{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:226f9499-528d-525e-ae12-9fe74bd8b513",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/elements",
      "purl": "pkg:npm/%40angular/elements@16.2.11-tuxcare.1",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/elements@16.2.11-tuxcare.1",
      "version": "16.2.11-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@16.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d6c696f6-b2f3-51df-95a0-b9f815aea1a5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59052 affects version 16.2.11-tuxcare.1 of @angular/elements."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@16.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:45a66770-00c0-56b9-b1b2-437b40dc4084",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 16.2.11-tuxcare.1 of @angular/elements."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@16.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8045e541-7cc6-59d6-bd00-f17baa399efe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 16.2.11-tuxcare.1 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@16.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:44556561-b149-57a4-9f37-5ebf57639880",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 16.2.11-tuxcare.1 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@16.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1d502994-ef1c-5c01-9eef-214a9b80e010",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 16.2.11-tuxcare.1 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@16.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:95ad5a54-3238-51c9-b733-4f90b17b43d7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 16.2.11-tuxcare.1 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@16.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:00d59ba0-7fbd-5256-b4cc-d87d7f1882b7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 16.2.11-tuxcare.1 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@16.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0187d27d-3629-5561-a461-752857cd4dce",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 16.2.11-tuxcare.1 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@16.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6e8f8b11-0932-5712-911d-421febdddb5c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 16.2.11-tuxcare.1 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@16.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3ac724a8-8a64-5ee6-b330-efe544a59df3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 16.2.11-tuxcare.1 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@16.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4ee51492-38d8-5343-8078-5b3f661334ab",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 16.2.11-tuxcare.1 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@16.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ea3fa017-b26e-593d-81c5-c288cc7d42bb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 16.2.11-tuxcare.1 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@16.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:50391c60-132f-5cce-ad90-00afa7f83798",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 16.2.11-tuxcare.1 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@16.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8ae21141-8104-541e-bf2f-62063c6684ab",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 16.2.11-tuxcare.1 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@16.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:274440ed-5ea2-5961-a6a2-1e157b35b3dd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 16.2.11-tuxcare.1 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@16.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:15648275-b6a7-5ebb-aa8b-2be46547f8f2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 16.2.11-tuxcare.1 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@16.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:dfa8db51-01fa-5ef1-be0b-aac919b893b6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 16.2.11-tuxcare.1 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@16.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c796bf71-59c9-58fe-98bd-9c3933f10c48",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 16.2.11-tuxcare.1 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@16.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2485e8a6-5919-52ac-9ad1-cd706d7bb9eb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 16.2.11-tuxcare.1 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@16.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c69aa61c-7e50-51ed-b437-e2bf5cea446e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 16.2.11-tuxcare.1 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@16.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2c21ac4a-9f3e-5430-b670-2c34f1c11157",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 16.2.11-tuxcare.1 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@16.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8ea8f25f-0686-527e-ad66-ed5258e215a4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 16.2.11-tuxcare.1 of @angular/elements, and is fixed in 16.2.11-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@16.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b8141026-d8c2-5498-817e-7d5fdadabb76",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 16.2.11-tuxcare.1 of @angular/elements, and is fixed in 16.2.11-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@16.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:991deb34-f174-5f31-ba46-2e6341b1d94b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 16.2.11-tuxcare.1 of @angular/elements, and is fixed in 16.2.11-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@16.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0a108b86-ebd3-50d4-84b0-a4cff7137f08",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 16.2.11-tuxcare.1 of @angular/elements. not_affected \u2014 Angular 16.2.11-tuxcare.2 is NOT affected by CVE-2026-88056. The vulnerability requires WHATWG URL validation combined with String.prototype.trim() on URLs during SSR, creating a discrepancy that enables SSRF. While the target uses WHATWG URL parsing (backported in commit c03fbfd7cc for CVE-2026-50168), it does NOT call String.prototype.trim() on URLs. The attack chain is broken at the trim() s...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@16.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:38c9ecd0-3b5d-53b7-9f46-108e2e8d3c6b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 16.2.11-tuxcare.1 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@16.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:55b30abe-aed6-53ff-8cb8-7ad6ed297149",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 16.2.11-tuxcare.1 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@16.2.11-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7d1ff436-cb7b-5591-9a3e-a2b06383e557",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 16.2.11-tuxcare.1 of @angular/elements."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/elements@16.2.11-tuxcare.1"
    }
  ]
}