{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:54d922b8-3487-5521-a504-5c3c632e426f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/angular@1.8.3-tuxcare.7",
      "type": "library",
      "name": "angular",
      "version": "1.8.3-tuxcare.7",
      "purl": "pkg:npm/angular@1.8.3-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:9de0046e-156f-5bb9-9809-d2708da41b66",
      "id": "CVE-2020-36048",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-36048 is fixed in version 1.8.3-tuxcare.7 of angular."
      },
      "affects": [
        {
          "ref": "pkg:npm/angular@1.8.3-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8da34fc8-ea14-5325-a608-cc92fc21ef23",
      "id": "CVE-2022-25844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-25844 is fixed in version 1.8.3-tuxcare.7 of angular."
      },
      "affects": [
        {
          "ref": "pkg:npm/angular@1.8.3-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1996aa1-ba7f-521a-9ad8-88e173302040",
      "id": "CVE-2022-25869",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-25869 is fixed in version 1.8.3-tuxcare.7 of angular."
      },
      "affects": [
        {
          "ref": "pkg:npm/angular@1.8.3-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b2235b3-ab44-5db5-92c3-2334054bec70",
      "id": "CVE-2022-41940",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-41940 is fixed in version 1.8.3-tuxcare.7 of angular."
      },
      "affects": [
        {
          "ref": "pkg:npm/angular@1.8.3-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a148009d-5253-5990-8c17-855fcf277bc4",
      "id": "CVE-2023-26116",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-26116 is fixed in version 1.8.3-tuxcare.7 of angular."
      },
      "affects": [
        {
          "ref": "pkg:npm/angular@1.8.3-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6d80a0e-4442-5718-8501-2794257ee8f4",
      "id": "CVE-2023-26117",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-26117 is fixed in version 1.8.3-tuxcare.7 of angular."
      },
      "affects": [
        {
          "ref": "pkg:npm/angular@1.8.3-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29bd9460-44d8-5fde-a5b5-3ab475059366",
      "id": "CVE-2023-26118",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-26118 is fixed in version 1.8.3-tuxcare.7 of angular."
      },
      "affects": [
        {
          "ref": "pkg:npm/angular@1.8.3-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9b20635-bd40-5d4c-8e95-6ae6081db22c",
      "id": "CVE-2024-21490",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-21490 is fixed in version 1.8.3-tuxcare.7 of angular."
      },
      "affects": [
        {
          "ref": "pkg:npm/angular@1.8.3-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db7d0c5f-5953-5cdf-a07f-55165e905d1b",
      "id": "CVE-2024-8372",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-8372 is fixed in version 1.8.3-tuxcare.7 of angular."
      },
      "affects": [
        {
          "ref": "pkg:npm/angular@1.8.3-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c75de785-8d07-5e12-b4eb-e301c263b16a",
      "id": "CVE-2024-8373",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-8373 is fixed in version 1.8.3-tuxcare.7 of angular."
      },
      "affects": [
        {
          "ref": "pkg:npm/angular@1.8.3-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a294f6e-9911-5b14-9bd8-ba67ec7ace93",
      "id": "CVE-2025-0716",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-0716 is fixed in version 1.8.3-tuxcare.7 of angular."
      },
      "affects": [
        {
          "ref": "pkg:npm/angular@1.8.3-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95bcbaed-9194-56f0-9887-7e798c402cf8",
      "id": "CVE-2025-2336",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-2336 is fixed in version 1.8.3-tuxcare.7 of angular."
      },
      "affects": [
        {
          "ref": "pkg:npm/angular@1.8.3-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0cae2456-5cec-5d1a-be04-e45b68a17c48",
      "id": "CVE-2025-4690",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-4690 is fixed in version 1.8.3-tuxcare.7 of angular."
      },
      "affects": [
        {
          "ref": "pkg:npm/angular@1.8.3-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1dcd2d9e-4508-50ae-aac8-b80a6b99b0bd",
      "id": "CVE-2026-11998",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-11998 does not affect version 1.8.3-tuxcare.7 of angular. already_fixed \u2014 AngularJS 1.8.3 already contains the fix for CVE-2026-11998. The adjustMatcher function in src/ng/sce.js enforces full URL matching by wrapping all regex matchers with '^' and '$' anchors, preventing the partial match vulnerability described in the CVE."
      },
      "affects": [
        {
          "ref": "pkg:npm/angular@1.8.3-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/angular@1.8.3-tuxcare.7"
    }
  ]
}