{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:6f048a17-719b-5ea4-99dc-39604ce5e4db",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/compiler@7.2.11-tuxcare.4",
      "type": "library",
      "name": "@angular/compiler",
      "version": "7.2.11-tuxcare.4",
      "purl": "pkg:npm/%40angular/compiler@7.2.11-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:4dae7e4a-38d6-52a9-ba1c-cc65c024d72a",
      "id": "CVE-2021-4231",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 7.2.11-tuxcare.4 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6d03950-afd3-50ba-b174-7481d245bf25",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 7.2.11-tuxcare.4 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c3fbdda-c942-527f-aa9e-296f7b34cba1",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 7.2.11-tuxcare.4 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c39881e7-ee3f-5e91-a541-235da2973b88",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 7.2.11-tuxcare.4 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9934257f-dd17-5883-98e3-f80071fbaf3b",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 7.2.11-tuxcare.4 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ede4f4dc-fb53-5366-8c82-ebaeb32cdca7",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 7.2.11-tuxcare.4 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6867095-5810-594c-8e63-fdac146f200a",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 7.2.11-tuxcare.4 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8e8f622-8650-54f5-becf-1a1cc410d34a",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50168 does not affect version 7.2.11-tuxcare.4 of @angular/compiler. not_affected \u2014 CVE-2026-50168 addresses vulnerabilities in the WHATWG URL-based parseUrl implementation and allowedHosts validation feature introduced in Angular's CVE-2026-41423 fix. The target (v7.2.11) uses a completely different architecture with Node.js legacy url.parse() and does not have the allowedHosts feature. The specific vulnerable code patterns that CVE-2026-50168 patches do not exist in this ver..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2ef6ca7-bb35-5755-9d86-96b440162dbf",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 7.2.11-tuxcare.4 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71b0dc07-db94-5e6e-a2ef-e45fdd718409",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50170 does not affect version 7.2.11-tuxcare.4 of @angular/compiler. not_affected \u2014 Angular v7.2.11 is not affected by CVE-2026-50170. The HTTP Transfer Cache feature that is vulnerable does not exist in this version. The feature was introduced in Angular v16+, and v7.2.11 lacks the transfer_cache.ts module, withHttpTransferCache provider, and provideClientHydration functionality entirely."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:320501c0-123a-5b1f-b802-569cb3a37ffb",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 7.2.11-tuxcare.4 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55f38114-55db-5650-96a5-7de0120ee892",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 7.2.11-tuxcare.4 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:219ebc5a-4787-51d2-ad00-a183c36c19f4",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 7.2.11-tuxcare.4 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae15b369-64ec-5a8c-9fee-9ddeacfb98ec",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 7.2.11-tuxcare.4 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7073d32-ee2b-5a13-bdea-69fa288e4572",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 7.2.11-tuxcare.4 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57532b4b-653e-5817-a764-7331f53a49d5",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 7.2.11-tuxcare.4 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3c3a4c7-5518-5957-88e0-be07a970c4e5",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54264 does not affect version 7.2.11-tuxcare.4 of @angular/compiler. not_affected \u2014 Angular 7.2.11-tuxcare.2 is not affected by CVE-2026-54264. The vulnerability concerns sensitive header leakage on cross-origin redirects in the request metadata preservation feature. This version predates that feature entirely - it strips ALL request headers when making network requests for assets, as evidenced by code comments and the absence of the newRequestWithMetadata method introduced in..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07c0b5da-91ad-5726-b539-39e328b740dd",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 7.2.11-tuxcare.4 of @angular/compiler. not_affected \u2014 Angular 7.2.11-tuxcare.2 uses View Engine compiler architecture, not Ivy. The vulnerability (CVE-2026-54265) is specific to Ivy's template compiler pipeline where TwoWayProperty operations were missing from the sanitizer resolution switch. View Engine does not have TwoWayProperty operations; two-way bindings desugar early in the template parser to the same parsePropertyBinding() code path as on..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:918756bc-1c96-5d9a-9eb8-654e2d3bc82d",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54266 does not affect version 7.2.11-tuxcare.4 of @angular/compiler. not_affected \u2014 Angular 7.2.11-tuxcare.2 is not affected by CVE-2026-54266. The HttpTransferCache feature that contains the weak hash vulnerability does not exist in this version - it was introduced in Angular 16."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28df375d-c8a1-5d13-8e90-1bebfb977f5a",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 7.2.11-tuxcare.4 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b32f9b36-3037-574b-b18d-023205535c2f",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 7.2.11-tuxcare.4 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:295b6aeb-3de3-51d5-9efa-5ff7a112d03c",
      "id": "CVE-2026-68945",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 7.2.11-tuxcare.4 of @angular/compiler. not_affected \u2014 Angular v7.2.11-tuxcare.3 is NOT AFFECTED by CVE-2026-68945. The vulnerability affects Angular's `HttpTransferCache` feature, which caches HTTP requests during Server-Side Rendering (SSR) for client-side hydration. This feature did not exist in v7.2.11 \u2014 it was introduced in Angular v16. The vulnerable file `packages/common/http/src/transfer_cache.ts` is absent from the target SHA (8c4c3a453736..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:729de9c7-c989-5ca1-980e-8342cec13dfc",
      "id": "CVE-2026-69149",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 7.2.11-tuxcare.4 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:802f2ed5-16c2-5a56-97b2-630460ef7d7a",
      "id": "CVE-2026-69151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 7.2.11-tuxcare.4 of @angular/compiler."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@7.2.11-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/compiler@7.2.11-tuxcare.4"
    }
  ]
}