{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c2bf3310-a0a8-5d71-b2da-9d782183a139",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/platform-browser-dynamic@15.0.3-tuxcare.3",
      "type": "library",
      "name": "@angular/platform-browser-dynamic",
      "version": "15.0.3-tuxcare.3",
      "purl": "pkg:npm/%40angular/platform-browser-dynamic@15.0.3-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:98255dd5-c06c-547d-a519-f8b5861aa9e9",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 15.0.3-tuxcare.3 of @angular/platform-browser-dynamic."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:065c34bb-352d-5977-bfc7-1a34bd954915",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 15.0.3-tuxcare.3 of @angular/platform-browser-dynamic."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b115b953-b383-51a9-8760-8a97e141ea45",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 15.0.3-tuxcare.3 of @angular/platform-browser-dynamic."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6161f502-af43-53d8-97fa-284056e492c1",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 15.0.3-tuxcare.3 of @angular/platform-browser-dynamic."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:994e81ee-c149-5780-914b-6d83e6ec0814",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 15.0.3-tuxcare.3 of @angular/platform-browser-dynamic."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ffcff8d-b794-5082-b258-57844e765ed7",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 15.0.3-tuxcare.3 of @angular/platform-browser-dynamic."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:decbf411-a0bd-5cdd-abd8-2b52e21bb8b9",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 15.0.3-tuxcare.3 of @angular/platform-browser-dynamic."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e09ee78-22c6-5126-943e-30a10ef267d2",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 15.0.3-tuxcare.3 of @angular/platform-browser-dynamic."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec265d72-aac0-5a96-b59d-6f321c52c7a0",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50170 does not affect version 15.0.3-tuxcare.3 of @angular/platform-browser-dynamic. not_affected \u2014 Angular 15.0.3-tuxcare.1 is NOT affected by CVE-2026-50170. The HTTP TransferCache feature that is vulnerable in later Angular versions (v16+) does not exist in this version. The vulnerable code (transfer_cache.ts, hasAuthHeaders(), shouldCacheRequest(), withHttpTransferCache, provideClientHydration) is absent from Angular 15.0.3."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68cde3e6-ba10-5058-8984-9c64f733b731",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 15.0.3-tuxcare.3 of @angular/platform-browser-dynamic."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f0bd642-99ae-5cf2-94f8-cebff3a2e54b",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 15.0.3-tuxcare.3 of @angular/platform-browser-dynamic."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d023d587-6aef-5eb9-ba44-f8e3fee7399f",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 15.0.3-tuxcare.3 of @angular/platform-browser-dynamic."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b94c6f8-82d9-50d4-a811-f5c36d5306ca",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 15.0.3-tuxcare.3 of @angular/platform-browser-dynamic."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01d46c45-7924-588f-8dc9-b314142e5f98",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 15.0.3-tuxcare.3 of @angular/platform-browser-dynamic."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70920aef-81bd-5217-bcd9-30539979a40f",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 15.0.3-tuxcare.3 of @angular/platform-browser-dynamic."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e6c3c59-1b06-56ae-895c-76f084c5ef41",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 15.0.3-tuxcare.3 of @angular/platform-browser-dynamic."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:270f8f19-3cfe-5a8f-a264-40ed73509030",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 15.0.3-tuxcare.3 of @angular/platform-browser-dynamic. not_affected \u2014 Angular 15.0.3 is NOT AFFECTED by CVE-2026-54265. This version uses a different compiler architecture where two-way bindings desugar through the same code path as one-way bindings, both receiving identical security context resolution and sanitizer assignment. The vulnerable code (Ivy template pipeline with separate TwoWayProperty operation type) does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56b4ed94-3756-5668-99a6-f5007da34e7e",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54266 does not affect version 15.0.3-tuxcare.3 of @angular/platform-browser-dynamic. not_affected \u2014 Angular v15.0.3-tuxcare.1 is NOT affected by CVE-2026-54266. The vulnerable HttpTransferCache feature with weak DJB2 hash-based cache keys does not exist in this version. This feature was introduced in Angular v16+. The target has no code path from HTTP request handling to the vulnerability's cache poisoning goal."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7227f7d-ea15-5e9a-b823-bfc70e95ef3b",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 15.0.3-tuxcare.3 of @angular/platform-browser-dynamic."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1171d730-f347-5c23-9f6d-266edd7cab98",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 15.0.3-tuxcare.3 of @angular/platform-browser-dynamic."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@15.0.3-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/platform-browser-dynamic@15.0.3-tuxcare.3"
    }
  ]
}