{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:340d13c5-cfdc-5968-9624-9fe5ccd18028",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/language-service",
      "purl": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.21",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.21",
      "version": "5.2.11-tuxcare.21",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:0106854a-567a-5ced-8110-51d4b8c8c74d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 5.2.11-tuxcare.21 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:a4aec604-1121-5ec8-9a0a-4d7bb3c724c3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 5.2.11-tuxcare.21 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:fb7cf385-0682-5439-b9b2-573c8b0bc18e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 5.2.11-tuxcare.21 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:529e164a-5d29-5dd8-8b5b-7cf56dc3bcb5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101895 affects version 5.2.11-tuxcare.21 of @angular/language-service, and is fixed in 5.2.11-tuxcare.22."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:f9cab785-dee0-50a1-acfd-6fa6e5e05417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 5.2.11-tuxcare.21 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:0b6a5efb-e10f-551d-98ff-78230c26d8cf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 5.2.11-tuxcare.21 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:3cd4928d-5913-5dd5-8d5f-10a129a1a996",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 5.2.11-tuxcare.21 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:0c81ba58-239a-5fcb-b493-a4ad7cfa6f20",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 5.2.11-tuxcare.21 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:7e3417d9-3dd0-5614-8266-065bb37c23ca",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 5.2.11-tuxcare.21 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:e8612c57-6209-54a3-abc9-201f1ef95db4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 5.2.11-tuxcare.21 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:f1751c49-b251-5187-a80c-99d9f7e7dadf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 5.2.11-tuxcare.21 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:b6739625-e703-5aab-9f12-9958fb7b85f5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 5.2.11-tuxcare.21 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:a83e9188-eeda-5853-8575-0b718f85b88d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 5.2.11-tuxcare.21 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:002cef1b-6d07-51be-805d-a62b9d3382f4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 5.2.11-tuxcare.21 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:747d9ab9-938a-5a1d-8df5-97d7b697a469",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 5.2.11-tuxcare.21 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:0e2ebf47-5e0b-5e64-9d42-a8d16ba95a7e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 5.2.11-tuxcare.21 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:9eb36b3e-f44e-55a6-a2e6-c263d85e88d8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 5.2.11-tuxcare.21 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:21043d0f-b396-5030-945b-01fd36af20e0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 5.2.11-tuxcare.21 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:2519ef87-9741-51eb-bd2d-258b2ced6672",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 5.2.11-tuxcare.21 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:76659221-37b9-5083-a3f1-71138bad7947",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 5.2.11-tuxcare.21 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:bfa3f625-b25b-5b83-84dc-298a7eb4b392",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 5.2.11-tuxcare.21 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:9448f926-6728-59a4-bcf5-61815f654c6f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 5.2.11-tuxcare.21 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:1efba27a-373e-5e26-8823-6b2cce336c7a",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 5.2.11-tuxcare.21 of @angular/language-service. not_affected \u2014 Angular 5.2.11 is NOT affected by CVE-2026-68945. The vulnerable component `HttpTransferCache` does not exist in this version. This feature was introduced in Angular v16 as part of the modern SSR hydration system. Angular 5.2.11 only has the basic `TransferState` API (a generic key-value store for manual state transfer), not the automatic HTTP request caching interceptor that contains the vulne...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:67e80034-3fc4-56b9-b481-5385d89ff7a0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 5.2.11-tuxcare.21 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:7e1e30ec-776c-55c0-a4b6-99f7ed02b594",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 5.2.11-tuxcare.21 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:aa94f984-ed75-543d-a474-b4509b8e4e02",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 5.2.11-tuxcare.21 of @angular/language-service. not_affected \u2014 Angular 5.2.11-tuxcare.19 does not contain the vulnerable URL resolution code pattern described in CVE-2026-88056. The vulnerability requires the url.ts file with parseUrl function calling String.prototype.trim() and the relativeUrlsTransformerInterceptorFn HTTP interceptor, both introduced in later Angular versions (post-June 2026). The target version uses a fundamentally different architectur...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:2e2ef37d-115d-5abc-8b6a-3fe8112cc830",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 5.2.11-tuxcare.21 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:178ad5af-7894-557a-a323-5974252de897",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88058 does not affect version 5.2.11-tuxcare.21 of @angular/language-service. not_affected \u2014 CVE-2026-88058 affects the domino library's HTML serialization (XSS via ancestor fallback raw-content tag injection in comments/processing instructions during SSR). The target Angular 5.2.11-tuxcare.19 repository declares domino 2.1.2 as a dependency but does NOT vendor its source code. The vulnerable code (NodeUtils.js serializeOne() function) lives in the domino npm package, not in Angular's ...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:67ab6d34-2268-5548-8538-3947e77c9e10",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 5.2.11-tuxcare.21 of @angular/language-service. not_affected \u2014 Angular 5.2.11 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache with hierarchical HttpClient delegation (withRequestsMadeViaParent()), features that were introduced in Angular v16. Angular 5.2.11 predates these features by approximately 6+ years and contains only a basic HTTP interceptor architecture with no automatic response caching mechanism. While TransferStat...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:fd88704e-5be5-5369-a1a5-6aceb37a3e89",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 5.2.11-tuxcare.21 of @angular/language-service."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/language-service@5.2.11-tuxcare.21"
    }
  ]
}