{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3ed2b325-dfcb-5000-ab7e-21522311668a",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.2",
      "type": "library",
      "name": "@angular/service-worker",
      "version": "15.2.2-tuxcare.2",
      "purl": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:7c88a37f-d9d7-59ea-9459-96ef5e343002",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 15.2.2-tuxcare.2 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69e0afff-286a-5015-b054-553a041032d3",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 15.2.2-tuxcare.2 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9518ddac-333f-5f79-8b65-36f82f1e1bcb",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 15.2.2-tuxcare.2 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d51bd76-5c3f-558d-8471-1a3467ca0004",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 15.2.2-tuxcare.2 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e56d779f-e637-54a5-8295-1997532b0c33",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41423 does not affect version 15.2.2-tuxcare.2 of @angular/service-worker. not_affected \u2014 The target repository (Angular 15.2.2-tuxcare.1) is NOT affected by CVE-2026-41423. While the target lacks the specific fix from the upstream patch, it uses a fundamentally different URL parsing mechanism (Node.js legacy url.parse()) that does not exhibit the WHATWG URL specification behavior exploited in the vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b960d602-cde8-593f-8f64-862c1033bf17",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 15.2.2-tuxcare.2 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:533e3608-7c99-5169-a265-e2eb9dbd0d26",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 15.2.2-tuxcare.2 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b243e0c7-a639-59c6-95b9-69496038335b",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 15.2.2-tuxcare.2 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c67601c-6f9a-5109-a0d6-5c20a11fa1a6",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50170 does not affect version 15.2.2-tuxcare.2 of @angular/service-worker. not_affected \u2014 Angular v15.2.2 is not affected by CVE-2026-50170. The HTTP TransferCache feature, which is the subject of the vulnerability, was introduced in Angular v16.0.0 (March 2023). The target repository version (15.2.2-tuxcare.1) predates this feature entirely and does not contain the vulnerable code path."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:047c1a35-f309-5c68-854f-9d36c28525b5",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 15.2.2-tuxcare.2 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ade6247-d697-5408-b183-faf858e4ea2e",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 15.2.2-tuxcare.2 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b615bd15-4bea-5abc-9edc-5428f3f79292",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 15.2.2-tuxcare.2 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e7c5c2d-7830-5cee-880a-b985b3f85968",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 15.2.2-tuxcare.2 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0b52742-de12-571f-8999-5869a55aa05f",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 15.2.2-tuxcare.2 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5837ca4e-b293-5612-8c4a-82a6e462f7bb",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 15.2.2-tuxcare.2 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c482bd83-b9c5-5fa0-9539-bdd258a72294",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 15.2.2-tuxcare.2 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b26bffc-80bb-5ad3-a1f0-622e812fd342",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 15.2.2-tuxcare.2 of @angular/service-worker. not_affected \u2014 Angular v15.2.2 does not contain the vulnerable code path. The CVE-2026-54265 vulnerability affects the template pipeline's resolve_sanitizers.ts (TwoWayProperty operation), which does not exist in v15.2.2. This version uses TemplateDefinitionBuilder where two-way bindings desugar to regular property bindings that receive identical sanitization as one-way bindings."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d94a958-2ef2-58bd-b359-99fbdf27f146",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54266 does not affect version 15.2.2-tuxcare.2 of @angular/service-worker. not_affected \u2014 Angular 15.2.2 is not affected by CVE-2026-54266. The vulnerable HttpTransferCache feature was introduced in Angular 16.0.0 (May 2023), after this version was released (March 2023). The target codebase does not contain the transfer_cache.ts module, HttpTransferCache API, or any HTTP response caching mechanism that uses hash-based cache keys."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e0d14b8-199a-5435-b116-82e7a1437287",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 15.2.2-tuxcare.2 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f4177f6-45f8-507f-bfc9-e1a22c22aa2a",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 15.2.2-tuxcare.2 of @angular/service-worker."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/service-worker@15.2.2-tuxcare.2"
    }
  ]
}