{
  "@id": "urn:uuid:4863592d-e04e-4119-bc4d-55cebaea2952",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 6,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-10-03T18:28:00.095772+00:00",
  "statements": [
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40angular/common@11.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/common@11.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-26T17:44:00.105584+00:00",
      "status_notes": "Vulnerability CVE-2025-66035 is fixed in version 11.2.11-tuxcare.6 of @angular/common.",
      "vulnerability": {
        "name": "CVE-2025-66035"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40angular/common@11.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/common@11.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-26T17:44:00.105584+00:00",
      "status_notes": "Vulnerability CVE-2025-66412 is fixed in version 11.2.11-tuxcare.6 of @angular/common.",
      "vulnerability": {
        "name": "CVE-2025-66412"
      }
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/%40angular/common@11.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/common@11.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-10-03T18:28:00.095772+00:00",
      "status_notes": "Vulnerability CVE-2026-101895 affects version 11.2.11-tuxcare.6 of @angular/common, and is fixed in 11.2.11-tuxcare.7.",
      "vulnerability": {
        "name": "CVE-2026-101895"
      },
      "action_statement": "Vulnerability CVE-2026-101895 affects version 11.2.11-tuxcare.6 of @angular/common, and is fixed in 11.2.11-tuxcare.7."
    },
    {
      "status": "affected",
      "products": [
        {
          "@id": "pkg:npm/%40angular/common@11.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/common@11.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-30T15:57:50.734473+00:00",
      "status_notes": "Vulnerability CVE-2026-101896 affects version 11.2.11-tuxcare.6 of @angular/common.",
      "vulnerability": {
        "name": "CVE-2026-101896"
      },
      "action_statement": "Vulnerability CVE-2026-101896 affects version 11.2.11-tuxcare.6 of @angular/common."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40angular/common@11.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/common@11.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-26T17:44:00.105584+00:00",
      "status_notes": "Vulnerability CVE-2026-22610 is fixed in version 11.2.11-tuxcare.6 of @angular/common.",
      "vulnerability": {
        "name": "CVE-2026-22610"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40angular/common@11.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/common@11.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-26T17:44:00.105584+00:00",
      "status_notes": "Vulnerability CVE-2026-27970 is fixed in version 11.2.11-tuxcare.6 of @angular/common.",
      "vulnerability": {
        "name": "CVE-2026-27970"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40angular/common@11.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/common@11.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-26T17:44:00.105584+00:00",
      "status_notes": "Vulnerability CVE-2026-41423 is fixed in version 11.2.11-tuxcare.6 of @angular/common.",
      "vulnerability": {
        "name": "CVE-2026-41423"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40angular/common@11.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/common@11.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-26T17:44:00.105584+00:00",
      "status_notes": "Vulnerability CVE-2026-46417 is fixed in version 11.2.11-tuxcare.6 of @angular/common.",
      "vulnerability": {
        "name": "CVE-2026-46417"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40angular/common@11.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/common@11.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-26T17:44:00.105584+00:00",
      "status_notes": "Vulnerability CVE-2026-50168 is fixed in version 11.2.11-tuxcare.6 of @angular/common.",
      "vulnerability": {
        "name": "CVE-2026-50168"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40angular/common@11.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/common@11.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-26T17:44:00.105584+00:00",
      "status_notes": "Vulnerability CVE-2026-50169 is fixed in version 11.2.11-tuxcare.6 of @angular/common.",
      "vulnerability": {
        "name": "CVE-2026-50169"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/%40angular/common@11.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/common@11.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-26T17:44:00.105584+00:00",
      "status_notes": "Vulnerability CVE-2026-50170 does not affect version 11.2.11-tuxcare.6 of @angular/common. not_affected \u2014 Angular v11.2.11 is NOT AFFECTED by CVE-2026-50170. The vulnerability affects the HTTP transfer cache feature introduced in Angular v16+, which automatically caches HTTP responses during SSR and replays them during client hydration. This feature does not exist in v11.2.11. The target lacks the entire transfer_cache.ts module, withHttpTransferCache API, transferCacheInterceptorFn, and client hyd...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-50170"
      },
      "impact_statement": "not_affected \u2014 Angular v11.2.11 is NOT AFFECTED by CVE-2026-50170. The vulnerability affects the HTTP transfer cache feature introduced in Angular v16+, which automatically caches HTTP responses during SSR and replays them during client hydration. This feature does not exist in v11.2.11. The target lacks the entire transfer_cache.ts module, withHttpTransferCache API, transferCacheInterceptorFn, and client hyd..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40angular/common@11.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/common@11.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-26T17:44:00.105584+00:00",
