{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3a4ebc7c-bb65-5233-8d6e-3a2a2dde5042",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/compiler",
      "purl": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.3",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.3",
      "version": "16.2.11-tuxcare.3",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:5ed83d01-8acf-5d38-9c73-3b1c46abdf5a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59052 affects version 16.2.11-tuxcare.3 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:fcfb497c-2970-56c7-bf67-a1acbd2012af",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 16.2.11-tuxcare.3 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:9ccd875a-6678-50d7-88a1-5249af683c66",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 16.2.11-tuxcare.3 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:af78ed04-bbca-5d31-9ace-5e964254a274",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 16.2.11-tuxcare.3 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:dc0b9862-94d3-5c95-8c04-6f3773f58f05",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 16.2.11-tuxcare.3 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:2e3055af-f8a3-5e35-b677-c20b33ecf523",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 16.2.11-tuxcare.3 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:5df8e2ec-3e41-56a6-b859-914a770e90e4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 16.2.11-tuxcare.3 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:e176c2e8-c661-5ae5-8b6b-4e533c2bfa30",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 16.2.11-tuxcare.3 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:369b54bf-08e7-528a-846f-237e46ac83eb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 16.2.11-tuxcare.3 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:657f9ce4-ea4a-5b6a-995a-c2668e5a6bcf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 16.2.11-tuxcare.3 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:92b37397-e3db-5e99-8a70-97ec4b05e972",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 16.2.11-tuxcare.3 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:fd087714-8eed-5890-a4c5-4d1344ee47d4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 16.2.11-tuxcare.3 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:60c1b2a9-c000-55c3-b874-bb2bb3e0184b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 16.2.11-tuxcare.3 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:ef3c0ab2-cdf6-5b2e-a12c-33348d1b0680",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 16.2.11-tuxcare.3 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:73b4d9b9-28b1-56db-aa87-dc2afb473e9c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 16.2.11-tuxcare.3 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:e917ea5a-d0f3-5cce-b029-3350abf42966",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 16.2.11-tuxcare.3 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:3a87fbb5-9093-590f-bc40-f566e21df723",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 16.2.11-tuxcare.3 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:b530638d-9f39-5a62-bf13-f7de1287fb63",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 16.2.11-tuxcare.3 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:0a98dbd6-5d6c-5358-9531-62758f9e7607",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 16.2.11-tuxcare.3 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:f37645fd-cd89-5c7c-8ec4-da6d7806b02a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 16.2.11-tuxcare.3 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:5faebba0-d34c-5827-9b37-b4c6fb95598e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 16.2.11-tuxcare.3 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:4edd5f25-ac29-53a9-879c-d057a51a5c48",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 16.2.11-tuxcare.3 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:10671e09-02f7-53c8-a5b4-72eb0a820ab4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 16.2.11-tuxcare.3 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:7f480a98-cc12-5641-9aba-db9a2228ae1c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 16.2.11-tuxcare.3 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:5fe7721b-e868-504c-a5b1-bbb85a93b5a1",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 16.2.11-tuxcare.3 of @angular/compiler. not_affected \u2014 Angular 16.2.11-tuxcare.2 is NOT affected by CVE-2026-88056. The vulnerability requires WHATWG URL validation combined with String.prototype.trim() on URLs during SSR, creating a discrepancy that enables SSRF. While the target uses WHATWG URL parsing (backported in commit c03fbfd7cc for CVE-2026-50168), it does NOT call String.prototype.trim() on URLs. The attack chain is broken at the trim() s...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:db688bb8-cb8e-56d5-9290-73b4a56d0062",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 16.2.11-tuxcare.3 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:61cd3ce6-0a1d-5af0-8db1-18979ce3712e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 16.2.11-tuxcare.3 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:f6d1c8bb-2c46-5b5c-9abd-4350875ec254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 16.2.11-tuxcare.3 of @angular/compiler."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.3"
    }
  ]
}