{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c14e9994-1a28-530d-bfef-c7b000471ff3",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/forms@9.1.13-tuxcare.11",
      "type": "library",
      "name": "@angular/forms",
      "version": "9.1.13-tuxcare.11",
      "purl": "pkg:npm/%40angular/forms@9.1.13-tuxcare.11"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:93b879e0-0093-5b09-b830-c020279e54ad",
      "id": "CVE-2021-4231",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 9.1.13-tuxcare.11 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@9.1.13-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6fa8cd21-adb5-515a-ae2b-b96417070a66",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 9.1.13-tuxcare.11 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@9.1.13-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c4d5bae-70a5-54bc-8b5c-214c8c2a6559",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 9.1.13-tuxcare.11 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@9.1.13-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:132c5d91-af1b-5d78-8101-8222754cd0c5",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 9.1.13-tuxcare.11 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@9.1.13-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d7172f4-ad04-514d-96ef-b4d2467e5ee7",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 9.1.13-tuxcare.11 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@9.1.13-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c030ef55-9a6b-5548-8b3f-cd9e55078b7a",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 9.1.13-tuxcare.11 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@9.1.13-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ef4958c-462f-52a4-978a-1d9d0bf3ed17",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 9.1.13-tuxcare.11 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@9.1.13-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11d4cfd4-3866-58d9-af7d-a5aa04141178",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 9.1.13-tuxcare.11 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@9.1.13-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6959b04-8792-5a65-be3c-4d57e0387013",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 9.1.13-tuxcare.11 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@9.1.13-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23002288-2cf8-5610-979c-186d385b7541",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50170 does not affect version 9.1.13-tuxcare.11 of @angular/forms. not_affected \u2014 Angular v9.1.13 is not affected by CVE-2026-50170. The vulnerability exists in Angular's HttpTransferCache feature, which was introduced in Angular v16+. This feature does not exist in v9.1.13, making the vulnerability pattern impossible to manifest."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@9.1.13-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27812a0f-fd4a-590d-b3bb-f64dcbb8f77e",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 9.1.13-tuxcare.11 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@9.1.13-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f07d6cee-f62a-51f5-8dde-698b2bbcf4cc",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 9.1.13-tuxcare.11 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@9.1.13-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d316ee8-051d-5396-baf7-ee11e4892fcb",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 9.1.13-tuxcare.11 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@9.1.13-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5925f65-9d15-5114-9138-c2d4df590d74",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 9.1.13-tuxcare.11 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@9.1.13-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25ab9d1f-a7ba-5600-a096-73da8a652851",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 9.1.13-tuxcare.11 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@9.1.13-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab901ac8-10ba-5931-99eb-22b104090039",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 9.1.13-tuxcare.11 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@9.1.13-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d791a024-9a6c-56c7-a1db-f59dae263dd6",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54264 does not affect version 9.1.13-tuxcare.11 of @angular/forms. not_affected \u2014 Angular 9.1.13 is not affected by CVE-2026-54264. The target repository uses a fundamentally different request reconstruction architecture than the vulnerable upstream versions (22.0+). The vulnerability requires the presence of header-copying logic during request reconstruction, which does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@9.1.13-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:907fb4a1-d65c-5f62-a090-979f78b6a14a",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 9.1.13-tuxcare.11 of @angular/forms. not_affected \u2014 Angular 9.1.13-tuxcare.9 is NOT AFFECTED by CVE-2026-54265. The vulnerability exists in newer Ivy compiler's template/pipeline architecture where TwoWayProperty operations bypass sanitizer resolution. This version uses View Engine and early render3 (Ivy) implementations where two-way bindings desugar through the same parsePropertyBinding() path as one-way bindings, ensuring identical sanitizer ..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@9.1.13-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4767bf5-e5cc-5145-8f7f-10f76154972c",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54266 does not affect version 9.1.13-tuxcare.11 of @angular/forms. not_affected \u2014 Angular 9.1.13-tuxcare.9 does not contain the HttpTransferCache feature. The vulnerability CVE-2026-54266 affects the hash generation in HttpTransferCache, a feature introduced in Angular v16+. The target version (9.1.13) predates this feature by many major versions. While TransferState (generic state serialization) exists in v9, there is no HTTP caching integration that uses it. The packages/c..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@9.1.13-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcb97bc8-e544-555a-b1b2-a150400b31e2",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 9.1.13-tuxcare.11 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@9.1.13-tuxcare.11"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4c8503a-cd6d-5d7c-be16-b04736674679",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 9.1.13-tuxcare.11 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@9.1.13-tuxcare.11"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/forms@9.1.13-tuxcare.11"
    }
  ]
}