{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:6c136839-e8ce-5cdc-8c11-107224361674",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/core",
      "purl": "pkg:npm/%40angular/core@17.3.12-tuxcare.12",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.12",
      "version": "17.3.12-tuxcare.12",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:a6758443-6ab3-5efe-a478-fb538b32d3cd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.3.12-tuxcare.12 of @angular/core."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:13de2945-e945-5ff4-ad09-4a03db67e38c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.3.12-tuxcare.12 of @angular/core."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:52f83c72-8998-584e-8337-0845072ff2e3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.3.12-tuxcare.12 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:f6e5a5ed-a22f-5274-bd27-e252379aa97d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.3.12-tuxcare.12 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:0695a104-b185-5921-9502-6904fbf9a4d9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.3.12-tuxcare.12 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:59c12784-ab1a-5313-87ac-db921e2394ad",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.3.12-tuxcare.12 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:6b4d5799-883d-5a36-aef1-9bf05f399672",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 17.3.12-tuxcare.12 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:2b821c38-26e8-5bef-86bd-4e8f304b2fc6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 17.3.12-tuxcare.12 of @angular/core, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:ca736c90-37d1-55f0-886e-f5d106f06a63",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 17.3.12-tuxcare.12 of @angular/core, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:c3dc189f-12ef-5e44-8884-d8b359ea5c05",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 17.3.12-tuxcare.12 of @angular/core, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:cae7975b-65f1-5012-a75a-1a59688e12c9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 17.3.12-tuxcare.12 of @angular/core, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:7834e437-d29e-5560-8123-4328b7312df9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 17.3.12-tuxcare.12 of @angular/core, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:00a8f159-3c4a-5c4a-a25b-aa1d0850dd51",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 17.3.12-tuxcare.12 of @angular/core, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:b0bb343b-fe6e-579d-8e57-a3765dbd13cb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 17.3.12-tuxcare.12 of @angular/core, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:e7bd7e9e-4fe8-5841-a69e-f0db88a91f47",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 17.3.12-tuxcare.12 of @angular/core, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:07de4118-0149-5825-9ad6-fe10ffcfd401",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 17.3.12-tuxcare.12 of @angular/core, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:e9bbc78f-ed65-57e9-a0f6-ad536d923d81",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 17.3.12-tuxcare.12 of @angular/core, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:8ef0bff2-4677-5201-bf0c-9f8744620983",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 17.3.12-tuxcare.12 of @angular/core, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:908af720-b3ec-5063-82d1-97e8e1dad6dd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 17.3.12-tuxcare.12 of @angular/core, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:39f87752-946f-5acb-84a6-c953a017f927",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 17.3.12-tuxcare.12 of @angular/core, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:b1d24544-bba1-54c7-8f62-a3ef7ee4b5c7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 17.3.12-tuxcare.12 of @angular/core, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:7de2f11f-3ede-5f20-b332-dc64ff837a34",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 17.3.12-tuxcare.12 of @angular/core, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:20cb0ae2-ee35-51bc-8092-3605b62964ed",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 17.3.12-tuxcare.12 of @angular/core, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:93471f0b-96c2-5ee9-a233-e3f4683de897",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 17.3.12-tuxcare.12 of @angular/core, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:93d439c5-84bb-57e4-95b4-62719a49d8ca",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.3.12-tuxcare.12 of @angular/core. not_affected \u2014 Version 17.3.12 is not affected by CVE-2026-88056. The vulnerability involves String.prototype.trim() being applied during URL resolution in Angular's platform-server, converting validated same-origin URLs with Unicode whitespace into cross-origin protocol-relative URLs, leading to SSRF. This vulnerable code pattern was introduced in newer Angular versions (v20+) and does not exist in version 1...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:322c3d52-a05c-517e-b049-2e04b95055be",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 17.3.12-tuxcare.12 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:98357aeb-6612-5ae7-b00d-ae1601971c20",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 17.3.12-tuxcare.12 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:e8e8ad9f-6f80-5fb3-af25-300a9d82bee2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 17.3.12-tuxcare.12 of @angular/core."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.12"
    }
  ]
}