{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ab7bd756-0bbb-5feb-9dd6-3b4b856d9c01",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/platform-browser@15.2.1",
      "type": "library",
      "name": "@angular/platform-browser",
      "version": "15.2.1",
      "purl": "pkg:npm/%40angular/platform-browser@15.2.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:da0957aa-dd7e-5741-b402-22b695f27206",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66412 affects version 15.2.1 of @angular/platform-browser."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@15.2.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da0ca695-89cf-504a-980c-1663ac808710",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22610 affects version 15.2.1 of @angular/platform-browser."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@15.2.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1bc4905-5125-5c2a-8bdd-32bf346e65c7",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 15.2.1 of @angular/platform-browser."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@15.2.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1f0441f-9957-5579-876b-35e52fea9fb5",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41423 does not affect version 15.2.1 of @angular/platform-browser. not_affected \u2014 The target Angular version 15.2.1 uses Node.js url.parse() API which does not exhibit the protocol-relative URL hostname override vulnerability. The vulnerable behavior was introduced in Angular 17+ when the code was refactored to use WHATWG new URL() API. Version 15.2.1 is not affected by CVE-2026-41423."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@15.2.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:955dad2d-07d2-5238-8a8f-44e7b015788c",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 15.2.1 of @angular/platform-browser."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@15.2.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc049484-66f6-574b-9bfb-9034ed4bb3d5",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 15.2.1 of @angular/platform-browser."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@15.2.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f07b460d-d94e-5b4b-9a63-07a39949211c",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 15.2.1 of @angular/platform-browser."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@15.2.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e63c2262-764f-5e31-b2d8-8e39446a95ad",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50170 does not affect version 15.2.1 of @angular/platform-browser. not_affected \u2014 Angular 15.2.1 is not affected by CVE-2026-50170. The HTTP transfer cache feature that contains the vulnerability was introduced in Angular v16+ and does not exist in version 15.2.1. The target repository lacks the entire affected component (packages/common/http/src/transfer_cache.ts) and all related transfer cache functionality."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@15.2.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2292b1fc-2fac-5aae-8e07-d8f2d9cc14cf",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 15.2.1 of @angular/platform-browser."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@15.2.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6eacc17-f5c5-5cd5-9ed7-cccf88770a08",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 15.2.1 of @angular/platform-browser."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@15.2.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5647419c-30c2-532f-9089-83c4ed7c7067",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 15.2.1 of @angular/platform-browser."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@15.2.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc4e710c-4e85-556f-92e1-5beb78500a59",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 15.2.1 of @angular/platform-browser."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@15.2.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0c6021a-eb8f-5693-93a8-648797d6d5b5",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 15.2.1 of @angular/platform-browser."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@15.2.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6029233c-a17e-5c3c-a50e-62acb16ff943",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 15.2.1 of @angular/platform-browser."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@15.2.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d16ed8a-67b4-5a2a-8576-aa826228512a",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 15.2.1 of @angular/platform-browser."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@15.2.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b9a2a75-b0ed-530c-b026-7798b1a0a999",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 15.2.1 of @angular/platform-browser. not_affected \u2014 Angular 15.2.1-tuxcare.1 is NOT AFFECTED by CVE-2026-54265. The vulnerability exists only in Angular 16+ where the template pipeline architecture introduced a TwoWayProperty operation kind that was missing from the sanitizer resolution switch. Angular 15.2.1 uses the pre-pipeline Ivy compiler where two-way bindings desugar through the same parsePropertyBinding() as one-way bindings, inheriting ..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@15.2.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e29b6ab-a4e5-5000-bdfd-4cd0439285ac",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54266 does not affect version 15.2.1 of @angular/platform-browser. not_affected \u2014 Angular 15.2.1 does not contain the HttpTransferCache feature, which was introduced in Angular 16.0.0. The vulnerable code path involving hash-based HTTP request caching does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@15.2.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a7fb040-caec-5390-943e-5335de7a8bb0",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 15.2.1 of @angular/platform-browser."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@15.2.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8692122-fc8d-5254-ab14-301e59052091",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 15.2.1 of @angular/platform-browser."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@15.2.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/platform-browser@15.2.1"
    }
  ]
}