{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3fe6e83e-a10c-5e00-a5fb-aeeaee86dec2",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/elements",
      "purl": "pkg:npm/%40angular/elements@12.2.17",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/elements@12.2.17",
      "version": "12.2.17",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:be530309-e9e8-599c-bd7a-733319a7d953",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 12.2.17 of @angular/elements, and is fixed in 12.2.17-tuxcare.8."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:804590cf-21f5-5f19-b599-fa22c0e14649",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66412 affects version 12.2.17 of @angular/elements, and is fixed in 12.2.17-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:7ee9e59b-c6f6-5c67-8c30-33369a1f68de",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22610 affects version 12.2.17 of @angular/elements, and is fixed in 12.2.17-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:9be31595-9e06-5b1a-a90f-5b41e876681a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 12.2.17 of @angular/elements, and is fixed in 12.2.17-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:9a70626a-9f30-5be6-bea3-e8c1051015ee",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 12.2.17 of @angular/elements, and is fixed in 12.2.17-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:c8d76555-f2d3-59be-b481-6593ada313c7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 12.2.17 of @angular/elements, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:8cf1b8e4-9102-5b8e-b852-2e26aee8559e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 12.2.17 of @angular/elements, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:9ae78315-aad0-5ca7-ac38-b4632221062b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 12.2.17 of @angular/elements, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:c1203c48-d44d-532f-b40a-e0ba73ca2f50",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 12.2.17 of @angular/elements, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:9613b2dd-0945-5016-9eb3-ac209ce907a0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 12.2.17 of @angular/elements, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:6806a0e7-8d88-5ff4-863c-9995d91307b1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 12.2.17 of @angular/elements, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:ea69a44f-d09f-55e7-859f-d2fb1890602b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 12.2.17 of @angular/elements, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:e4367f6a-1cb5-5d99-a174-4ecbd6bb8852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 12.2.17 of @angular/elements, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:f0a9ee3b-770a-589e-803b-3fe397e7144d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 12.2.17 of @angular/elements, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:dbf35c40-f30f-5f1a-9cb2-94a37d516df5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 12.2.17 of @angular/elements, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:437628b7-adfd-5337-a049-eed658e6f383",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 12.2.17 of @angular/elements, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:6bc3b0d6-5065-5c4e-a662-37456894ffae",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 12.2.17 of @angular/elements, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:d2d3c6cb-e1a6-5ce0-a547-be6531367a6a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 12.2.17 of @angular/elements, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:84ecda15-6a07-5e9c-b09c-d742d92d2367",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 12.2.17 of @angular/elements, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:deec95f8-d8c2-5ba5-a9fe-1fbc3e41d3a7",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 12.2.17 of @angular/elements. not_affected \u2014 Angular 12.2.17 does not contain the HttpTransferCache feature affected by CVE-2026-68945. HttpTransferCache, which caches HTTP requests during Server-Side Rendering (SSR), was first introduced in Angular 16.0.0\u2014approximately 4 major versions after the target version. The vulnerability concerns cache-key collision when repeated HTTP parameters are serialized, but since the entire HttpTransferCa...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:23fdf7f7-b2c4-5014-9eed-4ac285e4547b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 12.2.17 of @angular/elements, and is fixed in 12.2.17-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:75f1622c-8112-53f7-b0a4-f6bef039a18a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 12.2.17 of @angular/elements, and is fixed in 12.2.17-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:bb8e51c7-b3b5-5f2b-b056-d8ecb9852279",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88056 affects version 12.2.17 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:012ce7e7-d1cc-5809-8c76-5c3ea03de723",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 12.2.17 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:a4f618a4-02a9-5b07-8799-f0805eaf332e",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 12.2.17 of @angular/elements. not_affected \u2014 Angular 12.2.17-tuxcare.9 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, withRequestsMadeViaParent(), and provideClientHydration() features which were introduced in Angular 16.0.0. This version uses the older module-based HttpClientModule system and lacks the entire SSR hydration transfer-cache infrastructure. The vulnerable code pattern described in the CVE do...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@12.2.17"
        }
      ],
      "bom-ref": "urn:uuid:7e779ede-d29b-5dcb-a056-22fe6c7383ef",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 12.2.17 of @angular/elements."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/elements@12.2.17"
    }
  ]
}