{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:7306a5c3-c7f5-586b-b59c-769d0c2c1e05",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/core",
      "purl": "pkg:npm/%40angular/core@17.3.12-tuxcare.13",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.13",
      "version": "17.3.12-tuxcare.13",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:55a5ab7c-0a8a-5f57-8a81-23a466624eaf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.3.12-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:dd663cbf-fb0e-5eb9-ab92-124b970763dd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.3.12-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:7a7a2712-fd96-550d-983e-a9fc7d361b8a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.3.12-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:a4175074-e9ae-5a0f-a7bc-e68c11517eb0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.3.12-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:014b4905-1eab-560a-823b-0a1b17ec6f74",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.3.12-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:0ed2d36c-feb3-5a16-b584-0946c1aa5ec4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.3.12-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:9b568bfe-f394-544d-8ab9-62684dca03f7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 17.3.12-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:f7227c23-cd3c-5365-b5a6-23750c2ccb89",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 17.3.12-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:e6c45142-81f0-5c52-a39f-972bfea02c52",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 17.3.12-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:8b79eb23-ce62-5b22-af98-c0740dd8317b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 17.3.12-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:145e5d4a-9a17-5ee3-853d-26fb7dc9fd9e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 17.3.12-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:697f35bd-6b2d-53f4-8eaf-a126d88a7eae",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 17.3.12-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:7d92fca1-0c4d-5ea2-b92b-9d06d4e8a603",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 17.3.12-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:75cc1cd5-8082-55e0-8d9d-fdf94d975b79",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 17.3.12-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:42f81132-d8d6-57a0-8160-41d4ffb325d6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 17.3.12-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:9c348761-7023-59c1-9649-5ad70bd3e78c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 17.3.12-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:3f02b30b-1854-5ec4-8752-36cfc64bc83c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 17.3.12-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:c6073be4-42e2-585e-9587-2858af4e5a8f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 17.3.12-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:df3e1a35-971f-508c-84e8-dc7cb14e9c65",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 17.3.12-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:82d20f03-3f7a-57e6-9faa-01144e43b248",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 17.3.12-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:a27330ea-7517-5838-9f0b-e357d59b8360",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 17.3.12-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:938ec454-1958-5550-bc77-1d7e9567da76",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 17.3.12-tuxcare.13 of @angular/core, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:c9732f9b-d81c-571f-b1d8-59b00e5993ab",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 17.3.12-tuxcare.13 of @angular/core, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:80b08877-7e6b-51fb-b73e-522070b87703",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 17.3.12-tuxcare.13 of @angular/core, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:fda15a57-49f0-5318-a914-55cd2237e276",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.3.12-tuxcare.13 of @angular/core. not_affected \u2014 Version 17.3.12 is not affected by CVE-2026-88056. The vulnerability involves String.prototype.trim() being applied during URL resolution in Angular's platform-server, converting validated same-origin URLs with Unicode whitespace into cross-origin protocol-relative URLs, leading to SSRF. This vulnerable code pattern was introduced in newer Angular versions (v20+) and does not exist in version 1...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:98768e88-e1e0-5bcf-822b-d72f84345035",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 17.3.12-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:ad2cee1b-5877-5874-9dfc-2f6f94daa32d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 17.3.12-tuxcare.13 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:dda14aab-52f0-5a71-9756-e54c298a5b2a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 17.3.12-tuxcare.13 of @angular/core."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.13"
    }
  ]
}