, generateHash function, and all related cache key gener..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@13.3.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a14d442-a294-56e0-87cd-1668edcbf275",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 13.3.12-tuxcare.4 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@13.3.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:598f7bf1-3408-52ab-b17b-88e0d86eb7e6",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 13.3.12-tuxcare.4 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@13.3.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05792ea4-f5f5-55c2-bb65-5437be7b4d3b",
      "id": "CVE-2026-68945",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 13.3.12-tuxcare.4 of @angular/bazel. not_affected \u2014 CVE-2026-68945 describes a cache-key collision vulnerability in Angular's HttpTransferCache feature that allows distinct HTTP requests with repeated query parameters to share cached responses during SSR. The target version (13.3.12-tuxcare.3) does not contain the HttpTransferCache feature, which was introduced in Angular 16.0.0-next.7 (commit aff1512950). Since the vulnerable component does not..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@13.3.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84f83cdf-6d4d-5755-b04d-4d93d4c277db",
      "id": "CVE-2026-69149",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 13.3.12-tuxcare.4 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@13.3.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37cdfe2d-9952-5b60-b940-964af9df4d11",
      "id": "CVE-2026-69151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 13.3.12-tuxcare.4 of @angular/bazel."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@13.3.12-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/bazel@13.3.12-tuxcare.4"
    }
  ]
}