{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:5210b95b-8dce-5cc1-aa82-8fae8cc8a9ad",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/core",
      "purl": "pkg:npm/%40angular/core@17.3.12-tuxcare.4",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.4",
      "version": "17.3.12-tuxcare.4",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:87eae84d-cc78-55af-84c8-1110d38dada8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.3.12-tuxcare.4 of @angular/core."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:f6bb79e5-147f-5665-9315-81b97d52244b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.3.12-tuxcare.4 of @angular/core."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a9d9827b-0be1-5fc6-bac4-e0fab71174c9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66412 affects version 17.3.12-tuxcare.4 of @angular/core, and is fixed in 17.3.12-tuxcare.5."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:50788071-fe4a-5753-ba50-9cf7d6936ea8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22610 affects version 17.3.12-tuxcare.4 of @angular/core, and is fixed in 17.3.12-tuxcare.5."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:531e9236-c812-5e77-b79b-5751834f3138",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 17.3.12-tuxcare.4 of @angular/core, and is fixed in 17.3.12-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:7c04875f-14ba-5078-8d22-70bebbba63f4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32635 affects version 17.3.12-tuxcare.4 of @angular/core, and is fixed in 17.3.12-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:909e198a-b057-5d96-853b-39fc220db76d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 17.3.12-tuxcare.4 of @angular/core, and is fixed in 17.3.12-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:05754e25-2d93-5b58-a76d-b806c94d4489",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 17.3.12-tuxcare.4 of @angular/core, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:584b5c89-78c0-5a30-86d4-5503242c1d2d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 17.3.12-tuxcare.4 of @angular/core, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:62cd908d-d220-5bac-865d-d14653a64583",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 17.3.12-tuxcare.4 of @angular/core, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:1c2c738b-b869-58be-9164-48ae7c1f73bc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 17.3.12-tuxcare.4 of @angular/core, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e7c386d9-b655-5e5a-837c-8c578085393a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 17.3.12-tuxcare.4 of @angular/core, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:5a0e9a29-f623-52b3-87f7-09e1290d5431",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 17.3.12-tuxcare.4 of @angular/core, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:4654174d-7dd4-5fd6-9166-bffb4502c546",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 17.3.12-tuxcare.4 of @angular/core, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:47d7ec61-3c7c-5d29-b3da-f97b586a6ec6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 17.3.12-tuxcare.4 of @angular/core, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:6f8ab8a6-8c45-567b-9557-ef832b92c87f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 17.3.12-tuxcare.4 of @angular/core, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a1c10d4f-6f16-5c85-bbf5-d33cf34c6d56",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 17.3.12-tuxcare.4 of @angular/core, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e2735bba-f6a8-53b9-b555-bd0f5950a2d7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 17.3.12-tuxcare.4 of @angular/core, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:c4718ac5-5c6d-5cb3-9f25-224e7a92ac62",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 17.3.12-tuxcare.4 of @angular/core, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e82ac4bf-aa5e-5aab-8ac1-ded5b8a594e7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 17.3.12-tuxcare.4 of @angular/core, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:b7b77148-5832-5a19-91ff-64b8fcb89b6e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 17.3.12-tuxcare.4 of @angular/core, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:36c7a077-35fd-59b0-9cd8-b205421a7578",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 17.3.12-tuxcare.4 of @angular/core, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:16d1977b-cb60-5ed4-8a68-63cd53092df3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 17.3.12-tuxcare.4 of @angular/core, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:9a6f0d59-0171-50ff-afa1-1cd39628a86b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 17.3.12-tuxcare.4 of @angular/core, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:5ff6937e-e7c1-5d37-8a13-577eb448a21e",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.3.12-tuxcare.4 of @angular/core. not_affected \u2014 Version 17.3.12 is not affected by CVE-2026-88056. The vulnerability involves String.prototype.trim() being applied during URL resolution in Angular's platform-server, converting validated same-origin URLs with Unicode whitespace into cross-origin protocol-relative URLs, leading to SSRF. This vulnerable code pattern was introduced in newer Angular versions (v20+) and does not exist in version 1...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e8e35ac5-d74d-5a6f-9c18-e41269f50410",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 17.3.12-tuxcare.4 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:fc9d6d79-da8c-5640-b1c8-c185b9c1ff8d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 17.3.12-tuxcare.4 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:38c11ab5-3bd2-55d0-aea9-70c6cf9c3c83",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 17.3.12-tuxcare.4 of @angular/core."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/core@17.3.12-tuxcare.4"
    }
  ]
}