{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ff6d15f0-ba42-50e3-bdfc-9f6a8bf26d6c",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/upgrade",
      "purl": "pkg:npm/%40angular/upgrade@5.2.11-tuxcare.21",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/upgrade@5.2.11-tuxcare.21",
      "version": "5.2.11-tuxcare.21",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:37ab5753-3281-5031-b0d1-d5eb8452bdc0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 5.2.11-tuxcare.21 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:f6b16092-2a6a-59eb-b041-4ea4c071bd1d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 5.2.11-tuxcare.21 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:d2522ce2-1b94-56f7-a528-e57b03583ece",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 5.2.11-tuxcare.21 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:987d50f7-64b4-5dcc-b7bc-866858241532",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101895 affects version 5.2.11-tuxcare.21 of @angular/upgrade, and is fixed in 5.2.11-tuxcare.22."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:6cfcf75a-6065-5b0d-af9e-1d0e0cafecb2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 5.2.11-tuxcare.21 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:92cd6bac-c93d-5043-9806-ad77ea660351",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 5.2.11-tuxcare.21 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:6faf4168-9872-5f98-87a5-18ffcf0a6536",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 5.2.11-tuxcare.21 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:cd4de6f2-3d19-59fc-a735-897615abf406",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 5.2.11-tuxcare.21 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:83e7b18b-04a0-5c83-b5ec-a61375b566ba",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 5.2.11-tuxcare.21 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:0cde6a48-a8d2-5ca8-b2a3-c7e6c6846cad",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 5.2.11-tuxcare.21 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:14623f0c-d379-58ee-96a4-22da17c520cb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 5.2.11-tuxcare.21 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:716f6c65-31b8-5b5d-b14d-695e86d4b909",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 5.2.11-tuxcare.21 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:e33c1ee0-4941-58c1-b515-f407dac67d6d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 5.2.11-tuxcare.21 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:64c5bd9c-1cba-5edd-9389-b20f3c85f7a6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 5.2.11-tuxcare.21 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:214361ec-3f99-58f5-9512-bfee2cddc37f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 5.2.11-tuxcare.21 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:60722735-3b47-5f38-9347-1aa3ac0e4a48",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 5.2.11-tuxcare.21 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:1af3cab0-3e2f-512a-87fd-e98d1a156c79",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 5.2.11-tuxcare.21 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:e2e824fe-7264-5a39-9f5f-bbecd4b0e715",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 5.2.11-tuxcare.21 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:5019bfe8-33eb-5659-959c-9dc9a2f017e6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 5.2.11-tuxcare.21 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:05a2615c-fb6c-5f61-944a-e7d73dbdc98c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 5.2.11-tuxcare.21 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:bd4e132c-556a-5dfe-816e-60ca7d634c0e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 5.2.11-tuxcare.21 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:d970abec-9d2b-5d84-a6d6-5102cd70298c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 5.2.11-tuxcare.21 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:38499bad-aa63-5b82-9720-58ebdff6cfa6",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 5.2.11-tuxcare.21 of @angular/upgrade. not_affected \u2014 Angular 5.2.11 is NOT affected by CVE-2026-68945. The vulnerable component `HttpTransferCache` does not exist in this version. This feature was introduced in Angular v16 as part of the modern SSR hydration system. Angular 5.2.11 only has the basic `TransferState` API (a generic key-value store for manual state transfer), not the automatic HTTP request caching interceptor that contains the vulne...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:94cb92ff-2b0a-54b8-8aa9-d7bf53f63763",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 5.2.11-tuxcare.21 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:6fcd1cb4-07f1-5442-8178-6b41aacfb19e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 5.2.11-tuxcare.21 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:b7be38f8-a59b-58a0-b317-8cbe183f337e",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 5.2.11-tuxcare.21 of @angular/upgrade. not_affected \u2014 Angular 5.2.11-tuxcare.19 does not contain the vulnerable URL resolution code pattern described in CVE-2026-88056. The vulnerability requires the url.ts file with parseUrl function calling String.prototype.trim() and the relativeUrlsTransformerInterceptorFn HTTP interceptor, both introduced in later Angular versions (post-June 2026). The target version uses a fundamentally different architectur...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:e7c1923a-16ec-5841-ab9f-a937191f01b9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 5.2.11-tuxcare.21 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:7aba0536-6fac-5e6a-a3fa-1d2cc0a2b48b",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88058 does not affect version 5.2.11-tuxcare.21 of @angular/upgrade. not_affected \u2014 CVE-2026-88058 affects the domino library's HTML serialization (XSS via ancestor fallback raw-content tag injection in comments/processing instructions during SSR). The target Angular 5.2.11-tuxcare.19 repository declares domino 2.1.2 as a dependency but does NOT vendor its source code. The vulnerable code (NodeUtils.js serializeOne() function) lives in the domino npm package, not in Angular's ...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:12d9a05e-7b0d-5a3f-a9c8-e2dbbb43b4c8",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 5.2.11-tuxcare.21 of @angular/upgrade. not_affected \u2014 Angular 5.2.11 is NOT AFFECTED by CVE-2026-88059. The vulnerability requires HttpTransferCache with hierarchical HttpClient delegation (withRequestsMadeViaParent()), features that were introduced in Angular v16. Angular 5.2.11 predates these features by approximately 6+ years and contains only a basic HTTP interceptor architecture with no automatic response caching mechanism. While TransferStat...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@5.2.11-tuxcare.21"
        }
      ],
      "bom-ref": "urn:uuid:4f6eed4c-2c17-565b-a4c6-a3d4d03a54dd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 5.2.11-tuxcare.21 of @angular/upgrade."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/upgrade@5.2.11-tuxcare.21"
    }
  ]
}