{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:37469398-3d48-5390-bad2-e1c50416d107",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/compiler-cli",
      "purl": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.10",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.10",
      "version": "17.3.12-tuxcare.10",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:ade4d3a5-0ab0-515e-b54c-225e063095ca",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.3.12-tuxcare.10 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:201ff246-5e88-56a0-808e-a428bc62fa7a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.3.12-tuxcare.10 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:c8b6b752-0371-5699-9875-4912fc84811a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.3.12-tuxcare.10 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:03d49afd-4b0c-565e-af8b-aecd2f03a5f1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.3.12-tuxcare.10 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:6571fca3-7d8c-5547-bec9-4acde5d2d2ea",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.3.12-tuxcare.10 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:25ab2ebb-98fa-515f-a6a2-163b82d123fc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.3.12-tuxcare.10 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:67376c15-2932-5164-8e36-0974209b4118",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 17.3.12-tuxcare.10 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:575b67c6-e94d-54f5-b633-a1d722fc7638",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 17.3.12-tuxcare.10 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:e4c39eae-45ed-5d31-a76b-56c14a6951b9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 17.3.12-tuxcare.10 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:061c636a-9182-5cc3-a3a7-c7e8396f2f57",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 17.3.12-tuxcare.10 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:73eefa31-cdb6-539b-b6b6-386bb5bf3865",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 17.3.12-tuxcare.10 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:7e52203d-b48e-5a53-b589-a7b1c3e04caf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 17.3.12-tuxcare.10 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:fc480bf2-28ed-5f3e-a05b-ed0ac78adfda",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 17.3.12-tuxcare.10 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:77da8300-c37f-504e-8a4a-d4ae3bf041bd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 17.3.12-tuxcare.10 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:801b6ec8-4ec0-5cec-b687-cfce9d18b817",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 17.3.12-tuxcare.10 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:0c28913b-eff7-5fc2-afdd-a1d3784fc72f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 17.3.12-tuxcare.10 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:983118ff-edc2-5e81-8e41-7d3562cf5bd2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 17.3.12-tuxcare.10 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:b616408d-211b-55de-a75d-c906718a42f3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 17.3.12-tuxcare.10 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:6cec97ee-b0dc-57bc-8c71-4dda0be79ae6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 17.3.12-tuxcare.10 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:d5910501-264b-581c-8f2e-01869a757e27",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 17.3.12-tuxcare.10 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:8aedd89a-352c-574a-b706-52afad6617ce",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 17.3.12-tuxcare.10 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:39036ea4-a5e5-591f-9403-618cc6a17e2c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 17.3.12-tuxcare.10 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:1217ceb9-8e71-5dfa-a24b-ef8413f1cdef",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 17.3.12-tuxcare.10 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:02a28a02-efe6-5a75-a5bd-fa4cdb9499e0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 17.3.12-tuxcare.10 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:cf9e089e-97a6-5902-bece-ce0641b14c5a",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.3.12-tuxcare.10 of @angular/compiler-cli. not_affected \u2014 Version 17.3.12 is not affected by CVE-2026-88056. The vulnerability involves String.prototype.trim() being applied during URL resolution in Angular's platform-server, converting validated same-origin URLs with Unicode whitespace into cross-origin protocol-relative URLs, leading to SSRF. This vulnerable code pattern was introduced in newer Angular versions (v20+) and does not exist in version 1...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:502db501-18af-59a2-ae7d-810fea7ed45d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 17.3.12-tuxcare.10 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:467d73d2-45b9-51c7-a302-484b075923bb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 17.3.12-tuxcare.10 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:2c536edd-7770-5776-a6e7-0653eeb85263",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 17.3.12-tuxcare.10 of @angular/compiler-cli."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.10"
    }
  ]
}