{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:0d961e2f-7d20-5f9c-bacc-a770a436d680",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/animations",
      "purl": "pkg:npm/%40angular/animations@8.2.14-tuxcare.8",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.8",
      "version": "8.2.14-tuxcare.8",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:b57480cb-83de-52f2-a9f1-c572bb30f2ed",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 8.2.14-tuxcare.8 of @angular/animations."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:db4f156d-9813-5deb-b6e5-401fcac6c78a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 8.2.14-tuxcare.8 of @angular/animations, and is fixed in 8.2.14-tuxcare.10."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:6c4612ce-9881-5d26-af2a-f4842a689524",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 8.2.14-tuxcare.8 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:4ca717ae-aab7-5eaa-8ddc-fed904cc3ee1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 8.2.14-tuxcare.8 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:b7f104e9-ed74-5abd-93c4-fe22e4047ed7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 8.2.14-tuxcare.8 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:39e14812-eca3-522d-b3a2-2ceb0036cc6e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 8.2.14-tuxcare.8 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:d8dce0c4-837e-5284-864e-41916667b4ba",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 8.2.14-tuxcare.8 of @angular/animations, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:ac2b4014-bd65-5ec5-99fb-af3e34729099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 8.2.14-tuxcare.8 of @angular/animations, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:a541bd06-b500-58d7-9ff8-5f7913b3cf4a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 8.2.14-tuxcare.8 of @angular/animations, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:775a91ef-8b3d-50f0-b1f1-b9f822ba1d01",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 8.2.14-tuxcare.8 of @angular/animations, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:9bd90685-8fd5-5ea9-ae29-57e0baa962df",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 8.2.14-tuxcare.8 of @angular/animations, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:47e569f7-ab3d-5c15-8cda-95978d59e604",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 8.2.14-tuxcare.8 of @angular/animations, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:d6d8bebe-88bf-58a1-96ff-fda5c26c6886",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 8.2.14-tuxcare.8 of @angular/animations, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:541e2ee5-b912-5918-841e-0aa2215b4de9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 8.2.14-tuxcare.8 of @angular/animations, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:95ee0d24-a4b1-565c-9b3b-3cd30a875b50",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 8.2.14-tuxcare.8 of @angular/animations, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:c54f54fa-3732-50d0-808e-74cb0f8cedac",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 8.2.14-tuxcare.8 of @angular/animations, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:49b77929-0d19-5ea6-ab45-7a9f0cafb333",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 8.2.14-tuxcare.8 of @angular/animations, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:c6a6cc47-a328-536f-9698-8bca3d8bc78e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 8.2.14-tuxcare.8 of @angular/animations, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:a34b6a87-79d3-55f4-b113-bc2745f947b4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 8.2.14-tuxcare.8 of @angular/animations, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:78750e7c-0fb0-594d-a86c-a1aab05ca9fc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 8.2.14-tuxcare.8 of @angular/animations, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:e0bac20f-8b1b-5850-a22d-212c72e072a2",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 8.2.14-tuxcare.8 of @angular/animations. not_affected \u2014 Angular 8.2.14 is NOT affected by CVE-2026-68945. The vulnerability exists in HttpTransferCache, a feature that automatically caches HTTP requests during SSR for client hydration. HttpTransferCache was introduced in Angular v16+ and does not exist in version 8.2.14. This version has only a manual TransferState key-value store with no automatic HttpClient integration, and no HTTP caching mechani...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:1940c8fc-bfc6-5dba-8585-fc6d794a54f4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 8.2.14-tuxcare.8 of @angular/animations, and is fixed in 8.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:001b9c34-415e-51c6-82fd-2f5753521a49",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 8.2.14-tuxcare.8 of @angular/animations, and is fixed in 8.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:ebfdd7d0-31a7-532d-b489-e27d2b844f95",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 8.2.14-tuxcare.8 of @angular/animations. not_affected \u2014 Angular 8.2.14 is NOT AFFECTED by CVE-2026-88056. The vulnerability requires a sophisticated URL resolution utility (`parseUrl` in `packages/platform-server/src/url.ts`) that calls `String.prototype.trim()` to strip Unicode whitespace, creating a discrepancy with WHATWG URL validation. This architecture was introduced in Angular v12+ (circa 2026 as TuxCare backports). Angular 8.2.14 (released N...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:17805d12-cfbd-5f31-8f1e-7d66b8176d0c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 8.2.14-tuxcare.8 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:fd32b8da-c4df-5d0d-990d-526c8e1c8170",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 8.2.14-tuxcare.8 of @angular/animations. not_affected \u2014 Angular v8.2.14 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, provideClientHydration(), and withRequestsMadeViaParent() \u2014 all features that do not exist in this version. These features were introduced in Angular v16 (per patches/CVE-2026-50170.patch and patches/CVE-2026-54266.patch). The target uses the legacy NgModule-based HttpClientModule without automatic ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:263636b3-a9a5-5b3e-aea8-7fa365fa782c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 8.2.14-tuxcare.8 of @angular/animations."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.8"
    }
  ]
}