{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:390601f8-d2ad-565c-9803-685981dd8556",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/language-service@13.3.0-tuxcare.4",
      "type": "library",
      "name": "@angular/language-service",
      "version": "13.3.0-tuxcare.4",
      "purl": "pkg:npm/%40angular/language-service@13.3.0-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:d1d7d539-2a30-527a-a16e-78fe626ab7e6",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 13.3.0-tuxcare.4 of @angular/language-service."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@13.3.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05d2b27f-4dce-51c2-a0d8-1c99fbccf93b",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 13.3.0-tuxcare.4 of @angular/language-service."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@13.3.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6dcf537-cc3e-599d-8d1a-c9cfecfcde4c",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 13.3.0-tuxcare.4 of @angular/language-service."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@13.3.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca456163-c1f1-5538-a1cf-1f69d9c3f162",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 13.3.0-tuxcare.4 of @angular/language-service."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@13.3.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:551c4305-78b4-54d5-b4dd-27c84b891ad4",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41423 does not affect version 13.3.0-tuxcare.4 of @angular/language-service. not_affected \u2014 The target repository (Angular 13.3.0-tuxcare.1) is NOT AFFECTED by CVE-2026-41423. While the target lacks the explicit sanitization that the upstream patch adds, it uses a fundamentally different URL parsing mechanism (Node's url.parse() without base URL) that does not extract hostnames from protocol-relative URLs. The architectural difference prevents the SSRF attack vector from succeeding."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@13.3.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d467115f-d1d5-5422-9e71-6d09e8f956e7",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 13.3.0-tuxcare.4 of @angular/language-service."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@13.3.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3af3b725-ab6d-5b18-abe2-f7a557b8545a",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 13.3.0-tuxcare.4 of @angular/language-service."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@13.3.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ad05ea8-93b2-5db8-907a-90b8be91b280",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 13.3.0-tuxcare.4 of @angular/language-service."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@13.3.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12d5819c-407e-500f-9734-55821864d172",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50170 does not affect version 13.3.0-tuxcare.4 of @angular/language-service. not_affected \u2014 Angular v13.3.0 is not affected by CVE-2026-50170. The vulnerable component (HttpTransferCache) does not exist in this version. The HttpTransferCache feature and automatic HTTP response caching during SSR were introduced in Angular v16+, while this target is v13.3.0-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@13.3.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ce68993-3849-5fc5-a2b8-e62c8c7b296e",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 13.3.0-tuxcare.4 of @angular/language-service."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@13.3.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e09ae8fd-06f9-55a5-bb27-1942d9aa19e7",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 13.3.0-tuxcare.4 of @angular/language-service."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@13.3.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a7db4b1-676a-5faf-9599-3a76456f647d",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 13.3.0-tuxcare.4 of @angular/language-service."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@13.3.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e1bf938-30f3-58c8-ba49-21d07147407b",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 13.3.0-tuxcare.4 of @angular/language-service."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@13.3.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eff7ff60-84ed-5bac-bf82-df749c79c379",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 13.3.0-tuxcare.4 of @angular/language-service."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@13.3.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99aa193f-92cc-59f4-b5a5-cd675a7aaca4",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 13.3.0-tuxcare.4 of @angular/language-service."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@13.3.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aee4aaa5-0fb5-570b-b2ed-d221aa62ab23",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54264 does not affect version 13.3.0-tuxcare.4 of @angular/language-service. not_affected \u2014 Angular 13.3.0 is not affected by CVE-2026-54264. The vulnerable method newRequestWithMetadata() does not exist in this version. The AssetGroup class creates new requests with only URLs when fetching assets, never preserving headers. On cross-origin redirects, the code creates a completely new request with no headers, preventing sensitive credential leakage."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@13.3.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:509b60bf-39b1-5482-b700-4b00799da465",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 13.3.0-tuxcare.4 of @angular/language-service. not_affected \u2014 Angular 13.3.0 is not affected by CVE-2026-54265. The vulnerability is specific to Angular's template/pipeline architecture (introduced in v14+) where TwoWayProperty operations bypass sanitizer resolution. Angular 13.3.0 uses an earlier Ivy architecture without the template/pipeline system, where two-way bindings desugar through the same parsePropertyBinding() function as one-way bindings, rece..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@13.3.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76b84854-28bf-5eda-ba17-c105d198c524",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54266 does not affect version 13.3.0-tuxcare.4 of @angular/language-service. not_affected \u2014 Angular 13.3.0 is not affected by CVE-2026-54266. The vulnerable HttpTransferCache feature with weak DJB2 hash-based cache key generation does not exist in this version. HttpTransferCache was introduced in Angular v16+, and version 13.3.0 predates this feature."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@13.3.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ccf6db1-c784-5079-8f94-d99698f6f95c",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 13.3.0-tuxcare.4 of @angular/language-service."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@13.3.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da1c2d65-5364-5018-b0d5-6b2ee8ddc310",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 13.3.0-tuxcare.4 of @angular/language-service."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@13.3.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f44f0e4b-21b1-5e3f-b919-aeb1eb738746",
      "id": "CVE-2026-68945",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 13.3.0-tuxcare.4 of @angular/language-service. not_affected \u2014 Angular v13.3.0 is NOT AFFECTED by CVE-2026-68945. The vulnerable HttpTransferCache feature does not exist in this version\u2014it was introduced in Angular v16.0.0. The cache-key collision vulnerability requires the HttpTransferCache's sortAndConcatParams() function in transfer_cache.ts, which is absent from v13. Verified by filesystem inspection, git history, and existing patch documentation (CVE-..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@13.3.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c86e1387-7b8a-53c3-bbce-34c9de5d9ef3",
      "id": "CVE-2026-69149",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 13.3.0-tuxcare.4 of @angular/language-service."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@13.3.0-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a4fae2b-2bd5-57e0-9ee8-61c5086d8c23",
      "id": "CVE-2026-69151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 13.3.0-tuxcare.4 of @angular/language-service."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@13.3.0-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/language-service@13.3.0-tuxcare.4"
    }
  ]
}