{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e63acc18-9523-5cbb-b23f-24e9d1f5865f",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/compiler-cli",
      "purl": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.3",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.3",
      "version": "8.2.14-tuxcare.3",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:b927098c-db6c-521e-af68-ab57dfdaddd1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-4231 affects version 8.2.14-tuxcare.3 of @angular/compiler-cli, and is fixed in 8.2.14-tuxcare.5."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:491b5a20-0a80-5b4a-bd9e-3560ed25c809",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 8.2.14-tuxcare.3 of @angular/compiler-cli, and is fixed in 8.2.14-tuxcare.10."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:70d2e433-4f1c-50c5-8c41-62afe2722815",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66412 affects version 8.2.14-tuxcare.3 of @angular/compiler-cli, and is fixed in 8.2.14-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:0f2f7ac7-7212-56cd-90de-0ccf3e47785b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 8.2.14-tuxcare.3 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:68f9eb05-c054-58b7-9e9a-0a9a092670da",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 8.2.14-tuxcare.3 of @angular/compiler-cli, and is fixed in 8.2.14-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:7fe4aa33-249d-5cb9-991f-87f55a6dd6c6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 8.2.14-tuxcare.3 of @angular/compiler-cli, and is fixed in 8.2.14-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:f24ccabc-5392-51b9-8ede-b8104685c93a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 8.2.14-tuxcare.3 of @angular/compiler-cli, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:b358ccda-6f6c-5a6e-8189-11b42c47936e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 8.2.14-tuxcare.3 of @angular/compiler-cli, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:dd8455a0-7d9b-5bf8-976e-e8e1f467fd9a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 8.2.14-tuxcare.3 of @angular/compiler-cli, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:a6946eef-7dff-53c0-b769-4bf0abc8636d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 8.2.14-tuxcare.3 of @angular/compiler-cli, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:09d6be3b-ceab-5c15-ab01-8db8a58bceb5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 8.2.14-tuxcare.3 of @angular/compiler-cli, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:23eda148-a96a-5058-9fe3-37ffa0e6b1ae",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 8.2.14-tuxcare.3 of @angular/compiler-cli, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:863c7494-037e-5715-bddf-db96918e5ac7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 8.2.14-tuxcare.3 of @angular/compiler-cli, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:983b0b4e-e2c0-55da-a039-4fd066504089",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 8.2.14-tuxcare.3 of @angular/compiler-cli, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:ac1d8cda-df84-5ad3-8d48-2018b1776c32",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 8.2.14-tuxcare.3 of @angular/compiler-cli, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:0e673624-48c6-5d8a-a080-fce60b2835ca",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 8.2.14-tuxcare.3 of @angular/compiler-cli, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:b69fcc10-a6ee-58b4-b130-bd33c921ad20",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 8.2.14-tuxcare.3 of @angular/compiler-cli, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:c8c11227-ddff-50e2-b082-fc200ccec605",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 8.2.14-tuxcare.3 of @angular/compiler-cli, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:20f6f225-d7e6-5727-b87d-3dc57a1315cb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 8.2.14-tuxcare.3 of @angular/compiler-cli, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:62f3eda6-9f7b-56b9-b624-6218fd7847b5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 8.2.14-tuxcare.3 of @angular/compiler-cli, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:62091292-5ae8-55ed-a854-4b3bc35b837b",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 8.2.14-tuxcare.3 of @angular/compiler-cli. not_affected \u2014 Angular 8.2.14 is NOT affected by CVE-2026-68945. The vulnerability exists in HttpTransferCache, a feature that automatically caches HTTP requests during SSR for client hydration. HttpTransferCache was introduced in Angular v16+ and does not exist in version 8.2.14. This version has only a manual TransferState key-value store with no automatic HttpClient integration, and no HTTP caching mechani...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:52f8aff8-e662-572e-ab4b-d9ba7907c552",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 8.2.14-tuxcare.3 of @angular/compiler-cli, and is fixed in 8.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:89283399-87e3-5dbf-822d-c53948bfe8cb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 8.2.14-tuxcare.3 of @angular/compiler-cli, and is fixed in 8.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:d5ccbcc9-2d1f-5fe9-8d3f-e9c9bee48bd5",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 8.2.14-tuxcare.3 of @angular/compiler-cli. not_affected \u2014 Angular 8.2.14 is NOT AFFECTED by CVE-2026-88056. The vulnerability requires a sophisticated URL resolution utility (`parseUrl` in `packages/platform-server/src/url.ts`) that calls `String.prototype.trim()` to strip Unicode whitespace, creating a discrepancy with WHATWG URL validation. This architecture was introduced in Angular v12+ (circa 2026 as TuxCare backports). Angular 8.2.14 (released N...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:fe478861-0c6a-5442-bea4-bef3f88ce903",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 8.2.14-tuxcare.3 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:56560010-fa06-58dc-b87b-9965dec33742",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 8.2.14-tuxcare.3 of @angular/compiler-cli. not_affected \u2014 Angular v8.2.14 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, provideClientHydration(), and withRequestsMadeViaParent() \u2014 all features that do not exist in this version. These features were introduced in Angular v16 (per patches/CVE-2026-50170.patch and patches/CVE-2026-54266.patch). The target uses the legacy NgModule-based HttpClientModule without automatic ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:d20a8310-d04a-5aa5-a62e-6fc4eded08dd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 8.2.14-tuxcare.3 of @angular/compiler-cli."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.3"
    }
  ]
}