{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c5dffad0-7c8f-51c5-8ee9-81fedc5481d8",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/platform-browser",
      "purl": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.21",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.21",
      "version": "5.2.11-tuxcare.21",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:ba83844e-ad74-5fd5-bfb7-07836a717d60",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 5.2.11-tuxcare.21 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:54c55cff-5156-5355-82fe-a5db1bb650b3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 5.2.11-tuxcare.21 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:cc1f9413-96d9-5cdb-8e01-9a3c5dd14665",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 5.2.11-tuxcare.21 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:4a7af07b-6806-5bab-91c6-8b7ec4d62c54",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101895 affects version 5.2.11-tuxcare.21 of @angular/platform-browser, and is fixed in 5.2.11-tuxcare.22."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:5d1db1ac-b577-5c89-9a77-c958ea3a42a0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 5.2.11-tuxcare.21 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:ebc04e8e-abf6-5f0f-84e3-ec335dec2337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 5.2.11-tuxcare.21 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:a32ee76a-572c-5159-b6c6-505d3e7c7785",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 5.2.11-tuxcare.21 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:7706ca1d-2f9d-5538-80b4-3625c64e6b62",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 5.2.11-tuxcare.21 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:4066e9c5-829e-5cb0-90e8-3ee92ad90067",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 5.2.11-tuxcare.21 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:fd028cd2-44b4-5ee8-a0aa-211d7cfa2d86",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 5.2.11-tuxcare.21 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:0ccf3895-51e5-5caa-97c3-e0ca3f19d80c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 5.2.11-tuxcare.21 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:6d8016ff-21af-51bf-b799-608f157428a9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 5.2.11-tuxcare.21 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:ead77c19-8c6b-5d67-918a-ba733bcb2c35",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 5.2.11-tuxcare.21 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:7b62a58a-fa5a-5083-a794-c273b9d58db1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 5.2.11-tuxcare.21 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:b5906e3d-a618-5a48-83ca-bad1742b1e61",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 5.2.11-tuxcare.21 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:5b21bb6a-8bb0-5f76-9b99-072c547d0c08",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 5.2.11-tuxcare.21 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:991c0b70-a9a8-52ab-9fbd-142bd793c94f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 5.2.11-tuxcare.21 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:2ad3f07d-eef8-5eaf-a651-72f3e6b30901",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 5.2.11-tuxcare.21 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:f01d6540-e0ff-522b-8014-2dc7c91e2bb2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 5.2.11-tuxcare.21 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:6846e502-f44f-5a71-a84c-7998ac628aac",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 5.2.11-tuxcare.21 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:c01de560-a3a9-50bb-8f50-99e015577102",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 5.2.11-tuxcare.21 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:2cf242b5-040f-5d66-be8e-c6fa20da1056",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 5.2.11-tuxcare.21 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:66abddd2-b6bd-52b3-8cb1-22c09be76744",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 5.2.11-tuxcare.21 of @angular/platform-browser. not_affected \u2014 Angular 5.2.11 is NOT affected by CVE-2026-68945. The vulnerable component `HttpTransferCache` does not exist in this version. This feature was introduced in Angular v16 as part of the modern SSR hydration system. Angular 5.2.11 only has the basic `TransferState` API (a generic key-value store for manual state transfer), not the automatic HTTP request caching interceptor that contains the vulne...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:bf84d49d-57b7-550e-b4b3-ff68dfdac340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 5.2.11-tuxcare.21 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:3d11d988-aa12-5d43-91d7-1b913004e3ec",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 5.2.11-tuxcare.21 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:766a5e28-dd2f-5f65-b69e-b04fd3ed9f93",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 5.2.11-tuxcare.21 of @angular/platform-browser. not_affected \u2014 Angular 5.2.11-tuxcare.19 does not contain the vulnerable URL resolution code pattern described in CVE-2026-88056. The vulnerability requires the url.ts file with parseUrl function calling String.prototype.trim() and the relativeUrlsTransformerInterceptorFn HTTP interceptor, both introduced in later Angular versions (post-June 2026). The target version uses a fundamentally different architectur...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:534ab25a-d536-5cfd-9565-5a3f2506b67c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 5.2.11-tuxcare.21 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:a7d07715-f17a-5628-b8a5-b40493858b30",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88058 does not affect version 5.2.11-tuxcare.21 of @angular/platform-browser. not_affected \u2014 CVE-2026-88058 affects the domino library's HTML serialization (XSS via ancestor fallback raw-content tag injection in comments/processing instructions during SSR). The target Angular 5.2.11-tuxcare.19 repository declares domino 2.1.2 as a dependency but does NOT vendor its source code. The vulnerable code (NodeUtils.js serializeOne() function) lives in the domino npm package, not in Angular's ...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:7b1cf68e-8c93-51e2-b851-b538ad4f9d53",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 5.2.11-tuxcare.21 of @angular/platform-browser. not_affected \u2014 Angular 5.2.11 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache with hierarchical HttpClient delegation (withRequestsMadeViaParent()), features that were introduced in Angular v16. Angular 5.2.11 predates these features by approximately 6+ years and contains only a basic HTTP interceptor architecture with no automatic response caching mechanism. While TransferStat...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:326400ba-c988-592f-acb4-243a041ad034",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 5.2.11-tuxcare.21 of @angular/platform-browser."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/platform-browser@5.2.11-tuxcare.21"
    }
  ]
}