{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:650efdac-7483-5135-9c8d-d4f1be13017b",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/elements@15.2.2-tuxcare.2",
      "type": "library",
      "name": "@angular/elements",
      "version": "15.2.2-tuxcare.2",
      "purl": "pkg:npm/%40angular/elements@15.2.2-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:0f6ab103-dd9b-5c82-8b4e-83cb5bfffbd8",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 15.2.2-tuxcare.2 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.2.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e7b2b01-7a80-5113-8d31-2610af4d397f",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 15.2.2-tuxcare.2 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.2.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d0be9c6-23e4-56a9-9f78-a05c1a347835",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 15.2.2-tuxcare.2 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.2.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb266d51-646d-51be-ad76-3281f4cdb404",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 15.2.2-tuxcare.2 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.2.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53079094-11cf-511d-b5e8-0af6af38c1a0",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41423 does not affect version 15.2.2-tuxcare.2 of @angular/elements. not_affected \u2014 The target repository (Angular 15.2.2-tuxcare.1) is NOT affected by CVE-2026-41423. While the target lacks the specific fix from the upstream patch, it uses a fundamentally different URL parsing mechanism (Node.js legacy url.parse()) that does not exhibit the WHATWG URL specification behavior exploited in the vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.2.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f48a08b3-e91e-506d-b181-27d445bf53af",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 15.2.2-tuxcare.2 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.2.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b323a13e-d80d-5f18-8d4a-361ea1f07a3e",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 15.2.2-tuxcare.2 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.2.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6f18d88-f771-5c48-a985-4c4324cfaa71",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 15.2.2-tuxcare.2 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.2.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f24a913-b7c0-5702-94b8-4dee3ed36974",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50170 does not affect version 15.2.2-tuxcare.2 of @angular/elements. not_affected \u2014 Angular v15.2.2 is not affected by CVE-2026-50170. The HTTP TransferCache feature, which is the subject of the vulnerability, was introduced in Angular v16.0.0 (March 2023). The target repository version (15.2.2-tuxcare.1) predates this feature entirely and does not contain the vulnerable code path."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.2.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f943b660-8bd3-5805-a6e2-797f281617e9",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 15.2.2-tuxcare.2 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.2.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1b05ee3-56ad-51dd-8025-308462cdad47",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 15.2.2-tuxcare.2 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.2.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd188ffc-7a89-5fbb-b2fc-8454c23b435c",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 15.2.2-tuxcare.2 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.2.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d29df75f-b254-53d6-ace9-699b61a1d61f",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 15.2.2-tuxcare.2 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.2.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37984b16-f176-591c-a8ae-ed7160741daa",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 15.2.2-tuxcare.2 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.2.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90c7a25c-1e04-5153-a6a8-ffeff70a5bd7",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 15.2.2-tuxcare.2 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.2.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9401b72a-3908-5834-bb15-28d11e73f0bf",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 15.2.2-tuxcare.2 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.2.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1a115ca-7c92-5874-965d-a9680bac6123",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 15.2.2-tuxcare.2 of @angular/elements. not_affected \u2014 Angular v15.2.2 does not contain the vulnerable code path. The CVE-2026-54265 vulnerability affects the template pipeline's resolve_sanitizers.ts (TwoWayProperty operation), which does not exist in v15.2.2. This version uses TemplateDefinitionBuilder where two-way bindings desugar to regular property bindings that receive identical sanitization as one-way bindings."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.2.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19a39f2a-ad5d-53a2-86fa-7e3d96f05215",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54266 does not affect version 15.2.2-tuxcare.2 of @angular/elements. not_affected \u2014 Angular 15.2.2 is not affected by CVE-2026-54266. The vulnerable HttpTransferCache feature was introduced in Angular 16.0.0 (May 2023), after this version was released (March 2023). The target codebase does not contain the transfer_cache.ts module, HttpTransferCache API, or any HTTP response caching mechanism that uses hash-based cache keys."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.2.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de1ba5bb-d38d-5e0b-9ac0-bd97d7c2c61e",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 15.2.2-tuxcare.2 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.2.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92240b92-68ca-5e68-ae52-f47d839b79df",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 15.2.2-tuxcare.2 of @angular/elements."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@15.2.2-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/elements@15.2.2-tuxcare.2"
    }
  ]
}