{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:57693ddb-e6aa-51c2-b92a-cf28c5b5d19a",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/platform-server@15.2.9-tuxcare.2",
      "type": "library",
      "name": "@angular/platform-server",
      "version": "15.2.9-tuxcare.2",
      "purl": "pkg:npm/%40angular/platform-server@15.2.9-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:cf6cc971-a0e7-5c7e-957d-96f26f6bda54",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 15.2.9-tuxcare.2 of @angular/platform-server."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@15.2.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e0eae9f-4354-5420-8cf8-79cfb623d2ba",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 15.2.9-tuxcare.2 of @angular/platform-server."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@15.2.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1de306c-83b2-5ecb-a629-978014a44bf1",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 15.2.9-tuxcare.2 of @angular/platform-server."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@15.2.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e29dcd8-a369-5a3a-82a5-b7b02b99b89d",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 15.2.9-tuxcare.2 of @angular/platform-server."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@15.2.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed7cea89-46ba-5743-b766-d18b62a52572",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41423 does not affect version 15.2.9-tuxcare.2 of @angular/platform-server. not_affected \u2014 Angular 15.2.9 is not affected by CVE-2026-41423. The SSRF vulnerability via protocol-relative URLs was introduced in Angular 17.0.0 when the codebase switched from Node.js url.parse to WHATWG URL API. Angular 15.2.9 still uses the legacy Node.js url.parse which treats protocol-relative URLs ('//evil.com') as pathnames, not hostname overrides, preventing the SSRF attack vector."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@15.2.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:432b1573-0f0b-5e89-a596-8577a47d9323",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 15.2.9-tuxcare.2 of @angular/platform-server."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@15.2.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc2b59d9-7c92-5eda-b005-62635ecef22c",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 15.2.9-tuxcare.2 of @angular/platform-server."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@15.2.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5b6bf1e-df66-58b2-8051-b6249a69b48f",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 15.2.9-tuxcare.2 of @angular/platform-server."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@15.2.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25ef98ad-884b-5df0-b1d6-7e5f1bc2abb0",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50170 does not affect version 15.2.9-tuxcare.2 of @angular/platform-server. not_affected \u2014 no evidence captured"
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@15.2.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ca4452e-90ac-547e-83b2-ea464fe22917",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 15.2.9-tuxcare.2 of @angular/platform-server."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@15.2.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6bda1c4c-20a6-5606-8eae-8765aab2b417",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 15.2.9-tuxcare.2 of @angular/platform-server."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@15.2.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d721498-f446-556b-88dc-37c26b7b4bdc",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 15.2.9-tuxcare.2 of @angular/platform-server."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@15.2.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1aef3697-8ad2-5695-89dc-f728c9357173",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 15.2.9-tuxcare.2 of @angular/platform-server."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@15.2.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a442de9-e12b-5aa7-af9d-f040d4585ef8",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 15.2.9-tuxcare.2 of @angular/platform-server."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@15.2.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6d685aa-cfb8-5fdd-a7ab-4c17bb146c6f",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 15.2.9-tuxcare.2 of @angular/platform-server."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@15.2.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:606ec3ae-5ac7-509e-81eb-bcec2a0e4882",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 15.2.9-tuxcare.2 of @angular/platform-server."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@15.2.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e09092b1-dbf7-5e57-bd3e-9a90947f2c57",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 15.2.9-tuxcare.2 of @angular/platform-server. not_affected \u2014 Angular 15.2.9-tuxcare.1 is not affected by CVE-2026-54265. The vulnerability requires the new Ivy compiler 'pipeline' architecture with the TwoWayProperty IR operation, which was introduced in Angular 16+. Angular 15.2.9 uses the older compiler architecture where two-way bindings are desugared into separate property and event bindings, causing them to automatically receive the same sanitizatio..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@15.2.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf7d07e2-406c-5259-bfcf-8cf3aae36d45",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54266 does not affect version 15.2.9-tuxcare.2 of @angular/platform-server. not_affected \u2014 Angular 15.2.9 is not affected by CVE-2026-54266. The vulnerable HttpTransferCache feature does not exist in this version - it was introduced in Angular v16+. Without this feature, there is no code that hashes HTTP request properties for cache key generation, so the hash collision vulnerability cannot manifest."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@15.2.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82f08c7e-8b2a-5a51-813b-267daae0d1d8",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 15.2.9-tuxcare.2 of @angular/platform-server."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@15.2.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee9a2711-5816-50ad-8830-9a7ea1e5ea86",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 15.2.9-tuxcare.2 of @angular/platform-server."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@15.2.9-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/platform-server@15.2.9-tuxcare.2"
    }
  ]
}