{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:948e74b9-f351-5754-a751-a921f2b63d8e",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/bazel",
      "purl": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.2",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.2",
      "version": "8.2.14-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:05590bae-6346-5b9b-bf73-6c24ee402490",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-4231 affects version 8.2.14-tuxcare.2 of @angular/bazel, and is fixed in 8.2.14-tuxcare.5."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:fd7cb556-4303-5887-92b4-0b912b26cb77",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 8.2.14-tuxcare.2 of @angular/bazel, and is fixed in 8.2.14-tuxcare.10."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c54805d9-3ea6-5348-8243-fc1e73c3a425",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66412 affects version 8.2.14-tuxcare.2 of @angular/bazel, and is fixed in 8.2.14-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4c1e7cf6-7fa6-5388-9791-16936bbeb33e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22610 affects version 8.2.14-tuxcare.2 of @angular/bazel, and is fixed in 8.2.14-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2aaa96d5-0317-5b9b-afcb-2d19fcdd40a2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 8.2.14-tuxcare.2 of @angular/bazel, and is fixed in 8.2.14-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b3f9cebe-579c-5aa0-bf18-888f5cd566f1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 8.2.14-tuxcare.2 of @angular/bazel, and is fixed in 8.2.14-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:98910b3a-bea5-5db0-ae69-16d5c90ae512",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 8.2.14-tuxcare.2 of @angular/bazel, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1258b19a-151b-5403-bfa8-11336c72728f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 8.2.14-tuxcare.2 of @angular/bazel, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e7e43956-2cfe-57cb-95fe-618d8886599c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 8.2.14-tuxcare.2 of @angular/bazel, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ab94724c-5f00-5dd8-bd0f-7d60770c393a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 8.2.14-tuxcare.2 of @angular/bazel, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:cad7a160-71b6-5b6b-9838-deb7e8e71487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 8.2.14-tuxcare.2 of @angular/bazel, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7dacfd76-7ecf-5a12-90b9-16b19b983d13",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 8.2.14-tuxcare.2 of @angular/bazel, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:81218d7f-af4e-5360-8aed-cf71c8ce95f1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 8.2.14-tuxcare.2 of @angular/bazel, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:82e19267-870c-5155-8725-9415678638dc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 8.2.14-tuxcare.2 of @angular/bazel, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:bbc8c79a-c980-5b8e-b9e6-d64e7c4000a8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 8.2.14-tuxcare.2 of @angular/bazel, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:817ccf52-b131-504b-a131-5c2ec6480ce7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 8.2.14-tuxcare.2 of @angular/bazel, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:29059d54-f149-5367-b652-edf9fd5d913e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 8.2.14-tuxcare.2 of @angular/bazel, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0e8d5e75-d212-51c4-b47f-466feee2325c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 8.2.14-tuxcare.2 of @angular/bazel, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8ecef990-7e3b-5c05-9132-5c2ef1469b85",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 8.2.14-tuxcare.2 of @angular/bazel, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:29ae13fc-5cee-5172-b9f6-dca9f81e6fda",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 8.2.14-tuxcare.2 of @angular/bazel, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9cf8f4e7-14b2-5b97-a06f-e73696be3f7e",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 8.2.14-tuxcare.2 of @angular/bazel. not_affected \u2014 Angular 8.2.14 is NOT affected by CVE-2026-68945. The vulnerability exists in HttpTransferCache, a feature that automatically caches HTTP requests during SSR for client hydration. HttpTransferCache was introduced in Angular v16+ and does not exist in version 8.2.14. This version has only a manual TransferState key-value store with no automatic HttpClient integration, and no HTTP caching mechani...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:99457119-8871-5e20-adf2-3bf1fc91fd3f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 8.2.14-tuxcare.2 of @angular/bazel, and is fixed in 8.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a68c8de3-2a9f-5f83-aa1b-49cb66e24530",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 8.2.14-tuxcare.2 of @angular/bazel, and is fixed in 8.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2466618d-940e-552e-9e4c-9ab0987cf23f",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 8.2.14-tuxcare.2 of @angular/bazel. not_affected \u2014 Angular 8.2.14 is NOT AFFECTED by CVE-2026-88056. The vulnerability requires a sophisticated URL resolution utility (`parseUrl` in `packages/platform-server/src/url.ts`) that calls `String.prototype.trim()` to strip Unicode whitespace, creating a discrepancy with WHATWG URL validation. This architecture was introduced in Angular v12+ (circa 2026 as TuxCare backports). Angular 8.2.14 (released N...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:27795b4a-75aa-5b42-94b7-c82b698f6415",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 8.2.14-tuxcare.2 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c6f916fb-b01b-594b-bfc3-093cd5bff1ac",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 8.2.14-tuxcare.2 of @angular/bazel. not_affected \u2014 Angular v8.2.14 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, provideClientHydration(), and withRequestsMadeViaParent() \u2014 all features that do not exist in this version. These features were introduced in Angular v16 (per patches/CVE-2026-50170.patch and patches/CVE-2026-54266.patch). The target uses the legacy NgModule-based HttpClientModule without automatic ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:03650b73-a0df-5ad4-a7e2-1478802b3083",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 8.2.14-tuxcare.2 of @angular/bazel."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.2"
    }
  ]
}