{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:48ee5a97-830a-5966-bae3-7bf02ca41c3b",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/animations",
      "purl": "pkg:npm/%40angular/animations@8.2.14-tuxcare.3",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.3",
      "version": "8.2.14-tuxcare.3",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:e69e444a-7af3-57c9-82f6-09dd80cc00a7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-4231 affects version 8.2.14-tuxcare.3 of @angular/animations, and is fixed in 8.2.14-tuxcare.5."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:f42d340d-e3ac-53cd-9489-19d5f0991130",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 8.2.14-tuxcare.3 of @angular/animations, and is fixed in 8.2.14-tuxcare.10."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:87fe00b4-e395-5390-92b2-07664e08bd70",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66412 affects version 8.2.14-tuxcare.3 of @angular/animations, and is fixed in 8.2.14-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:e484fa7e-a9ad-57f1-b065-5296c0095014",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 8.2.14-tuxcare.3 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:1bc2b640-a59c-5d34-ba68-2966432c2504",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 8.2.14-tuxcare.3 of @angular/animations, and is fixed in 8.2.14-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:4df27c44-4bab-57b1-bd3f-bebd541a1b72",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 8.2.14-tuxcare.3 of @angular/animations, and is fixed in 8.2.14-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:1390553b-1ef2-5bfc-905e-ee17a9549436",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 8.2.14-tuxcare.3 of @angular/animations, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:d5abe269-7e01-50ea-bfbe-2cf440fefc20",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 8.2.14-tuxcare.3 of @angular/animations, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:924e04e0-463b-5084-9688-0704a6c32028",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 8.2.14-tuxcare.3 of @angular/animations, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:9ea9300a-bbf4-531d-87f7-fd78a59f2880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 8.2.14-tuxcare.3 of @angular/animations, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:ff353743-ba3f-5401-b4fd-f0b96d4d6951",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 8.2.14-tuxcare.3 of @angular/animations, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:40cd26d5-1771-5c30-9f47-f89604e3a7c8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 8.2.14-tuxcare.3 of @angular/animations, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:d6272ca4-b6b3-56c5-877d-aa3a80e8b618",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 8.2.14-tuxcare.3 of @angular/animations, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:15cce39f-37b2-5fab-acf8-e7755f99cef0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 8.2.14-tuxcare.3 of @angular/animations, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:c461f29a-bcc6-56ec-bcde-81494ea688f2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 8.2.14-tuxcare.3 of @angular/animations, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:fcbfa383-5b4a-50a8-be41-bdd38003def1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 8.2.14-tuxcare.3 of @angular/animations, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:c56ec42b-5c9d-535a-8201-b573411214bd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 8.2.14-tuxcare.3 of @angular/animations, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:9c842593-97c1-5e30-a30f-788a65d22f99",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 8.2.14-tuxcare.3 of @angular/animations, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:637809ab-0b76-5e75-8719-5c53559bd21b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 8.2.14-tuxcare.3 of @angular/animations, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:0a99da21-bb5b-568f-a41a-665e9b3c9079",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 8.2.14-tuxcare.3 of @angular/animations, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:d1ddfad9-7e50-50b0-befa-66b17c54aa7e",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 8.2.14-tuxcare.3 of @angular/animations. not_affected \u2014 Angular 8.2.14 is NOT affected by CVE-2026-68945. The vulnerability exists in HttpTransferCache, a feature that automatically caches HTTP requests during SSR for client hydration. HttpTransferCache was introduced in Angular v16+ and does not exist in version 8.2.14. This version has only a manual TransferState key-value store with no automatic HttpClient integration, and no HTTP caching mechani...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:fd8495aa-cc2e-538d-90d6-542dd1001366",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 8.2.14-tuxcare.3 of @angular/animations, and is fixed in 8.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:74fe3049-dd8a-594a-9457-f3e141c144d1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 8.2.14-tuxcare.3 of @angular/animations, and is fixed in 8.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:dbfacea9-6118-5960-a815-6a9889d111fe",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 8.2.14-tuxcare.3 of @angular/animations. not_affected \u2014 Angular 8.2.14 is NOT AFFECTED by CVE-2026-88056. The vulnerability requires a sophisticated URL resolution utility (`parseUrl` in `packages/platform-server/src/url.ts`) that calls `String.prototype.trim()` to strip Unicode whitespace, creating a discrepancy with WHATWG URL validation. This architecture was introduced in Angular v12+ (circa 2026 as TuxCare backports). Angular 8.2.14 (released N...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:bc504e6d-c88f-5e02-a405-242caf3d7d1b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 8.2.14-tuxcare.3 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:920433d3-1216-5d21-8a5c-fe29c829a06f",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 8.2.14-tuxcare.3 of @angular/animations. not_affected \u2014 Angular v8.2.14 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, provideClientHydration(), and withRequestsMadeViaParent() \u2014 all features that do not exist in this version. These features were introduced in Angular v16 (per patches/CVE-2026-50170.patch and patches/CVE-2026-54266.patch). The target uses the legacy NgModule-based HttpClientModule without automatic ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:72408451-12f3-51fb-8ae7-902244c20dd6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 8.2.14-tuxcare.3 of @angular/animations."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.3"
    }
  ]
}