{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:0e8767e0-2fa8-5c16-914f-57ae14cf529a",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/forms@15.0.3-tuxcare.3",
      "type": "library",
      "name": "@angular/forms",
      "version": "15.0.3-tuxcare.3",
      "purl": "pkg:npm/%40angular/forms@15.0.3-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:21b7ade7-1d19-5bcc-87e8-b2c34f7ed7a6",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 15.0.3-tuxcare.3 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae78991b-f6f3-5839-81d8-acd834e09719",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 15.0.3-tuxcare.3 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17aca8ec-e797-5377-92ac-2ff002dd74f0",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 15.0.3-tuxcare.3 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f272b58-78eb-5725-b19b-a4ad3e0636e2",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 15.0.3-tuxcare.3 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38be97ba-fe1e-50ed-a055-29e2803f9cdf",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 15.0.3-tuxcare.3 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fd14ece-ed61-57f5-8f3e-17c6da396d2e",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 15.0.3-tuxcare.3 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e940266-c663-5e42-bff5-4cdf2b1a1779",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 15.0.3-tuxcare.3 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92bdf495-c689-5b48-907d-3ce4ba292078",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 15.0.3-tuxcare.3 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72ede2a2-7f72-5131-999c-d3d5c2027a9b",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50170 does not affect version 15.0.3-tuxcare.3 of @angular/forms. not_affected \u2014 Angular 15.0.3-tuxcare.1 is NOT affected by CVE-2026-50170. The HTTP TransferCache feature that is vulnerable in later Angular versions (v16+) does not exist in this version. The vulnerable code (transfer_cache.ts, hasAuthHeaders(), shouldCacheRequest(), withHttpTransferCache, provideClientHydration) is absent from Angular 15.0.3."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a732526-3ea1-57e6-b0f0-a136c8d85ad6",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 15.0.3-tuxcare.3 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e48c321-77f0-5d6f-b02c-e8e85f08528b",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 15.0.3-tuxcare.3 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25762d84-6cb0-573e-a3f5-5f6f50d68dbe",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 15.0.3-tuxcare.3 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30408dba-54f4-598b-9e8a-f36bb45759fd",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 15.0.3-tuxcare.3 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee3719c0-3617-5763-bbb9-3d03e8559ade",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 15.0.3-tuxcare.3 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83c6529c-1ec0-513d-9a71-08a1be9d73a3",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 15.0.3-tuxcare.3 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d72ba683-3358-550c-9ab9-bbd009bdd292",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 15.0.3-tuxcare.3 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df9d1560-8ec2-5f7a-8dc8-aa72ce12d188",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 15.0.3-tuxcare.3 of @angular/forms. not_affected \u2014 Angular 15.0.3 is NOT AFFECTED by CVE-2026-54265. This version uses a different compiler architecture where two-way bindings desugar through the same code path as one-way bindings, both receiving identical security context resolution and sanitizer assignment. The vulnerable code (Ivy template pipeline with separate TwoWayProperty operation type) does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54bbcc9c-4b76-531f-91e3-ca7f4e2eeec4",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54266 does not affect version 15.0.3-tuxcare.3 of @angular/forms. not_affected \u2014 Angular v15.0.3-tuxcare.1 is NOT affected by CVE-2026-54266. The vulnerable HttpTransferCache feature with weak DJB2 hash-based cache keys does not exist in this version. This feature was introduced in Angular v16+. The target has no code path from HTTP request handling to the vulnerability's cache poisoning goal."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b64164e-51b0-54c3-923a-298b2b13f9bb",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 15.0.3-tuxcare.3 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@15.0.3-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59ee5d5f-f99c-5c89-ba03-123647b089b6",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 15.0.3-tuxcare.3 of @angular/forms."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@15.0.3-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/forms@15.0.3-tuxcare.3"
    }
  ]
}