{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:7fb93138-d65c-598b-91e0-0c773222d750",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/bazel",
      "purl": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.6",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.6",
      "version": "18.2.14-tuxcare.6",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:5f98639f-12b6-5fe7-8c5d-ffac43f5ac0a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.2.14-tuxcare.6 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:69b64422-2780-53a2-b7f3-b3b1f8ca72a8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 18.2.14-tuxcare.6 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:0dae16b2-9cdb-50df-bfd8-5b7bf3aa0db4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 18.2.14-tuxcare.6 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:dd94c662-6626-5761-b575-5317e2691d67",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 18.2.14-tuxcare.6 of @angular/bazel, and is fixed in 18.2.14-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d1b1d1a0-9799-5432-8af6-c4a5c0efbbfb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 18.2.14-tuxcare.6 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:7e1eb8fa-2015-58b7-b390-735a585158a4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 18.2.14-tuxcare.6 of @angular/bazel, and is fixed in 18.2.14-tuxcare.10."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ad28ae6c-74bb-5c06-a3a1-432f49c4ade8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 18.2.14-tuxcare.6 of @angular/bazel, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:784644c7-308c-5964-9c3c-fae3b17b7922",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 18.2.14-tuxcare.6 of @angular/bazel, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ab4e91c2-9f58-5212-9885-9a7e274a8b48",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 18.2.14-tuxcare.6 of @angular/bazel, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:15fec30c-eb80-5de2-aa85-49bb33992f53",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 18.2.14-tuxcare.6 of @angular/bazel, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b8de4d88-aaf1-5e71-a696-1746ec7fb688",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 18.2.14-tuxcare.6 of @angular/bazel, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:18ea85c5-6791-540e-85bb-56e0a3a8b1fc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 18.2.14-tuxcare.6 of @angular/bazel, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:db4944f1-2943-5fb8-9831-f5d6a892da97",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 18.2.14-tuxcare.6 of @angular/bazel, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e1f5e26e-93b3-5288-a523-7b55257671be",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 18.2.14-tuxcare.6 of @angular/bazel, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6e69510e-bb87-5193-973a-cbba993c180f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 18.2.14-tuxcare.6 of @angular/bazel, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:524edeab-8af0-5e2d-a84c-98e4fa666a5a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 18.2.14-tuxcare.6 of @angular/bazel, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b4f8d12e-8afe-5d3f-afda-96179c0c5e64",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 18.2.14-tuxcare.6 of @angular/bazel, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:299cd556-90b7-52de-ab65-d0d908b393a5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 18.2.14-tuxcare.6 of @angular/bazel, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:34fa969c-4bea-5921-bc12-f7a0134e52d5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 18.2.14-tuxcare.6 of @angular/bazel, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:932b4119-078c-522b-bb46-9fd40b3ea23f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 18.2.14-tuxcare.6 of @angular/bazel, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:adfa4365-4cb1-5307-8667-714779755e58",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 18.2.14-tuxcare.6 of @angular/bazel, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:65339893-4a6a-5493-9979-13fea2236981",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 18.2.14-tuxcare.6 of @angular/bazel, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:361886e0-2617-5fcf-a19b-6e95bbd31461",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 18.2.14-tuxcare.6 of @angular/bazel, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c16f4c36-e554-5094-b445-fe62adea0f1b",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 18.2.14-tuxcare.6 of @angular/bazel. not_affected \u2014 The target version 18.2.14-tuxcare.13 is NOT affected by CVE-2026-88056. The vulnerable code pattern (calling String.prototype.trim() on URL strings before resolution) was never present in this version. The target uses a refactored parseUrl() implementation introduced via commit 49a60f6045 (May 2026) that correctly handles Unicode whitespace by percent-encoding it rather than stripping it, main...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:56168dad-8b14-5eb9-9919-38d7d6a0999f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 18.2.14-tuxcare.6 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:7ec29e45-6772-52d8-bf0c-57909b3a04df",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 18.2.14-tuxcare.6 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c8984c19-7e38-55fb-b20c-7dd6e8a63766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 18.2.14-tuxcare.6 of @angular/bazel."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.6"
    }
  ]
}