{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:9b0b8703-b968-5bfe-acf5-008c85d351fe",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.2",
      "type": "library",
      "name": "@angular/elements",
      "version": "15.0.3-tuxcare.2",
      "purl": "pkg:npm/%40angular/elements@15.0.3-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:898a7353-201d-571d-af60-6337aa18bd6d",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 15.0.3-tuxcare.2 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41e30a69-eb7b-5d97-aca4-27d32cee3821",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66412 affects version 15.0.3-tuxcare.2 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17406f97-d6c2-5375-b061-b333beeb7c43",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 15.0.3-tuxcare.2 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:409aea5a-be6d-5cc0-8914-7fc9f4a0c105",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 15.0.3-tuxcare.2 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78354fd0-344b-590d-a0ec-8ddbe9a3185b",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 15.0.3-tuxcare.2 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff7ad8b9-e72a-57b9-9899-c492a9819d56",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 15.0.3-tuxcare.2 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5604b58-b2cf-556b-a54f-ba8ca4788016",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 15.0.3-tuxcare.2 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:134ccce4-460a-5bf6-816e-8a1ea7e29ef0",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 15.0.3-tuxcare.2 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c16992b-8800-53a6-891d-8c17e0f8af1e",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50170 does not affect version 15.0.3-tuxcare.2 of @angular/elements. not_affected \u2014 Angular 15.0.3-tuxcare.1 is NOT affected by CVE-2026-50170. The HTTP TransferCache feature that is vulnerable in later Angular versions (v16+) does not exist in this version. The vulnerable code (transfer_cache.ts, hasAuthHeaders(), shouldCacheRequest(), withHttpTransferCache, provideClientHydration) is absent from Angular 15.0.3."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:330bd811-c8c6-5b30-b19c-46a372baf54b",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 15.0.3-tuxcare.2 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2684585e-56d2-5041-82c0-1726796e0fab",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 15.0.3-tuxcare.2 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:478261d1-d4d0-5991-b4d0-beba40143e76",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 15.0.3-tuxcare.2 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4dce4cbf-07ce-5735-b672-c683dd614f3b",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 15.0.3-tuxcare.2 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfd27ea2-bbf0-50cf-a04b-1997a9317623",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 15.0.3-tuxcare.2 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0627c189-e60a-5645-ac44-71c98340fb53",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 15.0.3-tuxcare.2 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a81468b-bec3-5275-a360-747de8a766ed",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 15.0.3-tuxcare.2 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2853a3e1-6704-5565-8852-d26b939d2b58",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 15.0.3-tuxcare.2 of @angular/elements. not_affected \u2014 Angular 15.0.3 is NOT AFFECTED by CVE-2026-54265. This version uses a different compiler architecture where two-way bindings desugar through the same code path as one-way bindings, both receiving identical security context resolution and sanitizer assignment. The vulnerable code (Ivy template pipeline with separate TwoWayProperty operation type) does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8b093fb-3f36-55de-98b6-a8f256fceb9b",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54266 does not affect version 15.0.3-tuxcare.2 of @angular/elements. not_affected \u2014 Angular v15.0.3-tuxcare.1 is NOT affected by CVE-2026-54266. The vulnerable HttpTransferCache feature with weak DJB2 hash-based cache keys does not exist in this version. This feature was introduced in Angular v16+. The target has no code path from HTTP request handling to the vulnerability's cache poisoning goal."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3dcbdcb4-7d47-5a5c-be8a-8505a9ee9826",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 15.0.3-tuxcare.2 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02a26889-6923-56b2-b5af-5857c89f63a1",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 15.0.3-tuxcare.2 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.2"
    }
  ]
}