{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:6fdd0d1b-cf3c-5a3b-b0d2-49f85d581f7b",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/upgrade@14.2.12-tuxcare.1",
      "type": "library",
      "name": "@angular/upgrade",
      "version": "14.2.12-tuxcare.1",
      "purl": "pkg:npm/%40angular/upgrade@14.2.12-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:27276b5f-0ed1-5b1f-98ce-ad5d3f5e1f63",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 14.2.12-tuxcare.1 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@14.2.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48acfded-9af0-54a0-97b2-080dbe7dbed5",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66412 affects version 14.2.12-tuxcare.1 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@14.2.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:691b8a53-6e53-5ff0-b93d-7cd35d35d6f5",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22610 affects version 14.2.12-tuxcare.1 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@14.2.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd04b8b3-ccda-50b0-8904-9da2e7fa2997",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 14.2.12-tuxcare.1 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@14.2.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52a725f9-9d98-5a0a-b534-b7aecbdbaf1d",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41423 affects version 14.2.12-tuxcare.1 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@14.2.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b47870b5-e65a-591f-8143-e99ca5b1ef22",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 14.2.12-tuxcare.1 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@14.2.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1565d6ef-8130-5f93-ac5c-889c1d2b8cf3",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 14.2.12-tuxcare.1 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@14.2.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96d96085-744e-5d3f-8b98-6ed88ec9be57",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 14.2.12-tuxcare.1 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@14.2.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b435102c-06ac-506b-8b43-4f6ea43f12ee",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50170 does not affect version 14.2.12-tuxcare.1 of @angular/upgrade. not_affected \u2014 Angular v14.2.12-tuxcare.1 is not affected by CVE-2026-50170. The HTTP TransferCache feature and client hydration mechanism that contain the vulnerability were introduced in Angular v16+. This version predates that feature introduction and does not have the vulnerable code path."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@14.2.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d38a876-bba0-5f6e-bd6a-a356831e746d",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 14.2.12-tuxcare.1 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@14.2.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6c757e7-c6af-5dc4-a88b-9a1ec31be274",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 14.2.12-tuxcare.1 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@14.2.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2fe87e0-0ee2-5b3c-8727-511758fa6d88",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 14.2.12-tuxcare.1 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@14.2.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68b94aaa-9517-5ce1-a354-4bb50927234d",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 14.2.12-tuxcare.1 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@14.2.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd9d7b26-af4b-5cce-889e-3d9c29929008",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 14.2.12-tuxcare.1 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@14.2.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e9d049e-12e2-5618-ae6c-ba5e86f233e7",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 14.2.12-tuxcare.1 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@14.2.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5797b9e0-7030-5142-bb94-61901fad7309",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 14.2.12-tuxcare.1 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@14.2.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9826aa7a-7dc8-54c6-8b78-648de4b91259",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 14.2.12-tuxcare.1 of @angular/upgrade. not_affected \u2014 Angular 14.2.12-tuxcare.1 is not affected by CVE-2026-54265. This version uses the pre-pipeline compiler architecture where two-way bindings are desugared into separate property and event bindings, both of which go through proper sanitization. The vulnerability only exists in Angular 17.3.0+ where the template pipeline with TwoWayProperty IR operation was introduced."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@14.2.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec50e516-113b-5006-bab7-1a5e5ea878a1",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54266 does not affect version 14.2.12-tuxcare.1 of @angular/upgrade. not_affected \u2014 Angular 14.2.12 is not affected by CVE-2026-54266. The vulnerable HttpTransferCache feature does not exist in this version - it was introduced in Angular v16+. The target has no code path that generates cache keys from HTTP request parameters, and therefore cannot experience cache key collisions."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@14.2.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11067fe7-468d-500a-8d18-924b952bbabb",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 14.2.12-tuxcare.1 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@14.2.12-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28864394-e187-575f-bdfe-c982e6ab9e5c",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 14.2.12-tuxcare.1 of @angular/upgrade."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@14.2.12-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/upgrade@14.2.12-tuxcare.1"
    }
  ]
}