{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:36f6aa04-e3d4-5d57-9703-41585ce5c58e",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/bazel",
      "purl": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.8",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.8",
      "version": "8.2.14-tuxcare.8",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:ce242b96-d45d-5f33-a4cc-79364f062ab5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 8.2.14-tuxcare.8 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:f731ffd0-751f-58c3-b2da-5d56a7e6a60e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 8.2.14-tuxcare.8 of @angular/bazel, and is fixed in 8.2.14-tuxcare.10."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:9f37d1eb-c7c2-50c8-942e-1c779ba34cc0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 8.2.14-tuxcare.8 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:94f924c0-b359-5b6a-aabb-a7a6abf0d4ef",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 8.2.14-tuxcare.8 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:9f6bd777-62f9-5048-a7a2-c796918309a8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 8.2.14-tuxcare.8 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:9d308af2-bc27-51bb-9083-0a0524f8216d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 8.2.14-tuxcare.8 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:81d37569-502e-5554-8b62-9e268a61a7f6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 8.2.14-tuxcare.8 of @angular/bazel, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:cd946eed-9e1d-5cc4-ae2f-daaeb2d212d8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 8.2.14-tuxcare.8 of @angular/bazel, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:b70cc19b-985e-5dce-889b-e7aeb40ec1b6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 8.2.14-tuxcare.8 of @angular/bazel, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:6393cd4f-ebfe-522d-a38b-0b973830aac9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 8.2.14-tuxcare.8 of @angular/bazel, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:1fa308d6-2aa8-5f10-9587-213e583c0234",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 8.2.14-tuxcare.8 of @angular/bazel, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:15f7a384-60cd-5774-a4cf-7a9e40d0ec83",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 8.2.14-tuxcare.8 of @angular/bazel, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:9b269856-2d7f-5147-9e0f-b81cfc1fc8af",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 8.2.14-tuxcare.8 of @angular/bazel, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:68928299-2274-525d-9c85-83a2b7c026e0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 8.2.14-tuxcare.8 of @angular/bazel, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:9afe3d8e-4cbb-5331-8388-09e27f98ced7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 8.2.14-tuxcare.8 of @angular/bazel, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:a183517e-74fe-50c9-9047-0255cf2a3893",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 8.2.14-tuxcare.8 of @angular/bazel, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:6b995288-b0c4-590e-89e1-64f906ebcd4c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 8.2.14-tuxcare.8 of @angular/bazel, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:c889f4ea-9a5f-5f81-aabe-f358c46dd782",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 8.2.14-tuxcare.8 of @angular/bazel, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:ef5e28a0-4296-5a84-a329-1576fa1a5bad",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 8.2.14-tuxcare.8 of @angular/bazel, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:1b76f803-c310-5b03-a1d8-8f0d51a2ffcc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 8.2.14-tuxcare.8 of @angular/bazel, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:cd93cae9-f4aa-538c-a213-a7e46e2e4268",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 8.2.14-tuxcare.8 of @angular/bazel. not_affected \u2014 Angular 8.2.14 is NOT affected by CVE-2026-68945. The vulnerability exists in HttpTransferCache, a feature that automatically caches HTTP requests during SSR for client hydration. HttpTransferCache was introduced in Angular v16+ and does not exist in version 8.2.14. This version has only a manual TransferState key-value store with no automatic HttpClient integration, and no HTTP caching mechani...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:0a56660a-f3de-5734-aaa3-c4f34329e5b0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 8.2.14-tuxcare.8 of @angular/bazel, and is fixed in 8.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:e3c2d5cf-4996-59d4-bd1a-46fce516f3fe",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 8.2.14-tuxcare.8 of @angular/bazel, and is fixed in 8.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:aa5009c1-73aa-5314-8235-cfb0ae808f57",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 8.2.14-tuxcare.8 of @angular/bazel. not_affected \u2014 Angular 8.2.14 is NOT AFFECTED by CVE-2026-88056. The vulnerability requires a sophisticated URL resolution utility (`parseUrl` in `packages/platform-server/src/url.ts`) that calls `String.prototype.trim()` to strip Unicode whitespace, creating a discrepancy with WHATWG URL validation. This architecture was introduced in Angular v12+ (circa 2026 as TuxCare backports). Angular 8.2.14 (released N...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:658c15ce-6d7d-52c3-9e3a-29aadb9ad4f2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 8.2.14-tuxcare.8 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:1d8322e1-ce02-5183-93a9-fc32d7b91781",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 8.2.14-tuxcare.8 of @angular/bazel. not_affected \u2014 Angular v8.2.14 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, provideClientHydration(), and withRequestsMadeViaParent() \u2014 all features that do not exist in this version. These features were introduced in Angular v16 (per patches/CVE-2026-50170.patch and patches/CVE-2026-54266.patch). The target uses the legacy NgModule-based HttpClientModule without automatic ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:5a7cbea5-cdb6-585b-a1c6-f6bcd0224879",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 8.2.14-tuxcare.8 of @angular/bazel."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.8"
    }
  ]
}