{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f39873c2-b1f1-566f-b397-078c6979517d",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/bazel",
      "purl": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.22",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.22",
      "version": "5.2.11-tuxcare.22",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:7360cb35-39aa-5920-914d-64976324c01f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 5.2.11-tuxcare.22 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:ea08b4f1-8234-5f11-b053-ff1d923b4d54",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 5.2.11-tuxcare.22 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:c41295f9-df89-55a6-8519-9e0d2868153e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 5.2.11-tuxcare.22 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:d713f269-3816-59f4-a1ff-a61771d90085",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-101895 is fixed in version 5.2.11-tuxcare.22 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:b4293469-720a-52b3-a3cf-d27c75951dd0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 5.2.11-tuxcare.22 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:510998dc-5eed-54e0-9051-5d2fca5b3ff5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 5.2.11-tuxcare.22 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:20e8a995-c36e-59ef-9b98-8a404e6da3ec",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 5.2.11-tuxcare.22 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:463ed11f-bd75-522c-9827-0cfcb1f37ca7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 5.2.11-tuxcare.22 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:053e2217-eb02-5315-a5bf-ccbb39dbdcbe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 5.2.11-tuxcare.22 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:1d00e109-98d9-5cac-bab3-3dea1d2de14a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 5.2.11-tuxcare.22 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:9c9cc9ff-a039-5668-a24e-37e0f329785a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 5.2.11-tuxcare.22 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:9c0db901-2c8c-5727-9ad2-ad74cf12b833",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 5.2.11-tuxcare.22 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:87237ed5-41d8-5bca-9a06-a2eddcc9f583",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 5.2.11-tuxcare.22 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:1f3de024-7608-5e0e-818a-39bdae5bf946",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 5.2.11-tuxcare.22 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:269f9320-c889-507e-aef4-9e809560d22f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 5.2.11-tuxcare.22 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:4f04a241-41e4-5b43-83e9-3323c8446655",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 5.2.11-tuxcare.22 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:04d26715-e5eb-505d-b8f2-e5885d039d1a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 5.2.11-tuxcare.22 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:621cc29b-f367-50e0-8d1c-43244bdb76d0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 5.2.11-tuxcare.22 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:60bee2a9-b800-512e-8b2d-c67ee25867cb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 5.2.11-tuxcare.22 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:85946215-df02-52c9-a2d3-15f86cbf45a2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 5.2.11-tuxcare.22 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:213e873b-6e75-5db8-91e8-8e5b0531e297",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 5.2.11-tuxcare.22 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:4c750b1d-d4f2-5ca8-9736-832e8eb76b16",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 5.2.11-tuxcare.22 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:44bc38e8-eab8-5f1d-9cf5-92ba66b6609f",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 5.2.11-tuxcare.22 of @angular/bazel. not_affected \u2014 Angular 5.2.11 is NOT affected by CVE-2026-68945. The vulnerable component `HttpTransferCache` does not exist in this version. This feature was introduced in Angular v16 as part of the modern SSR hydration system. Angular 5.2.11 only has the basic `TransferState` API (a generic key-value store for manual state transfer), not the automatic HTTP request caching interceptor that contains the vulne...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:d4b7df79-2854-5b64-b5a3-8b0ab7b57dce",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 5.2.11-tuxcare.22 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:11842443-46ea-5707-849c-503ff287ebe3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 5.2.11-tuxcare.22 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:564caf39-0d72-5081-8eec-7c415c35bfd2",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 5.2.11-tuxcare.22 of @angular/bazel. not_affected \u2014 Angular 5.2.11-tuxcare.19 does not contain the vulnerable URL resolution code pattern described in CVE-2026-88056. The vulnerability requires the url.ts file with parseUrl function calling String.prototype.trim() and the relativeUrlsTransformerInterceptorFn HTTP interceptor, both introduced in later Angular versions (post-June 2026). The target version uses a fundamentally different architectur...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:3401fe16-fcb7-5f2d-9cce-30d63244b90b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 5.2.11-tuxcare.22 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:ffa8202f-744e-5480-b50c-6f82efae9225",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88058 does not affect version 5.2.11-tuxcare.22 of @angular/bazel. not_affected \u2014 CVE-2026-88058 affects the domino library's HTML serialization (XSS via ancestor fallback raw-content tag injection in comments/processing instructions during SSR). The target Angular 5.2.11-tuxcare.19 repository declares domino 2.1.2 as a dependency but does NOT vendor its source code. The vulnerable code (NodeUtils.js serializeOne() function) lives in the domino npm package, not in Angular's ...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:955042af-196a-5a99-9e7d-c5a95728f58f",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 5.2.11-tuxcare.22 of @angular/bazel. not_affected \u2014 Angular 5.2.11 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache with hierarchical HttpClient delegation (withRequestsMadeViaParent()), features that were introduced in Angular v16. Angular 5.2.11 predates these features by approximately 6+ years and contains only a basic HTTP interceptor architecture with no automatic response caching mechanism. While TransferStat...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:fbcc9ac9-5d63-5ae8-8b3b-33c1e20e4db0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 5.2.11-tuxcare.22 of @angular/bazel."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/bazel@5.2.11-tuxcare.22"
    }
  ]
}