{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:8c374b71-c288-5d81-8a72-48aa849806ef",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/animations",
      "purl": "pkg:npm/%40angular/animations@18.2.14-tuxcare.8",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/animations@18.2.14-tuxcare.8",
      "version": "18.2.14-tuxcare.8",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:0ffbac4f-9480-53ce-8850-27245fb48d5d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.2.14-tuxcare.8 of @angular/animations."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:4a84be2d-b3da-5f02-962c-6668b87627be",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 18.2.14-tuxcare.8 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:c2aa9263-f7db-550d-89ed-bea0d1ab97f3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 18.2.14-tuxcare.8 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:8c8cca40-2674-5fff-8995-9629ea4c5276",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 18.2.14-tuxcare.8 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:7c173385-ab56-54a9-ab2d-83e21fda4be1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 18.2.14-tuxcare.8 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:a9640938-1a4e-5ce4-8dc3-da10892ce1bc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 18.2.14-tuxcare.8 of @angular/animations, and is fixed in 18.2.14-tuxcare.10."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:9d8cbfc2-a931-5d0c-9d45-a3fd4f39060a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 18.2.14-tuxcare.8 of @angular/animations, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:73df40a1-0dc7-5455-a119-2bc80f8509ae",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 18.2.14-tuxcare.8 of @angular/animations, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:6af10d1e-405f-58ba-8d6b-1e1604a2fcd9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 18.2.14-tuxcare.8 of @angular/animations, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:9b1807f6-dcd8-56de-81ae-e39e4162646e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 18.2.14-tuxcare.8 of @angular/animations, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:2dc77fc3-54bd-5205-ac55-e127aaa9b27b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 18.2.14-tuxcare.8 of @angular/animations, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:87fdaabf-c4e4-5b11-aa5e-987221ffb62b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 18.2.14-tuxcare.8 of @angular/animations, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:e94d168c-3403-5461-b784-cc7f862a2577",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 18.2.14-tuxcare.8 of @angular/animations, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:d19683ce-ed01-5237-a5ee-21935f4ef9f7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 18.2.14-tuxcare.8 of @angular/animations, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:50087916-8c9b-5a80-9932-077bae08838f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 18.2.14-tuxcare.8 of @angular/animations, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:75edfe53-2baf-5f9a-95f3-5ae32e5691c8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 18.2.14-tuxcare.8 of @angular/animations, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:0ab32b2e-81ea-5f5d-a82f-957174965952",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 18.2.14-tuxcare.8 of @angular/animations, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:524a46ad-41dd-53d1-8ed6-4c3c751b5d71",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 18.2.14-tuxcare.8 of @angular/animations, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:c3f8c121-2c01-54db-b278-eff4dbbe3da7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 18.2.14-tuxcare.8 of @angular/animations, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:c288f0bf-6955-50a9-ab46-6edd0949a1df",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 18.2.14-tuxcare.8 of @angular/animations, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:ed10a385-8661-539d-a641-ba0a3cfc8211",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 18.2.14-tuxcare.8 of @angular/animations, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:94037518-6334-5ef4-a614-4cd2d1155694",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 18.2.14-tuxcare.8 of @angular/animations, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:02570bf5-d394-5aa7-b86c-402b0e96c677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 18.2.14-tuxcare.8 of @angular/animations, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:f15a966b-c22d-58a1-9c7f-28c459072340",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 18.2.14-tuxcare.8 of @angular/animations. not_affected \u2014 The target version 18.2.14-tuxcare.13 is NOT affected by CVE-2026-88056. The vulnerable code pattern (calling String.prototype.trim() on URL strings before resolution) was never present in this version. The target uses a refactored parseUrl() implementation introduced via commit 49a60f6045 (May 2026) that correctly handles Unicode whitespace by percent-encoding it rather than stripping it, main...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:ac40d02e-5063-50f5-bb4b-be7071d95ac1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 18.2.14-tuxcare.8 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:1f9058e9-5d7b-52f9-8412-d71581403c1f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 18.2.14-tuxcare.8 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:e1f29cfd-51ae-5a64-9849-a0fbedf624f4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 18.2.14-tuxcare.8 of @angular/animations."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/animations@18.2.14-tuxcare.8"
    }
  ]
}