{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:294532a6-44d9-59f2-aea4-6f9b16e7694b",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/compiler-cli",
      "purl": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.4",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.4",
      "version": "8.2.14-tuxcare.4",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:ac477926-35be-5487-9c36-2372a9378029",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-4231 affects version 8.2.14-tuxcare.4 of @angular/compiler-cli, and is fixed in 8.2.14-tuxcare.5."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:573782ea-6f61-592c-aae3-e06f48225417",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 8.2.14-tuxcare.4 of @angular/compiler-cli, and is fixed in 8.2.14-tuxcare.10."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:d0c10dc3-d929-5988-9082-d05eefe00932",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 8.2.14-tuxcare.4 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:d68ec14c-b906-59aa-8764-73e89791c2b9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 8.2.14-tuxcare.4 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:880d06c2-dbfe-5b99-8e8b-837d41002a83",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 8.2.14-tuxcare.4 of @angular/compiler-cli, and is fixed in 8.2.14-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:28f93d77-8b7b-5c9a-b2ed-5e3ad752f31f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 8.2.14-tuxcare.4 of @angular/compiler-cli, and is fixed in 8.2.14-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:d08b4bf5-694c-56b6-ba0f-aaa7c0ab0074",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 8.2.14-tuxcare.4 of @angular/compiler-cli, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:0872e7d6-0048-5404-8a26-733cddd09076",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 8.2.14-tuxcare.4 of @angular/compiler-cli, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:7e13576d-3992-5ade-84c7-9c8e973993fd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 8.2.14-tuxcare.4 of @angular/compiler-cli, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:bd2efba9-67d0-5507-a304-f0c0c946288b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 8.2.14-tuxcare.4 of @angular/compiler-cli, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a9644a98-b5eb-5f31-8579-d2990d53c02a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 8.2.14-tuxcare.4 of @angular/compiler-cli, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:76ad05e7-2fde-5b03-8273-c27fc4708d64",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 8.2.14-tuxcare.4 of @angular/compiler-cli, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:101a4013-b85e-5034-bd92-2eb98b7442c9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 8.2.14-tuxcare.4 of @angular/compiler-cli, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:ccaa27c7-c724-578c-8376-15cd4f7f02e2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 8.2.14-tuxcare.4 of @angular/compiler-cli, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:2b3004b3-7a97-5788-b431-aaa044f022b0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 8.2.14-tuxcare.4 of @angular/compiler-cli, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:1e44ae77-1651-56c5-8b07-87b67a61adf6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 8.2.14-tuxcare.4 of @angular/compiler-cli, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:bc18d1ca-e3b3-5ae2-a709-311649c2bfe0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 8.2.14-tuxcare.4 of @angular/compiler-cli, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:4e7c9281-f385-5881-b88a-fdc67cde2c5b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 8.2.14-tuxcare.4 of @angular/compiler-cli, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:67a60f14-4768-53ee-849c-1d325b50231d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 8.2.14-tuxcare.4 of @angular/compiler-cli, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a86e8eea-f406-53ce-9e17-2a9dad06b09d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 8.2.14-tuxcare.4 of @angular/compiler-cli, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:8de56a82-7411-55e7-9079-1e28687a1a52",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 8.2.14-tuxcare.4 of @angular/compiler-cli. not_affected \u2014 Angular 8.2.14 is NOT affected by CVE-2026-68945. The vulnerability exists in HttpTransferCache, a feature that automatically caches HTTP requests during SSR for client hydration. HttpTransferCache was introduced in Angular v16+ and does not exist in version 8.2.14. This version has only a manual TransferState key-value store with no automatic HttpClient integration, and no HTTP caching mechani...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:64334f63-31a3-5b44-a5be-cdf624a01a9e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 8.2.14-tuxcare.4 of @angular/compiler-cli, and is fixed in 8.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:5c8117ae-dfb4-56be-a785-b706786784fe",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 8.2.14-tuxcare.4 of @angular/compiler-cli, and is fixed in 8.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:9f23489e-5bca-5111-aa6a-8aaea4edf833",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 8.2.14-tuxcare.4 of @angular/compiler-cli. not_affected \u2014 Angular 8.2.14 is NOT AFFECTED by CVE-2026-88056. The vulnerability requires a sophisticated URL resolution utility (`parseUrl` in `packages/platform-server/src/url.ts`) that calls `String.prototype.trim()` to strip Unicode whitespace, creating a discrepancy with WHATWG URL validation. This architecture was introduced in Angular v12+ (circa 2026 as TuxCare backports). Angular 8.2.14 (released N...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:7dd2e789-3e7c-5505-a1e3-79a653e66102",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 8.2.14-tuxcare.4 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:2125534a-596e-5b3f-b08f-0aa93ecd1f68",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 8.2.14-tuxcare.4 of @angular/compiler-cli. not_affected \u2014 Angular v8.2.14 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, provideClientHydration(), and withRequestsMadeViaParent() \u2014 all features that do not exist in this version. These features were introduced in Angular v16 (per patches/CVE-2026-50170.patch and patches/CVE-2026-54266.patch). The target uses the legacy NgModule-based HttpClientModule without automatic ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:39c858db-45a6-5022-b5d6-14efb16610b5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 8.2.14-tuxcare.4 of @angular/compiler-cli."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/compiler-cli@8.2.14-tuxcare.4"
    }
  ]
}