{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:8d75640b-dcb3-5476-9fd9-643cfe45f020",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/compiler-cli",
      "purl": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.8",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.8",
      "version": "17.3.12-tuxcare.8",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:21aa02f7-b702-5d7b-9fe0-8677c78b4741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.3.12-tuxcare.8 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:ccd6664a-64af-531f-93fd-60cfe5ce1310",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.3.12-tuxcare.8 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:65bb65fd-9c1b-50c5-9121-4c0382af6e10",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.3.12-tuxcare.8 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:c8b2eac5-2384-58e0-9ee3-7fc66b297fe7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.3.12-tuxcare.8 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:090e4edb-dbeb-5928-a984-e82dd0419d73",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 17.3.12-tuxcare.8 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:c0d88ead-beee-5d79-8755-775b0e05badb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.3.12-tuxcare.8 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:b1b786e8-c86b-52eb-b52d-c93a3e0ddc3d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 17.3.12-tuxcare.8 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:54d66ebd-8ca3-587b-b770-03f44f46d27b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 17.3.12-tuxcare.8 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:9bc40c43-fafc-55fa-a13e-c7e6ab20495f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 17.3.12-tuxcare.8 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:92c0f43d-31de-5f22-ace8-aba656b83dec",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 17.3.12-tuxcare.8 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:ea77abee-dff6-505f-af69-a286211f641e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 17.3.12-tuxcare.8 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:6e6b79ad-8295-5fe5-9f9f-0b79b7def6c7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 17.3.12-tuxcare.8 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:c4e10cf0-7f52-5362-a5f1-b231de6932d5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 17.3.12-tuxcare.8 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:7518f72e-7819-50d1-85fa-a9ba5377fad8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 17.3.12-tuxcare.8 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:e294d06f-e7c9-5991-acca-681ab3070684",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 17.3.12-tuxcare.8 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:6d696855-a83c-5381-bd77-6eb94babed62",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 17.3.12-tuxcare.8 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:fce74653-6c6a-539e-9b86-01bf80b74961",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 17.3.12-tuxcare.8 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:e7f3e060-b13a-5f78-a4d4-5fa1b2ab630a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 17.3.12-tuxcare.8 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:fe27e34c-8016-5b6c-ad57-3697876e1858",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 17.3.12-tuxcare.8 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:a85e61c7-1cbc-52a7-95a8-13f2401f0d1d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 17.3.12-tuxcare.8 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:7e1c881f-ed9d-56b4-82fa-fcd887b59594",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 17.3.12-tuxcare.8 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:518a2c53-4ac5-509d-a8b4-3009e3123247",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 17.3.12-tuxcare.8 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:d2f58236-974f-5eb7-85d1-8cd4941d04fe",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 17.3.12-tuxcare.8 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:79fc3d15-6808-5753-9c16-6171494d3779",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 17.3.12-tuxcare.8 of @angular/compiler-cli, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:5e6f28ef-7fef-54df-b4e5-a5d9b44fd395",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.3.12-tuxcare.8 of @angular/compiler-cli. not_affected \u2014 Version 17.3.12 is not affected by CVE-2026-88056. The vulnerability involves String.prototype.trim() being applied during URL resolution in Angular's platform-server, converting validated same-origin URLs with Unicode whitespace into cross-origin protocol-relative URLs, leading to SSRF. This vulnerable code pattern was introduced in newer Angular versions (v20+) and does not exist in version 1...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:fa5c1f60-58f5-512f-8c18-d9a28f54e145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 17.3.12-tuxcare.8 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:d63e2107-7af8-505c-b6b3-b56b0fab9bae",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 17.3.12-tuxcare.8 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:afe56a35-9be5-5319-9647-b19dc59c770b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 17.3.12-tuxcare.8 of @angular/compiler-cli."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/compiler-cli@17.3.12-tuxcare.8"
    }
  ]
}