{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:0d2c27aa-f9d0-55ad-a1e6-eeda7f6ccfa2",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/benchpress",
      "purl": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.13",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.13",
      "version": "17.3.12-tuxcare.13",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:298359bb-43fa-51f8-b4a6-56a9b78e9a5b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.3.12-tuxcare.13 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:6826db9e-47a5-5f4e-8a26-7b57b3de6287",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.3.12-tuxcare.13 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:c4b2050e-59a7-5c6f-8195-75751fe27560",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.3.12-tuxcare.13 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:cad6eb64-f1cf-5905-a89c-ebda970b47a7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.3.12-tuxcare.13 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:c07413ce-c28e-52d4-ad61-cff7be10b742",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.3.12-tuxcare.13 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:53bcef40-406d-5cf6-8915-7855f6990467",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.3.12-tuxcare.13 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:e6842091-5995-5cad-b444-46ad24f0bbf2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 17.3.12-tuxcare.13 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:8a4670e1-cca6-5131-8913-be971cd68203",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 17.3.12-tuxcare.13 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:1db74f0c-3d58-5773-9eeb-343217ef6e25",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 17.3.12-tuxcare.13 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:54b8feca-18b5-5a06-87dc-89986ae4f21e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 17.3.12-tuxcare.13 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:f4b793c4-d47e-5824-9135-e8e05d5d9aa5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 17.3.12-tuxcare.13 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:ea58985e-018c-5396-b2a3-811e7e8a68bb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 17.3.12-tuxcare.13 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:caaa9b02-03eb-503f-bcdf-25627671e43e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 17.3.12-tuxcare.13 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:5c47e1b5-ce43-5866-8f51-a12dd98501ce",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 17.3.12-tuxcare.13 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:ed81583a-85d5-52a0-b1e4-d9cfb56e9e00",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 17.3.12-tuxcare.13 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:c2c1167a-657a-5c6b-8f7c-af6303ccb067",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 17.3.12-tuxcare.13 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:3b82929d-b1f1-5c4e-8928-e57c221522de",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 17.3.12-tuxcare.13 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:5214e504-c31a-5d9f-a4bd-73849926bc2a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 17.3.12-tuxcare.13 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:701b8f4a-7951-5a69-a50a-c7fb76bdf36d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 17.3.12-tuxcare.13 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:0a0308b5-c023-5f8c-9b77-39ceb07a136d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 17.3.12-tuxcare.13 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:1351e0aa-bedb-5a0d-a31d-6d5b4ad2f8ed",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 17.3.12-tuxcare.13 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:b9ce2348-5bd9-5cad-a0da-1949593badbb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 17.3.12-tuxcare.13 of @angular/benchpress, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:abd369ee-8833-5d7a-970e-e7927cc719d7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 17.3.12-tuxcare.13 of @angular/benchpress, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:bbbbe255-a4e4-5ddd-bd08-94d149ba7138",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 17.3.12-tuxcare.13 of @angular/benchpress, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:0f685db9-402b-5e31-af04-1dc91303b9ae",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.3.12-tuxcare.13 of @angular/benchpress. not_affected \u2014 Version 17.3.12 is not affected by CVE-2026-88056. The vulnerability involves String.prototype.trim() being applied during URL resolution in Angular's platform-server, converting validated same-origin URLs with Unicode whitespace into cross-origin protocol-relative URLs, leading to SSRF. This vulnerable code pattern was introduced in newer Angular versions (v20+) and does not exist in version 1...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:938a20df-1bf0-5fcf-9cf1-439660610d7d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 17.3.12-tuxcare.13 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:b749a770-f981-529d-81e3-da0b87497b46",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 17.3.12-tuxcare.13 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:48c8024e-49c2-524e-b7d9-80f87ee6fe45",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 17.3.12-tuxcare.13 of @angular/benchpress."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.13"
    }
  ]
}