{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ae6bf45e-e171-51c6-9224-d2609cffc202",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/compiler",
      "purl": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.22",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.22",
      "version": "5.2.11-tuxcare.22",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:f93fb205-3215-54cd-b67e-30465fa8cd8b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 5.2.11-tuxcare.22 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:80d480ac-e04b-5c28-817e-a26db508fb4e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 5.2.11-tuxcare.22 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:c9ebdf2d-e2f5-58b9-bb58-d73c279d6ee1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 5.2.11-tuxcare.22 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:7d9ecdb7-2dad-557b-9caa-8a633f7c275c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-101895 is fixed in version 5.2.11-tuxcare.22 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:1b08dde2-71b0-586c-b591-9d605173ef97",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 5.2.11-tuxcare.22 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:4431706b-905c-5f14-85e2-269d26e72def",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 5.2.11-tuxcare.22 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:92256077-4cd6-5f48-bc79-89204d467cad",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 5.2.11-tuxcare.22 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:d5b73e14-68d9-517b-8fea-d6c054cac831",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 5.2.11-tuxcare.22 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:bf3a77c5-fbb8-58ba-afdb-40956d214430",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 5.2.11-tuxcare.22 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:4dac21a7-00f4-5490-a3d4-76fb692283c2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 5.2.11-tuxcare.22 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:93364ed4-eede-5dcc-9654-909b1ac0e28a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 5.2.11-tuxcare.22 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:21819b0b-039b-5357-bea1-4007ec7c45b6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 5.2.11-tuxcare.22 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:3e316c09-3b68-5937-a20a-56064f15d400",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 5.2.11-tuxcare.22 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:ae48362f-4f2a-54f5-b549-af2609e6d800",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 5.2.11-tuxcare.22 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:f7ae7687-1f54-5d72-abbd-16a74c608b11",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 5.2.11-tuxcare.22 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:f2c8d36d-2dc5-5184-989c-adcb527f495a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 5.2.11-tuxcare.22 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:685e4b39-1564-54a7-ad22-0e6c789fd363",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 5.2.11-tuxcare.22 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:e3809257-e0bf-57b5-a5d0-85faa9c3ea18",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 5.2.11-tuxcare.22 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:fc06eae4-bc9a-5fba-a33a-baced8f74c33",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 5.2.11-tuxcare.22 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:5581a28e-ffb1-5bcc-9b62-67497eda60ec",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 5.2.11-tuxcare.22 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:fe520a78-8a67-5ed4-a7f6-deae29477821",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 5.2.11-tuxcare.22 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:be4275be-ee41-5542-b570-1e7058e7e899",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 5.2.11-tuxcare.22 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:5aa05451-6153-56d1-beb7-57092c2c4f01",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 5.2.11-tuxcare.22 of @angular/compiler. not_affected \u2014 Angular 5.2.11 is NOT affected by CVE-2026-68945. The vulnerable component `HttpTransferCache` does not exist in this version. This feature was introduced in Angular v16 as part of the modern SSR hydration system. Angular 5.2.11 only has the basic `TransferState` API (a generic key-value store for manual state transfer), not the automatic HTTP request caching interceptor that contains the vulne...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:1326f7d1-b843-55ad-9a1c-10dd07eb09a6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 5.2.11-tuxcare.22 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:22f7547e-e5d0-57af-9213-963805f23a3a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 5.2.11-tuxcare.22 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:167f1b3a-95aa-51f9-b59e-349a662f244f",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 5.2.11-tuxcare.22 of @angular/compiler. not_affected \u2014 Angular 5.2.11-tuxcare.19 does not contain the vulnerable URL resolution code pattern described in CVE-2026-88056. The vulnerability requires the url.ts file with parseUrl function calling String.prototype.trim() and the relativeUrlsTransformerInterceptorFn HTTP interceptor, both introduced in later Angular versions (post-June 2026). The target version uses a fundamentally different architectur...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:ca167a2c-8893-5f40-a858-6b713c047a58",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 5.2.11-tuxcare.22 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:281175ee-202c-5b4e-84fd-26b3398324f0",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88058 does not affect version 5.2.11-tuxcare.22 of @angular/compiler. not_affected \u2014 CVE-2026-88058 affects the domino library's HTML serialization (XSS via ancestor fallback raw-content tag injection in comments/processing instructions during SSR). The target Angular 5.2.11-tuxcare.19 repository declares domino 2.1.2 as a dependency but does NOT vendor its source code. The vulnerable code (NodeUtils.js serializeOne() function) lives in the domino npm package, not in Angular's ...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:83ae7c86-ea82-542f-96bd-d6d5c3a24081",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 5.2.11-tuxcare.22 of @angular/compiler. not_affected \u2014 Angular 5.2.11 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache with hierarchical HttpClient delegation (withRequestsMadeViaParent()), features that were introduced in Angular v16. Angular 5.2.11 predates these features by approximately 6+ years and contains only a basic HTTP interceptor architecture with no automatic response caching mechanism. While TransferStat...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.22"
        }
      ],
      "bom-ref": "urn:uuid:81e5501c-8f14-54a9-8da2-44539e7c90cd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 5.2.11-tuxcare.22 of @angular/compiler."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/compiler@5.2.11-tuxcare.22"
    }
  ]
}