{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:66ed6c72-ee16-5004-b0a1-d6c8b50ca626",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/animations",
      "purl": "pkg:npm/%40angular/animations@16.2.12-tuxcare.2",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/animations@16.2.12-tuxcare.2",
      "version": "16.2.12-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ad6ce6a4-b9f2-519b-8482-d02c08c5251b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 16.2.12-tuxcare.2 of @angular/animations."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2e2ccbc4-a2da-5f5d-9965-f5dede4c1876",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 16.2.12-tuxcare.2 of @angular/animations."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b812d38e-df9e-58df-8aa1-4695004afe26",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66412 affects version 16.2.12-tuxcare.2 of @angular/animations, and is fixed in 16.2.12-tuxcare.5."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6368f3d5-5721-5f9b-9ef8-c501ae93aa42",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22610 affects version 16.2.12-tuxcare.2 of @angular/animations, and is fixed in 16.2.12-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:fb32f8fe-bc2b-591a-b7ca-fc43e814ead1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 16.2.12-tuxcare.2 of @angular/animations, and is fixed in 16.2.12-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5220f1d7-a294-5f6b-89c9-c8503d3fc0fd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 16.2.12-tuxcare.2 of @angular/animations, and is fixed in 16.2.12-tuxcare.10."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ddc725d4-9f32-504a-ac56-7b43d1157088",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 16.2.12-tuxcare.2 of @angular/animations, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:31450942-9691-58f7-a9fc-ed9b462f7cd1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 16.2.12-tuxcare.2 of @angular/animations, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:44cb21f2-e804-5c4a-a59a-97b17aecdbee",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 16.2.12-tuxcare.2 of @angular/animations, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:87ddf73b-7738-59cb-80f0-ec2b1ec61e9f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 16.2.12-tuxcare.2 of @angular/animations, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4e494b51-048b-5836-9e0f-4c41dd20e820",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 16.2.12-tuxcare.2 of @angular/animations, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6e9dc556-dc9e-55ad-91c2-2c982b734286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 16.2.12-tuxcare.2 of @angular/animations, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9b5c112e-2b6f-5b59-9e3b-b631011f1ae4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 16.2.12-tuxcare.2 of @angular/animations, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4feaee8e-0466-5d51-b48b-d76f7e87e81f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 16.2.12-tuxcare.2 of @angular/animations, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6293bb91-66c4-5a17-9ed7-84fa4313e3d4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 16.2.12-tuxcare.2 of @angular/animations, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8911e47e-97ca-5d93-9d06-fd735b76527f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 16.2.12-tuxcare.2 of @angular/animations, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:54faa9ef-ace2-5132-bb73-15185e9eecb0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 16.2.12-tuxcare.2 of @angular/animations, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b7d98150-015b-5235-8a9e-e051373872df",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 16.2.12-tuxcare.2 of @angular/animations, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:15a70553-49df-58d9-864d-d0bdb2e2f16b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 16.2.12-tuxcare.2 of @angular/animations, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7c974448-944c-506b-b1cc-2b11443a0335",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 16.2.12-tuxcare.2 of @angular/animations, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3ee05d3d-422e-5d6b-890b-4bda8994e4cb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 16.2.12-tuxcare.2 of @angular/animations, and is fixed in 16.2.12-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3d34f49d-3797-5a16-9a0c-a130b1a168e7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 16.2.12-tuxcare.2 of @angular/animations, and is fixed in 16.2.12-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2b482774-ec30-5066-b89f-d9dea3a991b0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 16.2.12-tuxcare.2 of @angular/animations, and is fixed in 16.2.12-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:50dcc6d8-5a79-50d3-b699-50c1f6c7ae0a",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 16.2.12-tuxcare.2 of @angular/animations. not_affected \u2014 CVE-2026-88056 affects Angular versions 20.3.x, 21.2.x, and 22.x where a refactored URL parsing utility added String.prototype.trim() that strips Unicode whitespace, enabling SSRF bypasses. The target (Angular 16.2.12-tuxcare.12) is based on Angular 16.2.x architecture, which predates the vulnerable code pattern entirely. TuxCare created url.ts fresh on June 24, 2026 for CVE-2026-50168, modelin...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4caf44b0-a62a-5cca-b40d-b0006fca9244",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 16.2.12-tuxcare.2 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:446f849b-9693-58df-b9df-cc3df291e200",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 16.2.12-tuxcare.2 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.12-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1cd0a524-cec3-5a4d-9331-fc4615913f1d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 16.2.12-tuxcare.2 of @angular/animations."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/animations@16.2.12-tuxcare.2"
    }
  ]
}