{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:69b7c329-d56d-572e-982a-10d0fd50b80f",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/compiler",
      "purl": "pkg:npm/%40angular/compiler@17.3.12-tuxcare.4",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/compiler@17.3.12-tuxcare.4",
      "version": "17.3.12-tuxcare.4",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:9994be59-c595-588d-b538-f0e1698feec6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.3.12-tuxcare.4 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:914f9c2c-cfb3-5f54-9428-2766e4ce5ac7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.3.12-tuxcare.4 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:21f9e9de-50c6-5d39-b2d9-c16fe7b1550d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66412 affects version 17.3.12-tuxcare.4 of @angular/compiler, and is fixed in 17.3.12-tuxcare.5."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:3fb9181f-ec4b-556b-9c71-037832c3e07d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22610 affects version 17.3.12-tuxcare.4 of @angular/compiler, and is fixed in 17.3.12-tuxcare.5."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:1e8b67ce-1e5a-5b3c-a2bd-4108dc75859e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 17.3.12-tuxcare.4 of @angular/compiler, and is fixed in 17.3.12-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:0868b5be-c486-59e5-8762-b8971985a2e4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32635 affects version 17.3.12-tuxcare.4 of @angular/compiler, and is fixed in 17.3.12-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:88adb0bb-f4a4-5341-bc6f-15992c1d469f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 17.3.12-tuxcare.4 of @angular/compiler, and is fixed in 17.3.12-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:b37fc8c8-fda4-5f61-9d2d-0f4677f7d39f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 17.3.12-tuxcare.4 of @angular/compiler, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:66d074ae-2681-5d06-8ff9-16e2a0c223af",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 17.3.12-tuxcare.4 of @angular/compiler, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:505dd5d6-9602-5993-ad1f-cd2018047d5e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 17.3.12-tuxcare.4 of @angular/compiler, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:56ff18d3-3cb5-59f3-b0cf-6e347301d033",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 17.3.12-tuxcare.4 of @angular/compiler, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:84f272be-d8c2-53a6-ae0d-5e48e408fe60",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 17.3.12-tuxcare.4 of @angular/compiler, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:75806b11-5f12-5c6e-9e69-94f4c7a430f4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 17.3.12-tuxcare.4 of @angular/compiler, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:388dde25-e7d3-5a59-b31e-7c66c720b502",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 17.3.12-tuxcare.4 of @angular/compiler, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:65620e2a-1ac5-5ee1-930f-6f448ec3d096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 17.3.12-tuxcare.4 of @angular/compiler, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:40534767-a3ee-5902-bca6-0c99a0d6b22d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 17.3.12-tuxcare.4 of @angular/compiler, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:647dcdc4-9661-591e-977a-49fe610d3fbf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 17.3.12-tuxcare.4 of @angular/compiler, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:6e98e7e5-6351-592f-8c2c-42ab928f4d79",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 17.3.12-tuxcare.4 of @angular/compiler, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:5ecd997f-b90a-553b-9877-2aeae06a20ec",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 17.3.12-tuxcare.4 of @angular/compiler, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:ffaff2af-ccf6-5c72-b49a-a368006f6706",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 17.3.12-tuxcare.4 of @angular/compiler, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:383fdea0-09d8-5799-aadf-72d884afdeb7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 17.3.12-tuxcare.4 of @angular/compiler, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:997e4104-669c-59bb-a7c9-3cbb94d17719",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 17.3.12-tuxcare.4 of @angular/compiler, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:01a044e1-2d2c-51db-91c1-63f1baf5b576",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 17.3.12-tuxcare.4 of @angular/compiler, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:8d02a42f-b852-541f-a1c5-898924d5243a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 17.3.12-tuxcare.4 of @angular/compiler, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:b5a617df-b747-5cf6-a3c9-8e11f8f7d4f7",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.3.12-tuxcare.4 of @angular/compiler. not_affected \u2014 Version 17.3.12 is not affected by CVE-2026-88056. The vulnerability involves String.prototype.trim() being applied during URL resolution in Angular's platform-server, converting validated same-origin URLs with Unicode whitespace into cross-origin protocol-relative URLs, leading to SSRF. This vulnerable code pattern was introduced in newer Angular versions (v20+) and does not exist in version 1...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:479571ab-cb66-5eae-be2f-afeffa65895b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 17.3.12-tuxcare.4 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:c3e92441-af8a-5623-ae0e-39b93a5a4e68",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 17.3.12-tuxcare.4 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:74af7eaa-ab5b-5ad0-ab82-d6b4874bb552",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 17.3.12-tuxcare.4 of @angular/compiler."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/compiler@17.3.12-tuxcare.4"
    }
  ]
}