{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:6ec0e73f-b4e9-57d8-a4ee-0937589cafb5",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/compiler-cli@9.1.13-tuxcare.11",
      "type": "library",
      "name": "@angular/compiler-cli",
      "version": "9.1.13-tuxcare.11",
      "purl": "pkg:npm/%40angular/compiler-cli@9.1.13-tuxcare.11"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:fb821073-0965-569b-a126-e99358cdfc16",
      "id": "CVE-2021-4231",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 9.1.13-tuxcare.11 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@9.1.13-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca978c4c-da82-58b8-92e4-0f3db69a558c",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 9.1.13-tuxcare.11 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@9.1.13-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb90c8b5-fbe0-56fb-8d39-b492d951f535",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 9.1.13-tuxcare.11 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@9.1.13-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a441683e-d39f-5ba6-a799-218a5e927dcd",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 9.1.13-tuxcare.11 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@9.1.13-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8d63317-ac65-5121-89e7-9f6a1a29b0c7",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 9.1.13-tuxcare.11 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@9.1.13-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:110173ab-686d-5d93-8624-1864328934da",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 9.1.13-tuxcare.11 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@9.1.13-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e404078-55d6-55c2-8f2c-7acc25d112e6",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 9.1.13-tuxcare.11 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@9.1.13-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88138821-8799-5796-b4c4-bf42071b8203",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 9.1.13-tuxcare.11 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@9.1.13-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7c63532-c534-5fb4-95c7-b3fc719d1d3b",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 9.1.13-tuxcare.11 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@9.1.13-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f7955d7-d08b-5e16-9968-dc12aadeee47",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50170 does not affect version 9.1.13-tuxcare.11 of @angular/compiler-cli. not_affected \u2014 Angular v9.1.13 is not affected by CVE-2026-50170. The vulnerability exists in Angular's HttpTransferCache feature, which was introduced in Angular v16+. This feature does not exist in v9.1.13, making the vulnerability pattern impossible to manifest."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@9.1.13-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b966591b-757b-5e6e-a975-a2856bf328ad",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 9.1.13-tuxcare.11 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@9.1.13-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63883785-d830-5364-afdc-5d9d85a3b1ce",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 9.1.13-tuxcare.11 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@9.1.13-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9073673b-6d08-52d8-90a7-ce30770d0291",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 9.1.13-tuxcare.11 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@9.1.13-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3939b6f1-9442-55fb-a361-54b8dad6cb70",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 9.1.13-tuxcare.11 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@9.1.13-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd86930c-ca8a-5469-a22e-48f3fd52ca6e",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 9.1.13-tuxcare.11 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@9.1.13-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a508df4-816d-50da-aaf8-0d53c804cb78",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 9.1.13-tuxcare.11 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@9.1.13-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae56b8bb-de0c-51a0-b0f3-566e8b210922",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54264 does not affect version 9.1.13-tuxcare.11 of @angular/compiler-cli. not_affected \u2014 Angular 9.1.13 is not affected by CVE-2026-54264. The target repository uses a fundamentally different request reconstruction architecture than the vulnerable upstream versions (22.0+). The vulnerability requires the presence of header-copying logic during request reconstruction, which does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@9.1.13-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:408bbd68-9825-5965-a05e-2454fd70af23",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 9.1.13-tuxcare.11 of @angular/compiler-cli. not_affected \u2014 Angular 9.1.13-tuxcare.9 is NOT AFFECTED by CVE-2026-54265. The vulnerability exists in newer Ivy compiler's template/pipeline architecture where TwoWayProperty operations bypass sanitizer resolution. This version uses View Engine and early render3 (Ivy) implementations where two-way bindings desugar through the same parsePropertyBinding() path as one-way bindings, ensuring identical sanitizer ..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@9.1.13-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97e68d9d-2194-506d-b8d4-6f69ec45f8ce",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54266 does not affect version 9.1.13-tuxcare.11 of @angular/compiler-cli. not_affected \u2014 Angular 9.1.13-tuxcare.9 does not contain the HttpTransferCache feature. The vulnerability CVE-2026-54266 affects the hash generation in HttpTransferCache, a feature introduced in Angular v16+. The target version (9.1.13) predates this feature by many major versions. While TransferState (generic state serialization) exists in v9, there is no HTTP caching integration that uses it. The packages/c..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@9.1.13-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f18e6d13-a160-5396-bc97-1398ae03a515",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 9.1.13-tuxcare.11 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@9.1.13-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d24cd726-4cba-5c5a-8d57-69e1908245a2",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 9.1.13-tuxcare.11 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@9.1.13-tuxcare.11"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/compiler-cli@9.1.13-tuxcare.11"
    }
  ]
}