{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e3063936-b564-5381-a1fd-2c3641866784",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.3",
      "type": "library",
      "name": "@angular/elements",
      "version": "15.0.3-tuxcare.3",
      "purl": "pkg:npm/%40angular/elements@15.0.3-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:427ba632-2778-504e-8c81-65d08e7eb920",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 15.0.3-tuxcare.3 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b84df296-92eb-5608-a0ae-97907e862812",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 15.0.3-tuxcare.3 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80a5df3f-e115-52cb-b9bf-640beb126d77",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 15.0.3-tuxcare.3 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b40ee88d-d869-5489-99bb-1cb7c488d35a",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 15.0.3-tuxcare.3 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4164eec7-6c17-5cbf-a1a0-cda447fe3bd7",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 15.0.3-tuxcare.3 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42287158-12c5-572d-af4b-ac10591fa71d",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 15.0.3-tuxcare.3 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c900c83e-d8df-5b20-af7d-0af3ee0bf656",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 15.0.3-tuxcare.3 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ce39a09-c50c-5c88-8b83-9dc48d449698",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 15.0.3-tuxcare.3 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7a7d53b-f388-58d3-a8ae-53d433407efb",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50170 does not affect version 15.0.3-tuxcare.3 of @angular/elements. not_affected \u2014 Angular 15.0.3-tuxcare.1 is NOT affected by CVE-2026-50170. The HTTP TransferCache feature that is vulnerable in later Angular versions (v16+) does not exist in this version. The vulnerable code (transfer_cache.ts, hasAuthHeaders(), shouldCacheRequest(), withHttpTransferCache, provideClientHydration) is absent from Angular 15.0.3."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:651871e2-17be-511d-8143-fae0b8f69b7a",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 15.0.3-tuxcare.3 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2847123d-4605-5e83-b3fe-a4bde58eeb37",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 15.0.3-tuxcare.3 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9112153-665f-5c91-af67-a5e5d14196cc",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 15.0.3-tuxcare.3 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ddd38c2-54e0-5354-b8d6-87aa3c30c20e",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 15.0.3-tuxcare.3 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b75cde33-af95-5d70-8c91-72e6d5a065bc",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 15.0.3-tuxcare.3 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91c788b5-2a58-5a38-83b9-d5e596d8dd72",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 15.0.3-tuxcare.3 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44d84c33-4f9b-5d35-913e-e14f2030db17",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 15.0.3-tuxcare.3 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2632f8a6-064c-5342-a716-a2355e6b73a3",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 15.0.3-tuxcare.3 of @angular/elements. not_affected \u2014 Angular 15.0.3 is NOT AFFECTED by CVE-2026-54265. This version uses a different compiler architecture where two-way bindings desugar through the same code path as one-way bindings, both receiving identical security context resolution and sanitizer assignment. The vulnerable code (Ivy template pipeline with separate TwoWayProperty operation type) does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e3b16c3-f59c-50b2-8999-d1edcfd86e2c",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54266 does not affect version 15.0.3-tuxcare.3 of @angular/elements. not_affected \u2014 Angular v15.0.3-tuxcare.1 is NOT affected by CVE-2026-54266. The vulnerable HttpTransferCache feature with weak DJB2 hash-based cache keys does not exist in this version. This feature was introduced in Angular v16+. The target has no code path from HTTP request handling to the vulnerability's cache poisoning goal."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9dca323-b245-56be-a6bf-5cbdff7930c7",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 15.0.3-tuxcare.3 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9688ccc-f8ba-5f47-97a9-cc4e63541a0c",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 15.0.3-tuxcare.3 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/elements@15.0.3-tuxcare.3"
    }
  ]
}