{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:8f5ffe33-0605-51a3-a2ea-9a04ad95f53a",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/bazel",
      "purl": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.12",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.12",
      "version": "17.3.12-tuxcare.12",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:2497eef6-220d-5ecd-9847-1969d4e04640",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.3.12-tuxcare.12 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:5a8ea072-149e-51af-b7f4-ed4112161990",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.3.12-tuxcare.12 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:e5f8503c-90e7-5926-bd71-2204e229dbde",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.3.12-tuxcare.12 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:6f93b0ea-70ff-53d2-abc8-c75f17f1f3e1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.3.12-tuxcare.12 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:b31d88e1-4290-5e64-b2d7-9a1efc9a2624",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.3.12-tuxcare.12 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:a7788265-5ead-51e7-b084-fd61aef73672",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.3.12-tuxcare.12 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:a90b50fe-5c4b-5168-a843-04906cc828fd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 17.3.12-tuxcare.12 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:0cbbf2f1-af3d-50e9-8d3e-482bca4d721b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 17.3.12-tuxcare.12 of @angular/bazel, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:12e85cb4-d1dc-53d8-afd2-3e9005cf5b1a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 17.3.12-tuxcare.12 of @angular/bazel, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:9eaca4a9-95ed-5293-af55-ff9a03672e99",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 17.3.12-tuxcare.12 of @angular/bazel, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:58c45038-9dd5-5551-9e7d-996e7412a80f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 17.3.12-tuxcare.12 of @angular/bazel, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:044140e2-7e60-5bcc-9155-1c2d1f7a869b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 17.3.12-tuxcare.12 of @angular/bazel, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:8a77dcca-1224-51aa-b3bd-6c174a3f0d77",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 17.3.12-tuxcare.12 of @angular/bazel, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:645bb2bc-239f-5ff5-949f-c3729315dae9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 17.3.12-tuxcare.12 of @angular/bazel, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:73316b45-20ba-57e4-b2b6-61e59b796ee1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 17.3.12-tuxcare.12 of @angular/bazel, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:aecf07aa-ef10-5669-bf6b-907909f2f1a3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 17.3.12-tuxcare.12 of @angular/bazel, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:9ed6f14e-c5fc-51fc-b1cf-941e6addf089",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 17.3.12-tuxcare.12 of @angular/bazel, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:56b88a40-f47d-5029-a0bb-117ee4cf2824",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 17.3.12-tuxcare.12 of @angular/bazel, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:95bf1120-7570-50b9-911e-1aa895df7e02",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 17.3.12-tuxcare.12 of @angular/bazel, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:08c66766-c876-54d0-a726-95fc4fa3b57d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 17.3.12-tuxcare.12 of @angular/bazel, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:6566a125-87f6-53eb-abdd-ddabaa7ad8ae",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 17.3.12-tuxcare.12 of @angular/bazel, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:0a108221-0f03-58b8-8ba7-1ff0d9880565",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 17.3.12-tuxcare.12 of @angular/bazel, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:d02f67c1-df67-53de-9240-1741bc6ab273",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 17.3.12-tuxcare.12 of @angular/bazel, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:4d255218-89dc-59e0-8021-72a1d886fa10",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 17.3.12-tuxcare.12 of @angular/bazel, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:fa56284f-2888-5924-bdd7-4116a8dbf846",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.3.12-tuxcare.12 of @angular/bazel. not_affected \u2014 Version 17.3.12 is not affected by CVE-2026-88056. The vulnerability involves String.prototype.trim() being applied during URL resolution in Angular's platform-server, converting validated same-origin URLs with Unicode whitespace into cross-origin protocol-relative URLs, leading to SSRF. This vulnerable code pattern was introduced in newer Angular versions (v20+) and does not exist in version 1...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:b0b95852-472d-537b-9264-1d5c165eef30",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 17.3.12-tuxcare.12 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:492a35d4-9f6d-5cd5-a490-f95c2ecb7147",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 17.3.12-tuxcare.12 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:a6959566-76b9-51c3-bd19-d93327f47c50",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 17.3.12-tuxcare.12 of @angular/bazel."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.12"
    }
  ]
}