{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:29c9ba1d-442f-552f-be0d-88ac1883aa1c",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/bazel",
      "purl": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.1",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.1",
      "version": "17.1.0-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:df37fdcb-f13b-5106-8cbd-addacd428875",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59052 affects version 17.1.0-tuxcare.1 of @angular/bazel, and is fixed in 17.1.0-tuxcare.2."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:78be816d-ef95-5a97-859b-7e5fae005b24",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.1.0-tuxcare.1 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e6cb370d-7506-59e8-b328-f862728befe4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66412 affects version 17.1.0-tuxcare.1 of @angular/bazel, and is fixed in 17.1.0-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9dae1399-f4fd-5244-80ca-947922b76590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22610 affects version 17.1.0-tuxcare.1 of @angular/bazel, and is fixed in 17.1.0-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:91d2c272-c17a-584a-8577-f39074cec6c1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 17.1.0-tuxcare.1 of @angular/bazel, and is fixed in 17.1.0-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d030d91e-c707-5458-b1af-7ca2ec85b4b0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32635 affects version 17.1.0-tuxcare.1 of @angular/bazel, and is fixed in 17.1.0-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d222045d-ca21-55e9-83d1-c86ce71f0c24",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41423 affects version 17.1.0-tuxcare.1 of @angular/bazel, and is fixed in 17.1.0-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0a2b400f-f595-5f6e-9f4b-30a7b17fb827",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 17.1.0-tuxcare.1 of @angular/bazel, and is fixed in 17.1.0-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:98eea847-9fbd-5ae8-803d-e0a5a5a07285",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 17.1.0-tuxcare.1 of @angular/bazel, and is fixed in 17.1.0-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ec4cf07b-054e-5bdb-8319-09f5a2e08780",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 17.1.0-tuxcare.1 of @angular/bazel, and is fixed in 17.1.0-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:28501e96-1fb5-5580-a5b8-e83073c68c2d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 17.1.0-tuxcare.1 of @angular/bazel, and is fixed in 17.1.0-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ab56fe2e-32c3-513d-b6a8-d1faba696011",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 17.1.0-tuxcare.1 of @angular/bazel, and is fixed in 17.1.0-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:09f72395-f4ec-5eb9-aea8-7bad84661bb3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 17.1.0-tuxcare.1 of @angular/bazel, and is fixed in 17.1.0-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c6a7b7e0-086d-56a1-99b0-caf87cc8c510",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 17.1.0-tuxcare.1 of @angular/bazel, and is fixed in 17.1.0-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:207898ef-8993-59df-a189-67bbec7cafaa",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 17.1.0-tuxcare.1 of @angular/bazel, and is fixed in 17.1.0-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7328a1be-83ea-5d05-b732-54229f0d2814",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 17.1.0-tuxcare.1 of @angular/bazel, and is fixed in 17.1.0-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f1cb8c4c-4df6-5fcd-a45f-ba5e36fba8c9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 17.1.0-tuxcare.1 of @angular/bazel, and is fixed in 17.1.0-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f5aa1130-7184-5b9c-8434-d28e02c78337",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 17.1.0-tuxcare.1 of @angular/bazel, and is fixed in 17.1.0-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:53b9dfee-8706-5b95-8edc-cd8d463b85dd",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 17.1.0-tuxcare.1 of @angular/bazel. not_affected \u2014 Angular v17.1.0 does not have the TwoWayProperty IR operation that is the subject of CVE-2026-54265. Two-way bindings are desugared into separate property and event bindings before template pipeline processing, with the property half using the same parsePropertyBinding() code path as one-way property bindings, which are properly sanitized.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2907f7a5-e6f4-56c8-abe8-0135f845911c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 17.1.0-tuxcare.1 of @angular/bazel, and is fixed in 17.1.0-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a12f1444-506c-5d17-93d5-ef375b6d0884",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 17.1.0-tuxcare.1 of @angular/bazel, and is fixed in 17.1.0-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f0fa9ada-c304-5d85-a08e-846c0480bbe7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 17.1.0-tuxcare.1 of @angular/bazel, and is fixed in 17.1.0-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:53d1ae8d-a1d0-534d-b984-16197ae103bb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 17.1.0-tuxcare.1 of @angular/bazel, and is fixed in 17.1.0-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ef6e8b2c-9223-5ede-bd75-cf6aaa9860c0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 17.1.0-tuxcare.1 of @angular/bazel, and is fixed in 17.1.0-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:57c57c24-5279-53ab-9e8f-d3d28f0819af",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 17.1.0-tuxcare.1 of @angular/bazel, and is fixed in 17.1.0-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7d08e984-1152-5ad1-a128-7162f30e80b1",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.1.0-tuxcare.1 of @angular/bazel. not_affected \u2014 Angular 17.1.0 was never vulnerable to CVE-2026-88056. The vulnerability exists only in newer Angular versions (v18+, v19+, v20+ before fixes) where a url.ts file with a parseUrl function that uses String.prototype.trim() was introduced. Angular 17.1.0 does not have this file in the upstream release. TuxCare created url.ts for their 17.1.0 fork (commit e06d36f339 by ejarocki@cloudlinux.com) but...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:125f0430-f891-565b-8854-1953d1a9f41a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 17.1.0-tuxcare.1 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4df694a8-22f0-5c61-a79f-582f10d548d8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 17.1.0-tuxcare.1 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d2eef95c-1d43-560e-940c-9fda31930934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 17.1.0-tuxcare.1 of @angular/bazel."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/bazel@17.1.0-tuxcare.1"
    }
  ]
}