{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:cbc80982-a061-50eb-828f-676a89c96f5a",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/core",
      "purl": "pkg:npm/%40angular/core@18.2.14-tuxcare.2",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.2",
      "version": "18.2.14-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d6872da0-5c4d-52cd-8682-c6ed89d590fa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.2.14-tuxcare.2 of @angular/core."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:013f7771-0d5d-5de5-9d67-84661ed4fc2e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66412 affects version 18.2.14-tuxcare.2 of @angular/core, and is fixed in 18.2.14-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:60a4d920-0b57-5cb5-a47e-4d59735ebff6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22610 affects version 18.2.14-tuxcare.2 of @angular/core, and is fixed in 18.2.14-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:af6ede2e-da89-5a74-a24c-4efdcd9ec0bd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 18.2.14-tuxcare.2 of @angular/core, and is fixed in 18.2.14-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f1aaf13a-b988-5ca9-8d75-ca3f169595f4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32635 affects version 18.2.14-tuxcare.2 of @angular/core, and is fixed in 18.2.14-tuxcare.5."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d03ae33a-f360-5f24-8f5e-94f431e9b552",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 18.2.14-tuxcare.2 of @angular/core, and is fixed in 18.2.14-tuxcare.10."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7a701c59-19f4-5d67-b879-2d6c03be1251",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 18.2.14-tuxcare.2 of @angular/core, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:312cdeb0-2800-590d-9fa4-a06e41c23d8b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 18.2.14-tuxcare.2 of @angular/core, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:563fd128-24cd-51dd-9fcb-84be8231087a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 18.2.14-tuxcare.2 of @angular/core, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:affc030b-d83a-50fe-b6f9-0f844cd95234",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 18.2.14-tuxcare.2 of @angular/core, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f620254d-1c42-55a9-aec2-9e6e3509b986",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 18.2.14-tuxcare.2 of @angular/core, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:751c9ffa-32b0-518e-97df-a2ebf6f03213",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 18.2.14-tuxcare.2 of @angular/core, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b90e0683-571b-519e-b257-875929d563b7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 18.2.14-tuxcare.2 of @angular/core, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7da748d1-f643-54fb-b912-e3e7c05f3a3b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 18.2.14-tuxcare.2 of @angular/core, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3eda0bb5-ebf9-58c4-9107-6e8b7df115db",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 18.2.14-tuxcare.2 of @angular/core, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4cb3a137-f114-50c8-b2f2-61e6de141299",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 18.2.14-tuxcare.2 of @angular/core, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:946ee2b4-078a-55fd-b121-5109f769c189",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 18.2.14-tuxcare.2 of @angular/core, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:9bd49d3e-fb40-5cf3-b9d1-03b7098f2f7d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 18.2.14-tuxcare.2 of @angular/core, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:af3420d7-739f-5ca5-82a6-b60db25df6aa",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 18.2.14-tuxcare.2 of @angular/core, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:418f0475-8432-5247-995a-ec9ec9a7af5c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 18.2.14-tuxcare.2 of @angular/core, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4ce6990c-245d-55bd-864f-60b083c79b09",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 18.2.14-tuxcare.2 of @angular/core, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2046b590-f936-529c-97db-6e2e870acd23",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 18.2.14-tuxcare.2 of @angular/core, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ef41cab5-331c-5e07-bf33-c15342eb817b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 18.2.14-tuxcare.2 of @angular/core, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:78d9ffcb-73a1-5826-b14a-22019299b81f",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 18.2.14-tuxcare.2 of @angular/core. not_affected \u2014 The target version 18.2.14-tuxcare.13 is NOT affected by CVE-2026-88056. The vulnerable code pattern (calling String.prototype.trim() on URL strings before resolution) was never present in this version. The target uses a refactored parseUrl() implementation introduced via commit 49a60f6045 (May 2026) that correctly handles Unicode whitespace by percent-encoding it rather than stripping it, main...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:116600dc-47bf-56fe-b72f-c02a07cc4cea",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 18.2.14-tuxcare.2 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d1032883-2536-5eff-a74a-4eb6e1db0fbd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 18.2.14-tuxcare.2 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3618c268-3300-5bb6-a2a4-e6692f41fb69",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 18.2.14-tuxcare.2 of @angular/core."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.2"
    }
  ]
}