{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:7ea8fdcd-7af6-55d2-b799-42f502d3fe3c",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/benchpress",
      "purl": "pkg:npm/%40angular/benchpress@14.3.0-tuxcare.3",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/benchpress@14.3.0-tuxcare.3",
      "version": "14.3.0-tuxcare.3",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@14.3.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:95b75990-6712-59d4-92f1-36db1078a510",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 14.3.0-tuxcare.3 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@14.3.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:0ab35bd5-380c-5e95-95e3-810031e552e0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66412 affects version 14.3.0-tuxcare.3 of @angular/benchpress, and is fixed in 14.3.0-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@14.3.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:ed3a861f-d13c-54ee-a77d-b3de328ff173",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22610 affects version 14.3.0-tuxcare.3 of @angular/benchpress, and is fixed in 14.3.0-tuxcare.5."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@14.3.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:ff28a8bc-2de8-55ca-9279-cdbcaa900562",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 14.3.0-tuxcare.3 of @angular/benchpress, and is fixed in 14.3.0-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@14.3.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:60134a71-2c3b-577c-a5a4-3aea87956fe6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 14.3.0-tuxcare.3 of @angular/benchpress, and is fixed in 14.3.0-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@14.3.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:8faff3ac-68a7-5879-bc2f-66a41573bb7b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 14.3.0-tuxcare.3 of @angular/benchpress, and is fixed in 14.3.0-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@14.3.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:087de8d8-921a-5229-8562-c02d9fd1a64e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 14.3.0-tuxcare.3 of @angular/benchpress, and is fixed in 14.3.0-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@14.3.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:ae13d4f2-b210-54f0-bc80-310c7e325cf6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 14.3.0-tuxcare.3 of @angular/benchpress, and is fixed in 14.3.0-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@14.3.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:0a525f73-f48d-5b14-a92c-b08c84e84156",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 14.3.0-tuxcare.3 of @angular/benchpress, and is fixed in 14.3.0-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@14.3.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:2fdc5c5e-dd59-5727-8be7-12569ff5fd0a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 14.3.0-tuxcare.3 of @angular/benchpress, and is fixed in 14.3.0-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@14.3.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:86bd1dcd-86d0-5fe4-b6d1-b33d106bfb44",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 14.3.0-tuxcare.3 of @angular/benchpress, and is fixed in 14.3.0-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@14.3.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:3925a6d1-5d8c-5477-9cfa-db37529636b1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 14.3.0-tuxcare.3 of @angular/benchpress, and is fixed in 14.3.0-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@14.3.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:51440327-78d6-5fc6-ace8-3bcac3b6ff39",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 14.3.0-tuxcare.3 of @angular/benchpress, and is fixed in 14.3.0-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@14.3.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:57ea1393-90c8-558c-b7f4-450864448db3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 14.3.0-tuxcare.3 of @angular/benchpress, and is fixed in 14.3.0-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@14.3.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:eb9c742e-87a7-5f5d-823d-b9a6a7660845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 14.3.0-tuxcare.3 of @angular/benchpress, and is fixed in 14.3.0-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@14.3.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:f98a943e-5d54-5d01-b90f-b6f112a3774a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 14.3.0-tuxcare.3 of @angular/benchpress, and is fixed in 14.3.0-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@14.3.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:39c99734-d83f-5de1-be2d-c300a2c06817",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 14.3.0-tuxcare.3 of @angular/benchpress, and is fixed in 14.3.0-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@14.3.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:0c700054-df6d-5a88-822b-b27d449e881d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 14.3.0-tuxcare.3 of @angular/benchpress, and is fixed in 14.3.0-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@14.3.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:418f64f7-1d92-5b40-8a81-c362065021c9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 14.3.0-tuxcare.3 of @angular/benchpress, and is fixed in 14.3.0-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@14.3.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:3fcb19d1-ff09-5ed8-a9c1-5e03627ad6f9",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 14.3.0-tuxcare.3 of @angular/benchpress. not_affected \u2014 Angular v14.3.0 is not affected by CVE-2026-68945. The vulnerable HttpTransferCache feature does not exist in this version\u2014it was introduced in Angular v16.0.0, two major versions later. Without HttpTransferCache, there is no code path that can generate ambiguous cache keys from repeated HTTP parameters. This finding is consistent with two prior TuxCare analyses (CVE-2026-54266, CVE-2026-50170)...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@14.3.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:d9ded525-1fec-56d3-a7e8-34a0a13037a8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 14.3.0-tuxcare.3 of @angular/benchpress, and is fixed in 14.3.0-tuxcare.10."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@14.3.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:bd7ba00d-6cf5-56b6-a64f-b4fbea26434f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 14.3.0-tuxcare.3 of @angular/benchpress, and is fixed in 14.3.0-tuxcare.10."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@14.3.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:279fdf9b-6642-5aef-bf07-9234f51ce6e2",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 14.3.0-tuxcare.3 of @angular/benchpress. not_affected \u2014 Angular 14.3.0-tuxcare.10 is not affected by CVE-2026-88056. The vulnerable code pattern (String.prototype.trim() call in URL resolution that strips Unicode whitespace and enables protocol-relative URL transformation) was never present in this version. The platform-server/src/url.ts file was created by TuxCare (commit 98195de23b by vvillevald@cloudlinux.com) as part of CVE-2026-50168 fix, and t...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@14.3.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:ff9ba712-c34c-5312-a124-8d3a590b862f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 14.3.0-tuxcare.3 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@14.3.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:16529eb1-5b9c-5713-9438-630158d1461d",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 14.3.0-tuxcare.3 of @angular/benchpress. not_affected \u2014 Version 14.3.0 is not affected by CVE-2026-88059. The vulnerable features (HttpTransferCache interceptor, withRequestsMadeViaParent() for hierarchical HttpClient configuration, and provideClientHydration() for SSR hydration) do not exist in this version. These features were introduced in Angular v16.0.0, while the target is v14.3.0 (two major versions earlier). Patch files CVE-2026-50170.patch ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@14.3.0-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:8fc05242-b798-5bd4-a375-706601cb830d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 14.3.0-tuxcare.3 of @angular/benchpress."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/benchpress@14.3.0-tuxcare.3"
    }
  ]
}