{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:619094bd-0861-54c0-ad59-b63967529e09",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/compiler-cli",
      "purl": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.4",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.4",
      "version": "17.3.12-tuxcare.4",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:f4b1eec8-6c41-5539-acc5-4f99f8f2d95c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.3.12-tuxcare.4 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:93b3383b-1f09-549e-bdfa-7faaabe7e816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.3.12-tuxcare.4 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:35a8bfaa-49fe-51d8-8270-f71a4fa36d17",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66412 affects version 17.3.12-tuxcare.4 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.5."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:09ab4d04-4f75-5cee-af68-aa2865900b19",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22610 affects version 17.3.12-tuxcare.4 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.5."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:8d6a9a3a-481e-55d5-99e3-13c7a7848686",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 17.3.12-tuxcare.4 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:520830e1-5f56-5e34-aa6a-98dcf8db70d3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32635 affects version 17.3.12-tuxcare.4 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:81bb01dd-736c-5e25-9fec-231667455d21",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 17.3.12-tuxcare.4 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:bbf6aba2-5066-5585-8b56-fa0a02178f13",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 17.3.12-tuxcare.4 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:bc559ef8-01ca-5f82-a77e-0ccb7d5e9ca2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 17.3.12-tuxcare.4 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:ee9ee296-f9f3-5612-af96-d14e80d8a60e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 17.3.12-tuxcare.4 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:98845b21-044a-500b-8e4e-89ea920c8745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 17.3.12-tuxcare.4 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:99c0b90b-11b5-54a6-8c2f-4b8a4fbaf406",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 17.3.12-tuxcare.4 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:8ad1c803-c9c8-557f-b963-3b3f4d54269f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 17.3.12-tuxcare.4 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:7bb847fa-d950-51a5-ac1f-6f445a072733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 17.3.12-tuxcare.4 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:01f57b4e-1397-5ea6-8d1f-9510c713d037",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 17.3.12-tuxcare.4 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:65c6e57a-4b70-55dc-aede-c456eee48526",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 17.3.12-tuxcare.4 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:db2079b4-cc77-5878-a8b3-a1b4d28cb313",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 17.3.12-tuxcare.4 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:3d866c6e-a3d8-57dd-875a-70a598d6433e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 17.3.12-tuxcare.4 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:54108560-ae33-5c0f-b8ae-c1d4fbec5877",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 17.3.12-tuxcare.4 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:34172f9c-9520-551a-9be2-30de020744ea",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 17.3.12-tuxcare.4 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:ea2432ba-3bfa-562e-8320-e94e2dae4c99",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 17.3.12-tuxcare.4 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:79e85c86-a1dc-5d6a-b987-ffb65555ed5a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 17.3.12-tuxcare.4 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:ac6c39bf-2f82-58a9-a960-652d498df5b2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 17.3.12-tuxcare.4 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:b30abfc2-fac3-518d-8977-7fdb526552eb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 17.3.12-tuxcare.4 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:dd3d8998-9f8e-5a0d-b18a-33d4df93097b",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.3.12-tuxcare.4 of @angular/compiler-cli. not_affected \u2014 Version 17.3.12 is not affected by CVE-2026-88056. The vulnerability involves String.prototype.trim() being applied during URL resolution in Angular's platform-server, converting validated same-origin URLs with Unicode whitespace into cross-origin protocol-relative URLs, leading to SSRF. This vulnerable code pattern was introduced in newer Angular versions (v20+) and does not exist in version 1...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:79a8e66c-34c4-5f3f-9360-97e17458eb39",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 17.3.12-tuxcare.4 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e144b8d8-dc13-5359-a7a7-cc1898d4b2e4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 17.3.12-tuxcare.4 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:891a3937-8b5b-5240-8c15-b762ae25e039",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 17.3.12-tuxcare.4 of @angular/compiler-cli."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.4"
    }
  ]
}