{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a2b0b20d-eace-5f8d-9850-631255e3408c",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/compiler-cli",
      "purl": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.8",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.8",
      "version": "16.2.12-tuxcare.8",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:07dd2777-5f91-5f63-8833-07efa40f5500",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 16.2.12-tuxcare.8 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:93be0501-35f3-5156-9106-b2bf3804fcff",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 16.2.12-tuxcare.8 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:6f2b05e9-64fb-576a-8bbd-a3c8af7c821e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 16.2.12-tuxcare.8 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:21b10bff-97be-5173-a1f5-80531e42b76c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 16.2.12-tuxcare.8 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:4949f094-a2fd-554a-8b71-56fb8f3fd8d2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 16.2.12-tuxcare.8 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:3dd57012-e814-532a-8196-0ac3b157309a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 16.2.12-tuxcare.8 of @angular/compiler-cli, and is fixed in 16.2.12-tuxcare.10."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:97bb4a33-e6f7-5c7a-be5e-1bf05e344af3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 16.2.12-tuxcare.8 of @angular/compiler-cli, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:cf94686b-56c2-54c5-b181-5f3899f6d8e1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 16.2.12-tuxcare.8 of @angular/compiler-cli, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:42be69e0-f524-52c5-97e8-ef2ceded238b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 16.2.12-tuxcare.8 of @angular/compiler-cli, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:6add38b3-ae7e-5f71-82a1-7a8b72a06473",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 16.2.12-tuxcare.8 of @angular/compiler-cli, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:19df90c5-57f6-582b-957c-767a0b1c161a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 16.2.12-tuxcare.8 of @angular/compiler-cli, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:2a9ad280-c1e9-5a67-8b96-132e9389ac6c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 16.2.12-tuxcare.8 of @angular/compiler-cli, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:21274d9b-2b24-53db-a166-02b8076613ca",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 16.2.12-tuxcare.8 of @angular/compiler-cli, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:3fcee27e-4a1c-577d-a916-d5783d341735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 16.2.12-tuxcare.8 of @angular/compiler-cli, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:e91f2e94-c879-5019-ab4d-313aafd2846d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 16.2.12-tuxcare.8 of @angular/compiler-cli, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:7f37d46f-a924-56e7-96c6-5965feea47ea",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 16.2.12-tuxcare.8 of @angular/compiler-cli, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:adcfd214-aa02-53f3-b691-7ecb1602a6e3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 16.2.12-tuxcare.8 of @angular/compiler-cli, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:e52bfdda-36fe-50f9-a30b-004ed29d3201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 16.2.12-tuxcare.8 of @angular/compiler-cli, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:b53c1b44-5ec3-5255-bde1-ec9e90d28b03",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 16.2.12-tuxcare.8 of @angular/compiler-cli, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:ad602490-c327-5ff5-a9c7-3c4cc717577f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 16.2.12-tuxcare.8 of @angular/compiler-cli, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:6a4030cb-2002-55f3-b158-84b1510cbcdb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 16.2.12-tuxcare.8 of @angular/compiler-cli, and is fixed in 16.2.12-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:3ffa2687-f14f-5757-9198-98f112d988ae",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 16.2.12-tuxcare.8 of @angular/compiler-cli, and is fixed in 16.2.12-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:09d0bdff-7224-55b3-a4ce-a796b8836856",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 16.2.12-tuxcare.8 of @angular/compiler-cli, and is fixed in 16.2.12-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:eb829693-0968-5c61-97e5-6b52d95d633e",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 16.2.12-tuxcare.8 of @angular/compiler-cli. not_affected \u2014 CVE-2026-88056 affects Angular versions 20.3.x, 21.2.x, and 22.x where a refactored URL parsing utility added String.prototype.trim() that strips Unicode whitespace, enabling SSRF bypasses. The target (Angular 16.2.12-tuxcare.12) is based on Angular 16.2.x architecture, which predates the vulnerable code pattern entirely. TuxCare created url.ts fresh on June 24, 2026 for CVE-2026-50168, modelin...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:23aac5d6-6287-5e74-a159-86c9ec7a594a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 16.2.12-tuxcare.8 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:65bce407-d0e3-5821-a4ef-89a6bcb8b6d2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 16.2.12-tuxcare.8 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:289f35a8-19f3-57cb-b13e-47ee039a92a6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 16.2.12-tuxcare.8 of @angular/compiler-cli."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/compiler-cli@16.2.12-tuxcare.8"
    }
  ]
}