{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d1c53897-3f34-5deb-959f-6ddb3319dc48",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/bazel",
      "purl": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.7",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.7",
      "version": "18.2.14-tuxcare.7",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:d3f6470e-d210-5ef9-8fe8-045e56f51721",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.2.14-tuxcare.7 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:4bc1f65d-0e54-5cf3-9b7b-794f19812a4a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 18.2.14-tuxcare.7 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:d4fc8411-413f-5460-90e0-cb28259bcce7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 18.2.14-tuxcare.7 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:d7715a84-4a66-5da5-993d-5b5d003d4b94",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 18.2.14-tuxcare.7 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:904c4b9f-bbfd-5154-9c3e-4601f2f71686",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 18.2.14-tuxcare.7 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:06e6af67-ae55-559a-9eac-039ee30860fc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 18.2.14-tuxcare.7 of @angular/bazel, and is fixed in 18.2.14-tuxcare.10."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:4ce297f9-90c5-5fe2-97c3-1346921f8def",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 18.2.14-tuxcare.7 of @angular/bazel, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:fc04181f-394b-588f-9f2f-72463b66ad05",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 18.2.14-tuxcare.7 of @angular/bazel, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:b13748c9-c14f-5184-b782-117c9be1535c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 18.2.14-tuxcare.7 of @angular/bazel, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:f9974b19-5852-5f8b-86bd-55ea978fcc1f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 18.2.14-tuxcare.7 of @angular/bazel, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:3c8586f8-ec99-5083-937f-004a8ae3f086",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 18.2.14-tuxcare.7 of @angular/bazel, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:3c71832a-a7ac-5a27-b587-127edbbd045e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 18.2.14-tuxcare.7 of @angular/bazel, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:c6f4dcce-59e6-52b5-ba90-52a5760a7c9b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 18.2.14-tuxcare.7 of @angular/bazel, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:cfb89475-5646-528a-9829-7aaa270e5529",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 18.2.14-tuxcare.7 of @angular/bazel, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:e759f1b0-849c-5aee-b4c9-49610d704911",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 18.2.14-tuxcare.7 of @angular/bazel, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:82f96ff2-33e5-5e91-8158-b850d7d5b6a2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 18.2.14-tuxcare.7 of @angular/bazel, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:23ec145e-1408-50ee-a64e-bf2f490bb2f7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 18.2.14-tuxcare.7 of @angular/bazel, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:85a539f2-342f-5712-a43c-d2101c3ba154",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 18.2.14-tuxcare.7 of @angular/bazel, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:976f8180-db1e-50e8-a570-e30604f415f5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 18.2.14-tuxcare.7 of @angular/bazel, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:27231e91-e997-513b-b80a-edbd2622f802",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 18.2.14-tuxcare.7 of @angular/bazel, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:fbbb7d12-4568-5258-b04e-f6d2fcca49f7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 18.2.14-tuxcare.7 of @angular/bazel, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:3b7a3401-fec4-5d98-aee7-487352b868f5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 18.2.14-tuxcare.7 of @angular/bazel, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:9663a06e-529f-5e35-b45a-c4a56148796d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 18.2.14-tuxcare.7 of @angular/bazel, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:446a402d-fdb9-5d7b-bdcd-cc8935e744b0",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 18.2.14-tuxcare.7 of @angular/bazel. not_affected \u2014 The target version 18.2.14-tuxcare.13 is NOT affected by CVE-2026-88056. The vulnerable code pattern (calling String.prototype.trim() on URL strings before resolution) was never present in this version. The target uses a refactored parseUrl() implementation introduced via commit 49a60f6045 (May 2026) that correctly handles Unicode whitespace by percent-encoding it rather than stripping it, main...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:46147a68-ae05-5104-89ca-117424680a6e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 18.2.14-tuxcare.7 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:b87f599a-eff6-5ba2-956f-5f4c526ae466",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 18.2.14-tuxcare.7 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:ce1b58cb-61d8-5e8a-9d64-1e5ac118ddfc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 18.2.14-tuxcare.7 of @angular/bazel."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.7"
    }
  ]
}