{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:8b39f022-0aa4-5f3d-acea-b2d1348d17d0",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/benchpress",
      "purl": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.3",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.3",
      "version": "16.2.11-tuxcare.3",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:478c4fbf-e94d-5bc6-bf36-3b62ebb642dd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59052 affects version 16.2.11-tuxcare.3 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:384da2e2-2341-5998-af99-9efe16d0c0c8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 16.2.11-tuxcare.3 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:1534d75e-e70d-5371-b641-43bf239c1eeb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 16.2.11-tuxcare.3 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:86aad19d-41fe-5afb-95f1-523a0bc2300e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 16.2.11-tuxcare.3 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:ffa59545-0087-5314-bca3-baf150ca75b3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 16.2.11-tuxcare.3 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:02c8c83a-64ac-5b6d-9e7f-b58ad288a489",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 16.2.11-tuxcare.3 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:a0b621cd-d4ea-5cab-b11f-6472cf4174e7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 16.2.11-tuxcare.3 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:facb7fbe-37b1-5755-9b90-c5a19279ca28",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 16.2.11-tuxcare.3 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:f774ea4d-405a-5f13-81da-aa1fbc4a9d70",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 16.2.11-tuxcare.3 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:033be970-1f7c-59c9-8100-5fa88152e808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 16.2.11-tuxcare.3 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:cf1843ab-9b3d-51ca-9be7-98660133e147",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 16.2.11-tuxcare.3 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:853c562a-df04-5157-8ea0-41901a41b753",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 16.2.11-tuxcare.3 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:477f3a46-3264-52db-b82e-e536d6d014cb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 16.2.11-tuxcare.3 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:e0b10393-6bad-539b-815a-a759efcfcd48",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 16.2.11-tuxcare.3 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:0647161b-6ab8-5380-a88f-e023d4159afb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 16.2.11-tuxcare.3 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:a755cb28-4821-59ba-a31a-19c41329d016",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 16.2.11-tuxcare.3 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:8af9e50f-a07b-56a6-be92-5c730038e11c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 16.2.11-tuxcare.3 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:e14bd430-cb88-5e2e-808e-2d7208756bea",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 16.2.11-tuxcare.3 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:c095c8a4-0984-5e25-90d3-9992750e0dd0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 16.2.11-tuxcare.3 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:a45d7933-a589-5aca-84cd-06f03ba0c94d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 16.2.11-tuxcare.3 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:f5c6295b-e194-5317-b5fe-b34fbf7e44e3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 16.2.11-tuxcare.3 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:77504e3f-55d3-5fff-bac2-f0bca97a912b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 16.2.11-tuxcare.3 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:e9000cd7-33f1-5dc7-97c8-fd50710009c7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 16.2.11-tuxcare.3 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:c30c0b27-06c7-5ea2-b7f3-bf65b2bd64de",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 16.2.11-tuxcare.3 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:cb1af0d5-2c45-5a77-a529-3d1b709e28db",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 16.2.11-tuxcare.3 of @angular/benchpress. not_affected \u2014 Angular 16.2.11-tuxcare.2 is NOT affected by CVE-2026-88056. The vulnerability requires WHATWG URL validation combined with String.prototype.trim() on URLs during SSR, creating a discrepancy that enables SSRF. While the target uses WHATWG URL parsing (backported in commit c03fbfd7cc for CVE-2026-50168), it does NOT call String.prototype.trim() on URLs. The attack chain is broken at the trim() s...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:9b1f9ca7-07f8-5bb1-a509-4cf726e7dfc1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 16.2.11-tuxcare.3 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:ca44b0ce-4ca5-5a85-89b0-e4a62072bb01",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 16.2.11-tuxcare.3 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:b27c2b3d-ae88-506e-9638-00fadf5630a5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 16.2.11-tuxcare.3 of @angular/benchpress."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.3"
    }
  ]
}