{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:8a415fee-ece3-56b9-bfdc-87eeccd3a0fb",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/compiler",
      "purl": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.12",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.12",
      "version": "8.2.14-tuxcare.12",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:eb6bdf0a-b33e-53e7-ab45-91e5b0c1db4e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 8.2.14-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:c5ddfa96-0bfe-5b4a-970f-e34c6a365db5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 8.2.14-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:73268831-3353-55d3-870f-e85743c58e43",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 8.2.14-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:18e3f374-4a4c-5e19-869a-41ed8aaccca9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 8.2.14-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:5ca79f6a-7d37-5a0e-99dd-0c149d9cf1a7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 8.2.14-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:a4e0230b-64c9-5c17-87e7-9ab480c2945d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 8.2.14-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:25de2526-ae98-5da7-883b-c8125bd2d564",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 8.2.14-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:dd8f4eaa-e8af-55d3-86e5-f4bfd07edbeb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 8.2.14-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:75c28b05-f622-5e46-82ff-34c4ab8bb422",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 8.2.14-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:bf24f94e-f00e-5788-bef7-4e7c82d6327d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 8.2.14-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:381dc914-2955-51de-ba06-abfd67542295",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 8.2.14-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:28e84a88-cea7-5f1a-bfe6-3bf1904f0b6d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 8.2.14-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:30c786a0-a587-5327-9851-fb83af8e2933",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 8.2.14-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:3ced1468-e108-5242-b54a-2ebfb96e9a3f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 8.2.14-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:599cf5e6-1b20-5a76-8911-3b48ac417da6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 8.2.14-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:9f8b367d-c384-5a4c-b047-3307f4724a48",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 8.2.14-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:32349d82-4a54-5dff-8106-d7a5af78ecb6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 8.2.14-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:f11eefd3-233e-51b9-aa77-81ec9d8dcbd4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 8.2.14-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:e46d439a-2aca-5a19-8b1d-52fd263c0cd5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 8.2.14-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:6958b291-94d8-52f7-97bd-0490d3b6a5c6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 8.2.14-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:95c09446-21d6-5c12-8815-e8caaefa464f",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 8.2.14-tuxcare.12 of @angular/compiler. not_affected \u2014 Angular 8.2.14 is NOT affected by CVE-2026-68945. The vulnerability exists in HttpTransferCache, a feature that automatically caches HTTP requests during SSR for client hydration. HttpTransferCache was introduced in Angular v16+ and does not exist in version 8.2.14. This version has only a manual TransferState key-value store with no automatic HttpClient integration, and no HTTP caching mechani...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:4ce876fc-5c30-591b-9f56-3be3001c0124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 8.2.14-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:655349fa-6477-575f-bd13-35f516906811",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 8.2.14-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:5bb4303e-15b7-53a7-b4cd-0993e26e5d10",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 8.2.14-tuxcare.12 of @angular/compiler. not_affected \u2014 Angular 8.2.14 is NOT AFFECTED by CVE-2026-88056. The vulnerability requires a sophisticated URL resolution utility (`parseUrl` in `packages/platform-server/src/url.ts`) that calls `String.prototype.trim()` to strip Unicode whitespace, creating a discrepancy with WHATWG URL validation. This architecture was introduced in Angular v12+ (circa 2026 as TuxCare backports). Angular 8.2.14 (released N...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:b8d42839-8b5a-57bb-a38a-44ff6780a422",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 8.2.14-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:faaa51b0-d2cd-52e3-89bd-9ca958b091c8",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 8.2.14-tuxcare.12 of @angular/compiler. not_affected \u2014 Angular v8.2.14 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, provideClientHydration(), and withRequestsMadeViaParent() \u2014 all features that do not exist in this version. These features were introduced in Angular v16 (per patches/CVE-2026-50170.patch and patches/CVE-2026-54266.patch). The target uses the legacy NgModule-based HttpClientModule without automatic ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:0c3644fb-984a-590c-bd81-d839f36f4787",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 8.2.14-tuxcare.12 of @angular/compiler."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/compiler@8.2.14-tuxcare.12"
    }
  ]
}