      "status_notes": "Vulnerability CVE-2026-50171 is fixed in version 11.2.11-tuxcare.6 of @angular/common.",
      "vulnerability": {
        "name": "CVE-2026-50171"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40angular/common@11.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/common@11.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-26T17:44:00.105584+00:00",
      "status_notes": "Vulnerability CVE-2026-50184 is fixed in version 11.2.11-tuxcare.6 of @angular/common.",
      "vulnerability": {
        "name": "CVE-2026-50184"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/%40angular/common@11.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/common@11.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-26T17:44:00.105584+00:00",
      "status_notes": "Vulnerability CVE-2026-50555 does not affect version 11.2.11-tuxcare.6 of @angular/common. already_fixed \u2014 CVE-2026-50555 has already been fixed in the target repository. The fix is implemented in tools/postinstall-patches.js (lines 96-139) which patches the domino dependency during installation. The fix adds NOSCRIPT to hasRawContent, removes _scripting_enabled conditionals, and implements escapeMatchingClosingTag to prevent XSS via raw-text element breakout.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-50555"
      },
      "impact_statement": "already_fixed \u2014 CVE-2026-50555 has already been fixed in the target repository. The fix is implemented in tools/postinstall-patches.js (lines 96-139) which patches the domino dependency during installation. The fix adds NOSCRIPT to hasRawContent, removes _scripting_enabled conditionals, and implements escapeMatchingClosingTag to prevent XSS via raw-text element breakout."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40angular/common@11.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/common@11.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-26T17:44:00.105584+00:00",
      "status_notes": "Vulnerability CVE-2026-50556 is fixed in version 11.2.11-tuxcare.6 of @angular/common.",
      "vulnerability": {
        "name": "CVE-2026-50556"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40angular/common@11.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/common@11.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-26T17:44:00.105584+00:00",
      "status_notes": "Vulnerability CVE-2026-50557 is fixed in version 11.2.11-tuxcare.6 of @angular/common.",
      "vulnerability": {
        "name": "CVE-2026-50557"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40angular/common@11.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/common@11.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-26T17:44:00.105584+00:00",
      "status_notes": "Vulnerability CVE-2026-52725 is fixed in version 11.2.11-tuxcare.6 of @angular/common.",
      "vulnerability": {
        "name": "CVE-2026-52725"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/%40angular/common@11.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/common@11.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-26T17:44:00.105584+00:00",
      "status_notes": "Vulnerability CVE-2026-54264 does not affect version 11.2.11-tuxcare.6 of @angular/common. not_affected \u2014 Angular 11.2.11-tuxcare.2 is NOT AFFECTED by CVE-2026-54264. The service worker in this version does not forward request headers during asset reconstruction, eliminating the cross-origin credential leak vulnerability. The vulnerable method `newRequestWithMetadata` that copies headers from the original request does not exist in this version.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54264"
      },
      "impact_statement": "not_affected \u2014 Angular 11.2.11-tuxcare.2 is NOT AFFECTED by CVE-2026-54264. The service worker in this version does not forward request headers during asset reconstruction, eliminating the cross-origin credential leak vulnerability. The vulnerable method `newRequestWithMetadata` that copies headers from the original request does not exist in this version."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/%40angular/common@11.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/common@11.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-26T17:44:00.105584+00:00",
      "status_notes": "Vulnerability CVE-2026-54265 does not affect version 11.2.11-tuxcare.6 of @angular/common. not_affected \u2014 Angular 11.2.11 is not affected by CVE-2026-54265. The vulnerability targets the new Ivy compiler's TwoWayProperty operation in the template compilation pipeline, which does not exist in Angular 11.2.11. In this version, two-way bindings desugar through the same sanitization-aware parsePropertyBinding code path as one-way bindings, ensuring security-sensitive properties are properly sanitized.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54265"
      },
      "impact_statement": "not_affected \u2014 Angular 11.2.11 is not affected by CVE-2026-54265. The vulnerability targets the new Ivy compiler's TwoWayProperty operation in the template compilation pipeline, which does not exist in Angular 11.2.11. In this version, two-way bindings desugar through the same sanitization-aware parsePropertyBinding code path as one-way bindings, ensuring security-sensitive properties are properly sanitized."
