{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f518564a-aef6-5360-bfda-2625ea9c2c1b",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/bazel",
      "purl": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.10",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.10",
      "version": "17.3.12-tuxcare.10",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:5be89b7f-5067-51e2-990c-1f9544263628",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.3.12-tuxcare.10 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:124cb265-8de8-586b-9500-f6f65ba12bec",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.3.12-tuxcare.10 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:f23dd814-5eca-537b-93d4-ee897195f5a5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.3.12-tuxcare.10 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:4839b3a1-d793-571c-8285-5542e172faf0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.3.12-tuxcare.10 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:55f66a3a-a3df-5532-ae4a-0c2f8cac2912",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.3.12-tuxcare.10 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:91e71800-b06b-5c11-aed1-ac11a2bf252c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.3.12-tuxcare.10 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:e1d88b19-a1fe-5357-95aa-2da65e2337a1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 17.3.12-tuxcare.10 of @angular/bazel, and is fixed in 17.3.12-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:a87bd000-8267-5362-9f12-0565554b0664",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 17.3.12-tuxcare.10 of @angular/bazel, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:224a6553-7eec-51a3-806e-d0047c9754ba",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 17.3.12-tuxcare.10 of @angular/bazel, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:c2416ee7-13b4-55ca-b32e-f771829db83b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 17.3.12-tuxcare.10 of @angular/bazel, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:c4108acc-87f3-5916-8ce9-cda04dadfc7d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 17.3.12-tuxcare.10 of @angular/bazel, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:461e0a45-37db-587b-8da3-b53e78db1471",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 17.3.12-tuxcare.10 of @angular/bazel, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:6558b0b1-08cc-58b1-b3c8-5277196f5179",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 17.3.12-tuxcare.10 of @angular/bazel, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:f51f9618-15a0-5430-82e8-66f6faa201a1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 17.3.12-tuxcare.10 of @angular/bazel, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:f10fad2f-b245-5238-b19b-10ddfdac892d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 17.3.12-tuxcare.10 of @angular/bazel, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:28acfd76-f157-58a7-8479-1e2e5cad9c8c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 17.3.12-tuxcare.10 of @angular/bazel, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:0d129ecc-0608-5fba-8114-14909ae8f625",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 17.3.12-tuxcare.10 of @angular/bazel, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:136b51b8-9114-5815-85d4-9130e18765bd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 17.3.12-tuxcare.10 of @angular/bazel, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:8e095ab1-f879-5b75-a35e-13440d8dcb7c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 17.3.12-tuxcare.10 of @angular/bazel, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:9bc1a6ba-1f49-5876-a10f-3015458df6b6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 17.3.12-tuxcare.10 of @angular/bazel, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:9ed92a04-bfaf-50d1-bf33-ea62eb165242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 17.3.12-tuxcare.10 of @angular/bazel, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:212debdc-1477-55cb-9a73-0e7081d4bd48",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 17.3.12-tuxcare.10 of @angular/bazel, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:31d12644-79ef-58d7-9c3d-67ebd26932f2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 17.3.12-tuxcare.10 of @angular/bazel, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:b66b07f4-d3a9-52bf-9add-19fa8c8bc29f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 17.3.12-tuxcare.10 of @angular/bazel, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:8ee4338e-b188-53e7-b697-15e8337dc5fa",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.3.12-tuxcare.10 of @angular/bazel. not_affected \u2014 Version 17.3.12 is not affected by CVE-2026-88056. The vulnerability involves String.prototype.trim() being applied during URL resolution in Angular's platform-server, converting validated same-origin URLs with Unicode whitespace into cross-origin protocol-relative URLs, leading to SSRF. This vulnerable code pattern was introduced in newer Angular versions (v20+) and does not exist in version 1...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:eedca169-3f0a-5b8e-b99f-b00770d9150d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 17.3.12-tuxcare.10 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:5ff5f238-ace4-5031-aa54-0c2798a86849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 17.3.12-tuxcare.10 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:8c4756c0-947c-5e8d-bcb9-9c5a6bf75d61",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 17.3.12-tuxcare.10 of @angular/bazel."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.10"
    }
  ]
}