{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b0ca5ae0-3929-506e-9f9b-3f78b968a2e1",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/platform-server@9.1.13-tuxcare.3",
      "type": "library",
      "name": "@angular/platform-server",
      "version": "9.1.13-tuxcare.3",
      "purl": "pkg:npm/%40angular/platform-server@9.1.13-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:9ded78a1-5c3a-517b-bd9e-fac027ded2f2",
      "id": "CVE-2021-4231",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-4231 affects version 9.1.13-tuxcare.3 of @angular/platform-server."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@9.1.13-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae38a841-3617-5219-807c-431eba1a5c82",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 9.1.13-tuxcare.3 of @angular/platform-server."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@9.1.13-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65242dcc-dd83-5e77-abc8-6b9ec46d960c",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 9.1.13-tuxcare.3 of @angular/platform-server."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@9.1.13-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5383f9f4-962e-532d-a596-eb779a930b8e",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22610 affects version 9.1.13-tuxcare.3 of @angular/platform-server."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@9.1.13-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b360c7b9-f0f6-5a2b-b017-fdfc206ace87",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 9.1.13-tuxcare.3 of @angular/platform-server."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@9.1.13-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69879c97-fcc3-55aa-84dd-c726fb6073e1",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 9.1.13-tuxcare.3 of @angular/platform-server."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@9.1.13-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd3b3ac8-96e5-555d-bf73-f6bd42f49754",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 9.1.13-tuxcare.3 of @angular/platform-server."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@9.1.13-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d17a7532-84b5-5a95-95df-1a99a8df1e56",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 9.1.13-tuxcare.3 of @angular/platform-server."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@9.1.13-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46f2e019-617f-534e-9d62-7a8f746be3da",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 9.1.13-tuxcare.3 of @angular/platform-server."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@9.1.13-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4b84ee3-f35d-5a19-b7fa-896f37d0921e",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50170 does not affect version 9.1.13-tuxcare.3 of @angular/platform-server. not_affected \u2014 Angular v9.1.13 is not affected by CVE-2026-50170. The vulnerability exists in Angular's HttpTransferCache feature, which was introduced in Angular v16+. This feature does not exist in v9.1.13, making the vulnerability pattern impossible to manifest."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@9.1.13-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f94dea75-7bc4-58c8-be2e-b060e036be35",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 9.1.13-tuxcare.3 of @angular/platform-server."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@9.1.13-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a99d5aef-5dec-5f65-adaf-0856b8c10ed7",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 9.1.13-tuxcare.3 of @angular/platform-server."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@9.1.13-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50f868fa-a6e2-5386-abe5-5572d9fb36b8",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 9.1.13-tuxcare.3 of @angular/platform-server."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@9.1.13-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e19e737-a3b3-56dc-8f74-361c5ebfa4d4",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 9.1.13-tuxcare.3 of @angular/platform-server."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@9.1.13-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bfc8d09-781f-5f46-9349-6ddd6a2b30e9",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 9.1.13-tuxcare.3 of @angular/platform-server."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@9.1.13-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03348c85-f807-5659-98c4-cc3620c78643",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 9.1.13-tuxcare.3 of @angular/platform-server."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@9.1.13-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1803a65e-c571-5eb2-8336-1a66e7badf35",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54264 does not affect version 9.1.13-tuxcare.3 of @angular/platform-server. not_affected \u2014 Angular 9.1.13 is not affected by CVE-2026-54264. The target repository uses a fundamentally different request reconstruction architecture than the vulnerable upstream versions (22.0+). The vulnerability requires the presence of header-copying logic during request reconstruction, which does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@9.1.13-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:267571ac-d3ea-5a3d-b38d-f2779e54c92f",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 9.1.13-tuxcare.3 of @angular/platform-server. not_affected \u2014 Angular 9.1.13-tuxcare.9 is NOT AFFECTED by CVE-2026-54265. The vulnerability exists in newer Ivy compiler's template/pipeline architecture where TwoWayProperty operations bypass sanitizer resolution. This version uses View Engine and early render3 (Ivy) implementations where two-way bindings desugar through the same parsePropertyBinding() path as one-way bindings, ensuring identical sanitizer ..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@9.1.13-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d91beb06-91d2-5780-9f87-8da84df06eb6",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54266 does not affect version 9.1.13-tuxcare.3 of @angular/platform-server. not_affected \u2014 Angular 9.1.13-tuxcare.9 does not contain the HttpTransferCache feature. The vulnerability CVE-2026-54266 affects the hash generation in HttpTransferCache, a feature introduced in Angular v16+. The target version (9.1.13) predates this feature by many major versions. While TransferState (generic state serialization) exists in v9, there is no HTTP caching integration that uses it. The packages/c..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@9.1.13-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:356825a7-559b-52c5-a9e8-de13711c2fd6",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 9.1.13-tuxcare.3 of @angular/platform-server."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@9.1.13-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbc35f19-00fa-59db-92d1-5dd4af506705",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 9.1.13-tuxcare.3 of @angular/platform-server."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@9.1.13-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/platform-server@9.1.13-tuxcare.3"
    }
  ]
}