{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b3e250d6-1b65-53d1-b6d1-f640e738b282",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/animations@5.1.2-tuxcare.3",
      "type": "library",
      "name": "@angular/animations",
      "version": "5.1.2-tuxcare.3",
      "purl": "pkg:npm/%40angular/animations@5.1.2-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:1aefa5b7-d2a4-5ee9-8e03-0083ab19e53b",
      "id": "CVE-2021-4231",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 5.1.2-tuxcare.3 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.1.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09cbe859-4786-59df-90b2-73d34fcbc5f7",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 5.1.2-tuxcare.3 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.1.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88fe2829-0200-53b8-ad72-f56866c39875",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 5.1.2-tuxcare.3 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.1.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01b3c405-8640-550c-9665-d546c460a69a",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 5.1.2-tuxcare.3 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.1.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:046dbac8-905f-502d-96ce-e4b7536e1232",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 5.1.2-tuxcare.3 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.1.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19346d73-9297-55b6-8819-7e4140c81103",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41423 does not affect version 5.1.2-tuxcare.3 of @angular/animations. not_affected \u2014 Angular version 5.1.2 is not affected by CVE-2026-41423. The vulnerability requires the WHATWG URL API which exhibits hostname override behavior with protocol-relative URLs. The target uses Node.js's legacy url.parse() API which does not have this behavior."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.1.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:861fa95a-295b-5bcb-b4bf-61d728eedf4b",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 5.1.2-tuxcare.3 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.1.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18c399d4-1612-5202-af5e-d26e6dbcbfbc",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 5.1.2-tuxcare.3 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.1.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9453877c-2537-5d9c-a837-16c010b7b15b",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 5.1.2-tuxcare.3 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.1.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af27b4f9-8ba7-5da6-8a9a-d40c89f7b7b9",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50170 does not affect version 5.1.2-tuxcare.3 of @angular/animations. not_affected \u2014 no evidence captured"
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.1.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ad0503e-161a-508d-b48d-0b68569b3bc7",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 5.1.2-tuxcare.3 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.1.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fa887c5-1c2d-5d2d-9dc7-86fd3006106f",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 5.1.2-tuxcare.3 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.1.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50be8b03-4467-5df1-ba9b-7436882038eb",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 5.1.2-tuxcare.3 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.1.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:280f131e-5849-5da3-a76f-7d97a822df85",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 5.1.2-tuxcare.3 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.1.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21ffe2f1-16ba-5b43-abac-9affd7320a1e",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 5.1.2-tuxcare.3 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.1.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9255292f-73b0-5ad7-afbf-267d69bc32be",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 5.1.2-tuxcare.3 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.1.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4123d40c-174a-5cb4-ae03-cdd596725bf9",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54264 does not affect version 5.1.2-tuxcare.3 of @angular/animations. not_affected \u2014 Angular v5.1.2-tuxcare.1 is NOT affected by CVE-2026-54264. The vulnerability requires a `newRequestWithMetadata` function that copies request headers, which does not exist in this version. The service worker reconstructs asset requests from URLs only using bare `adapter.newRequest(url)` calls, never copying or forwarding request headers. Therefore, credential headers cannot be leaked on cross-..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.1.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:862a063a-b01b-514e-883a-9b893813fce7",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 5.1.2-tuxcare.3 of @angular/animations. not_affected \u2014 Angular 5.1.2 uses the View Engine compiler architecture, which does not have the TwoWayProperty operation kind that is vulnerable in the Ivy compiler. In View Engine, two-way bindings desugar through the same parsePropertyBinding() code path as one-way bindings, ensuring both receive identical security context resolution and sanitization. The vulnerability pattern described in CVE-2026-54265 c..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.1.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2d710f7-9bbf-5d33-b36c-c45a6af62501",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54266 does not affect version 5.1.2-tuxcare.3 of @angular/animations. not_affected \u2014 Angular 5.1.2 is not affected by CVE-2026-54266. The vulnerable HttpTransferCache feature that generates cache keys using a weak 32-bit DJB2 hash does not exist in this version. This feature was introduced in Angular v16+, while the target is v5.1.2. Although TransferState exists in this version for basic state transfer, there is no integration with HttpClient for automatic response caching, no..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.1.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32a3d8b4-b06c-5df6-bb5a-77659a0822f4",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 5.1.2-tuxcare.3 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.1.2-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13c9bbf9-e5f7-5d66-befd-27e9b6dc3811",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 5.1.2-tuxcare.3 of @angular/animations."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@5.1.2-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/animations@5.1.2-tuxcare.3"
    }
  ]
}