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/%40angular/common@11.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/common@11.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-26T17:44:00.105584+00:00",
      "status_notes": "Vulnerability CVE-2026-54266 does not affect version 11.2.11-tuxcare.6 of @angular/common. not_affected \u2014 Angular version 11.2.11 is not affected by CVE-2026-54266. The vulnerable HttpTransferCache feature with weak DJB2 hash-based cache key generation does not exist in this version. This feature was introduced in Angular v16, and version 11.2.11 predates it entirely.",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-54266"
      },
      "impact_statement": "not_affected \u2014 Angular version 11.2.11 is not affected by CVE-2026-54266. The vulnerable HttpTransferCache feature with weak DJB2 hash-based cache key generation does not exist in this version. This feature was introduced in Angular v16, and version 11.2.11 predates it entirely."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40angular/common@11.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/common@11.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-26T17:44:00.105584+00:00",
      "status_notes": "Vulnerability CVE-2026-54267 is fixed in version 11.2.11-tuxcare.6 of @angular/common.",
      "vulnerability": {
        "name": "CVE-2026-54267"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40angular/common@11.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/common@11.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-26T17:44:00.105584+00:00",
      "status_notes": "Vulnerability CVE-2026-54268 is fixed in version 11.2.11-tuxcare.6 of @angular/common.",
      "vulnerability": {
        "name": "CVE-2026-54268"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/%40angular/common@11.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/common@11.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-26T17:44:00.105584+00:00",
      "status_notes": "Vulnerability CVE-2026-68945 does not affect version 11.2.11-tuxcare.6 of @angular/common. not_affected \u2014 Angular 11.2.11 does not have the HttpTransferCache feature. The vulnerability CVE-2026-68945 affects HttpTransferCache, which was introduced in Angular 16.0.0 (March 2023), approximately 2 years after Angular 11.2.11 was released. The file packages/common/http/src/transfer_cache.ts does not exist in the target version. Angular 11 has a generic TransferState feature for manual state transfer bu...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-68945"
      },
      "impact_statement": "not_affected \u2014 Angular 11.2.11 does not have the HttpTransferCache feature. The vulnerability CVE-2026-68945 affects HttpTransferCache, which was introduced in Angular 16.0.0 (March 2023), approximately 2 years after Angular 11.2.11 was released. The file packages/common/http/src/transfer_cache.ts does not exist in the target version. Angular 11 has a generic TransferState feature for manual state transfer bu..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40angular/common@11.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/common@11.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-26T17:44:00.105584+00:00",
      "status_notes": "Vulnerability CVE-2026-69149 is fixed in version 11.2.11-tuxcare.6 of @angular/common.",
      "vulnerability": {
        "name": "CVE-2026-69149"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40angular/common@11.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/common@11.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-26T17:44:00.105584+00:00",
      "status_notes": "Vulnerability CVE-2026-69151 is fixed in version 11.2.11-tuxcare.6 of @angular/common.",
      "vulnerability": {
        "name": "CVE-2026-69151"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/%40angular/common@11.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/common@11.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-26T17:44:00.105584+00:00",
      "status_notes": "Vulnerability CVE-2026-88056 does not affect version 11.2.11-tuxcare.6 of @angular/common. not_affected \u2014 Angular 11.2.11 is not affected by CVE-2026-88056. The vulnerability was introduced in Angular 19.x when URL resolution logic was refactored to include `String.prototype.trim()`, which strips Unicode whitespace and creates a discrepancy with WHATWG URL parsing. Angular 11.x never contained this vulnerable code pattern\u2014its URL resolution directly uses WHATWG URL standard without intermediate str...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-88056"
      },
      "impact_statement": "not_affected \u2014 Angular 11.2.11 is not affected by CVE-2026-88056. The vulnerability was introduced in Angular 19.x when URL resolution logic was refactored to include `String.prototype.trim()`, which strips Unicode whitespace and creates a discrepancy with WHATWG URL parsing. Angular 11.x never contained this vulnerable code pattern\u2014its URL resolution directly uses WHATWG URL standard without intermediate str..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40angular/common@11.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/common@11.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-26T17:44:00.105584+00:00",
      "status_notes": "Vulnerability CVE-2026-88057 is fixed in version 11.2.11-tuxcare.6 of @angular/common.",
      "vulnerability": {
        "name": "CVE-2026-88057"
      }
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40angular/common@11.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/common@11.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-26T17:44:00.105584+00:00",
      "status_notes": "Vulnerability CVE-2026-88058 is fixed in version 11.2.11-tuxcare.6 of @angular/common.",
      "vulnerability": {
        "name": "CVE-2026-88058"
      }
    },
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:npm/%40angular/common@11.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/common@11.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-26T17:44:00.105584+00:00",
      "status_notes": "Vulnerability CVE-2026-88059 does not affect version 11.2.11-tuxcare.6 of @angular/common. not_affected \u2014 Angular 11.2.11 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache interceptor and the hierarchical HttpClient delegation API (withRequestsMadeViaParent()), both introduced in Angular 16+. Angular 11 lacks the entire feature: packages/common/http/src/transfer_cache.ts does not exist, no HttpTransferCache class or interceptor is present, and neither withRequestsMadeV...",
      "justification": "vulnerable_code_not_present",
      "vulnerability": {
        "name": "CVE-2026-88059"
      },
      "impact_statement": "not_affected \u2014 Angular 11.2.11 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache interceptor and the hierarchical HttpClient delegation API (withRequestsMadeViaParent()), both introduced in Angular 16+. Angular 11 lacks the entire feature: packages/common/http/src/transfer_cache.ts does not exist, no HttpTransferCache class or interceptor is present, and neither withRequestsMadeV..."
    },
    {
      "status": "fixed",
      "products": [
        {
          "@id": "pkg:npm/%40angular/common@11.2.11-tuxcare.6",
          "identifiers": {
            "purl": "pkg:npm/%40angular/common@11.2.11-tuxcare.6"
          }
        }
      ],
      "timestamp": "2026-09-26T17:44:00.105584+00:00",
      "status_notes": "Vulnerability CVE-2026-88060 is fixed in version 11.2.11-tuxcare.6 of @angular/common.",
      "vulnerability": {
        "name": "CVE-2026-88060"
      }
    }
  ]
}
