{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:cc866813-0f36-546d-aa56-a673856b1ba0",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/core",
      "purl": "pkg:npm/%40angular/core@18.2.14-tuxcare.8",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.8",
      "version": "18.2.14-tuxcare.8",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:e347173e-c795-5014-9807-89a33a521c55",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.2.14-tuxcare.8 of @angular/core."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:3e0576a0-3560-5126-a781-6f7a01de15d6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 18.2.14-tuxcare.8 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:c3438bf1-a4a8-5db3-9e2e-8a764d2b0918",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 18.2.14-tuxcare.8 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:3785be2e-0b4a-507e-88ac-dbff48fca290",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 18.2.14-tuxcare.8 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:e2b6d2bf-5b36-5572-b0bd-266e58feb268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 18.2.14-tuxcare.8 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:6f55aaf1-5c9c-5469-bd17-8429899dc425",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 18.2.14-tuxcare.8 of @angular/core, and is fixed in 18.2.14-tuxcare.10."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:5f6214ea-7d20-50e8-8fe6-8ee815763dd7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 18.2.14-tuxcare.8 of @angular/core, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:6a62dec6-4f13-58ee-badc-4ff31bcb8ee0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 18.2.14-tuxcare.8 of @angular/core, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:8e031f20-ffe6-59c7-84b5-d20e30c2c6ed",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 18.2.14-tuxcare.8 of @angular/core, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:494ac411-34d1-5b8c-949c-b0561e93447d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 18.2.14-tuxcare.8 of @angular/core, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:12f5a484-cc10-5353-9f54-511487603e4c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 18.2.14-tuxcare.8 of @angular/core, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:89d17580-fa24-58aa-a1a7-7facb038a6d2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 18.2.14-tuxcare.8 of @angular/core, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:49c95139-0037-50d0-b71f-3184f67a370b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 18.2.14-tuxcare.8 of @angular/core, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:f3ceaed5-ed7c-5b5f-98a8-22aea6d5e07b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 18.2.14-tuxcare.8 of @angular/core, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:759dfba7-98be-5907-8119-605d8374cf99",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 18.2.14-tuxcare.8 of @angular/core, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:0736d11d-407c-574c-9b5d-8d867747c71f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 18.2.14-tuxcare.8 of @angular/core, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:0c44d533-5208-5d1e-b9e5-13f8992622ef",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 18.2.14-tuxcare.8 of @angular/core, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:cada0847-6098-5b33-9212-cca2f45f8c49",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 18.2.14-tuxcare.8 of @angular/core, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:3eba93a7-1313-587c-b10d-f4c1c834bb61",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 18.2.14-tuxcare.8 of @angular/core, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:70797bd5-5c69-5fbe-9bd8-d05b54d05af2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 18.2.14-tuxcare.8 of @angular/core, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:b33287f4-a5a4-546c-8a28-f2c842989af1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 18.2.14-tuxcare.8 of @angular/core, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:27a07300-038d-512e-99ba-cc4d952622aa",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 18.2.14-tuxcare.8 of @angular/core, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:e49734cf-63c0-5f98-a739-3b000f4910f1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 18.2.14-tuxcare.8 of @angular/core, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:542a76ae-9af2-5bbd-8939-7624dd3deead",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 18.2.14-tuxcare.8 of @angular/core. not_affected \u2014 The target version 18.2.14-tuxcare.13 is NOT affected by CVE-2026-88056. The vulnerable code pattern (calling String.prototype.trim() on URL strings before resolution) was never present in this version. The target uses a refactored parseUrl() implementation introduced via commit 49a60f6045 (May 2026) that correctly handles Unicode whitespace by percent-encoding it rather than stripping it, main...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:ce3fde6b-ad08-51b7-bb62-7de40ef377ef",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 18.2.14-tuxcare.8 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:96986534-459a-54a8-81da-98fed5b6da33",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 18.2.14-tuxcare.8 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:93ad7017-1325-5873-95d8-3692d24ae5d1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 18.2.14-tuxcare.8 of @angular/core."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/core@18.2.14-tuxcare.8"
    }
  ]
}