{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e63f6686-1c4d-533f-b74a-3e0a2a755a3c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/core@9.1.13-tuxcare.12",
      "type": "library",
      "name": "@angular/core",
      "version": "9.1.13-tuxcare.12",
      "purl": "pkg:npm/%40angular/core@9.1.13-tuxcare.12"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:e918410f-dd59-5b46-9c42-26b2a7da5df6",
      "id": "CVE-2021-4231",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 9.1.13-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b91f92f-310e-5c57-99ba-fd8718b14fd3",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 9.1.13-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5dadd0b-7fbb-52ad-9e3c-c3e9aba0bf85",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 9.1.13-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b9cdf58-585a-534d-957c-d0e05d6b2271",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 9.1.13-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8ab852c-0939-542d-b7bf-5c10a850eebd",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 9.1.13-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e359602b-bdd4-5a07-ace2-c71fecddad69",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 9.1.13-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e4ba48e-b57f-5293-acc1-65070ff0f772",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 9.1.13-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:095b341b-0a93-513b-b2da-edf6da92b512",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 9.1.13-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:425f7c19-8bc3-5412-9360-ab55c4bd63b5",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 9.1.13-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73f0d8cb-b2f6-5cb3-a78d-437b1f05030d",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50170 does not affect version 9.1.13-tuxcare.12 of @angular/core. not_affected \u2014 Angular v9.1.13 is not affected by CVE-2026-50170. The vulnerability exists in Angular's HttpTransferCache feature, which was introduced in Angular v16+. This feature does not exist in v9.1.13, making the vulnerability pattern impossible to manifest."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1639967c-277d-5f4b-a7a8-1389872510c7",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 9.1.13-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8825d6e9-29be-5605-851b-7d696f170f87",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 9.1.13-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14d4ffda-952a-5579-b390-5e3da36e6e6c",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 9.1.13-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd5a8f1d-c198-586e-9413-e49823bd5c90",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 9.1.13-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc965ced-831d-568a-9a21-8285bee90cc0",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 9.1.13-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c96179ec-aba3-5877-a6cb-762845549068",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 9.1.13-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:924e006b-3af5-542c-a416-603a422393ec",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54264 does not affect version 9.1.13-tuxcare.12 of @angular/core. not_affected \u2014 Angular 9.1.13 is not affected by CVE-2026-54264. The target repository uses a fundamentally different request reconstruction architecture than the vulnerable upstream versions (22.0+). The vulnerability requires the presence of header-copying logic during request reconstruction, which does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81ea820f-287f-5f91-bd93-6b7c993a34ab",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 9.1.13-tuxcare.12 of @angular/core. not_affected \u2014 Angular 9.1.13-tuxcare.9 is NOT AFFECTED by CVE-2026-54265. The vulnerability exists in newer Ivy compiler's template/pipeline architecture where TwoWayProperty operations bypass sanitizer resolution. This version uses View Engine and early render3 (Ivy) implementations where two-way bindings desugar through the same parsePropertyBinding() path as one-way bindings, ensuring identical sanitizer ..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b64bc844-b1d4-513b-a7b8-d59d92b3e1b6",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54266 does not affect version 9.1.13-tuxcare.12 of @angular/core. not_affected \u2014 Angular 9.1.13-tuxcare.9 does not contain the HttpTransferCache feature. The vulnerability CVE-2026-54266 affects the hash generation in HttpTransferCache, a feature introduced in Angular v16+. The target version (9.1.13) predates this feature by many major versions. While TransferState (generic state serialization) exists in v9, there is no HTTP caching integration that uses it. The packages/c..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b5d80c0-36e6-5aaf-96fe-cbf1fa120b92",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 9.1.13-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0edec205-a1c6-5f65-9c49-714e58461449",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 9.1.13-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2450f20b-0108-5e19-a79f-6a6cc0e8bb0a",
      "id": "CVE-2026-68945",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 9.1.13-tuxcare.12 of @angular/core. not_affected \u2014 Angular v9.1.13 is not affected by CVE-2026-68945. The vulnerable HttpTransferCache feature was introduced in Angular v16.0.0 (March 2023), approximately 7 major versions after v9.1.13. The target version does not contain the HttpTransferCache code, the transfer_cache.ts file, or any automatic HTTP request caching mechanism that could exhibit the cache-key ambiguity vulnerability. While v9 does..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5281fc59-5177-5582-a8b0-5968f9500b87",
      "id": "CVE-2026-69149",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 9.1.13-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@9.1.13-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85bd17b2-8b8a-50b0-ab47-9857f26356cf",
      "id": "CVE-2026-69151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 9.1.13-tuxcare.12 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@9.1.13-tuxcare.12"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/core@9.1.13-tuxcare.12"
    }
  ]
}