{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:6ee1ba03-ae63-5d8c-9b43-dd5b291f476f",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/benchpress",
      "purl": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.4",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.4",
      "version": "18.2.14-tuxcare.4",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:0cfb4c3a-44d4-5b1e-ae3a-cab4a299d3d3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.2.14-tuxcare.4 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:0370d518-5fc0-5f47-b9a2-b6e170b798c7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 18.2.14-tuxcare.4 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:235a2d6d-e926-5bba-aabd-847740bdeb81",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 18.2.14-tuxcare.4 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:2d91eb3e-1f78-5a1b-be48-63cc7f8920c8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 18.2.14-tuxcare.4 of @angular/benchpress, and is fixed in 18.2.14-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:8aa39e54-2194-578f-b977-5d6511463f39",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32635 affects version 18.2.14-tuxcare.4 of @angular/benchpress, and is fixed in 18.2.14-tuxcare.5."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:4b523583-d412-56a6-a007-3143cd4a1642",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 18.2.14-tuxcare.4 of @angular/benchpress, and is fixed in 18.2.14-tuxcare.10."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:03fcb1a5-bdff-592f-ba69-8e86e248a036",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 18.2.14-tuxcare.4 of @angular/benchpress, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:0a053864-f73a-5a1d-a61b-8b612eb2afa4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 18.2.14-tuxcare.4 of @angular/benchpress, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e8c31f63-22b8-55e0-a32c-7cfe3bfe9ac1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 18.2.14-tuxcare.4 of @angular/benchpress, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:f1b8f5ed-2c58-595f-9b62-771cb3277c28",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 18.2.14-tuxcare.4 of @angular/benchpress, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:b091a0b5-dfcc-5f6b-8c9f-8365f017621c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 18.2.14-tuxcare.4 of @angular/benchpress, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:45608fd3-0275-50e7-8524-c4eae4b8f266",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 18.2.14-tuxcare.4 of @angular/benchpress, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:8289e875-a5a4-515a-9ca1-ea71be02816b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 18.2.14-tuxcare.4 of @angular/benchpress, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:dc86b3a9-290d-5e49-8284-ae7f21220c56",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 18.2.14-tuxcare.4 of @angular/benchpress, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:05c01389-7001-5ae4-8123-8e4db6562bad",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 18.2.14-tuxcare.4 of @angular/benchpress, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:069e9587-32e6-5e84-8a90-f1bc39d48ebf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 18.2.14-tuxcare.4 of @angular/benchpress, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:ccb3781c-d1d3-5ffa-8d21-a18cb72ae633",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 18.2.14-tuxcare.4 of @angular/benchpress, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:8b02e679-39a3-5d9e-8793-a73aaf957f57",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 18.2.14-tuxcare.4 of @angular/benchpress, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:4d05d162-ac2e-5e49-a74e-518cbfa1deef",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 18.2.14-tuxcare.4 of @angular/benchpress, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:f6dd47f1-891f-5f21-bbf4-3bcad15f712c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 18.2.14-tuxcare.4 of @angular/benchpress, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:98659bdb-088a-5bc9-9d63-5eb8b5252d9c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 18.2.14-tuxcare.4 of @angular/benchpress, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:abc58767-0a6f-54f4-8e27-3fa075db6bcd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 18.2.14-tuxcare.4 of @angular/benchpress, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:9ed508ee-9a41-50c5-b677-b95c6fecb436",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 18.2.14-tuxcare.4 of @angular/benchpress, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:b9176389-5385-5ead-a1ff-a1e1042521ed",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 18.2.14-tuxcare.4 of @angular/benchpress. not_affected \u2014 The target version 18.2.14-tuxcare.13 is NOT affected by CVE-2026-88056. The vulnerable code pattern (calling String.prototype.trim() on URL strings before resolution) was never present in this version. The target uses a refactored parseUrl() implementation introduced via commit 49a60f6045 (May 2026) that correctly handles Unicode whitespace by percent-encoding it rather than stripping it, main...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:92083bd7-73d6-5cc1-aea9-e909623b4a1d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 18.2.14-tuxcare.4 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:1f5ca9b4-1d2f-5f6c-9a54-b1a4a76c98b9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 18.2.14-tuxcare.4 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:07389855-798f-537a-afb8-5d9a08ff8ae5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 18.2.14-tuxcare.4 of @angular/benchpress."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.4"
    }
  ]
}