{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:be554df0-8306-547b-a949-4f04f3d3aaec",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/forms",
      "purl": "pkg:npm/%40angular/forms@12.2.17-tuxcare.3",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/forms@12.2.17-tuxcare.3",
      "version": "12.2.17-tuxcare.3",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:334fff87-29a5-56a1-8003-bcd7e91c5726",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 12.2.17-tuxcare.3 of @angular/forms, and is fixed in 12.2.17-tuxcare.8."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:1ce9ad49-f702-5144-8df2-f15aea5ec822",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 12.2.17-tuxcare.3 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:d03ad25a-6fe4-5359-be2d-ab76c7b09656",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 12.2.17-tuxcare.3 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:32f4e936-fa1a-5e0d-b4f8-5110da9ad931",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 12.2.17-tuxcare.3 of @angular/forms, and is fixed in 12.2.17-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:084c6e58-96fe-5f56-9d51-eb0f9acaaf64",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 12.2.17-tuxcare.3 of @angular/forms, and is fixed in 12.2.17-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:5ab8391d-efe7-5c51-8a85-998cb3a40db5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 12.2.17-tuxcare.3 of @angular/forms, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:3ad3a240-d2fa-5a0c-a788-eccc17b08af5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 12.2.17-tuxcare.3 of @angular/forms, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:69029d5b-5085-5365-8d51-63bf7a4fcd74",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 12.2.17-tuxcare.3 of @angular/forms, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:6bb01591-e4c2-5104-ae63-e9ce6174e10e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 12.2.17-tuxcare.3 of @angular/forms, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:f1cf56ca-3591-5bd5-9a07-26a700acfa2e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 12.2.17-tuxcare.3 of @angular/forms, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:c8a8bfa4-cf18-57bb-9434-47f368cbb627",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 12.2.17-tuxcare.3 of @angular/forms, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:2c4e4da1-0cd4-509a-b5cd-61439941a2ab",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 12.2.17-tuxcare.3 of @angular/forms, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:826c2a2e-9d0c-56d7-8199-5e9f0e11f92d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 12.2.17-tuxcare.3 of @angular/forms, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:310ba247-0ac0-5d13-bf7f-f24e42396de1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 12.2.17-tuxcare.3 of @angular/forms, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:637fc8d6-801b-5eec-aae7-9b35940c6805",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 12.2.17-tuxcare.3 of @angular/forms, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:f80ef496-eb8b-5aa0-b8d3-a46239da5201",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 12.2.17-tuxcare.3 of @angular/forms, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:39cf23e8-202f-55f7-bfc3-2431fc73d54e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 12.2.17-tuxcare.3 of @angular/forms, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:39bcde5b-2c0f-5fa0-89cb-e28912308eaf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 12.2.17-tuxcare.3 of @angular/forms, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:6994e163-6723-511f-a839-ef467663e4d6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 12.2.17-tuxcare.3 of @angular/forms, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:42fb6d6e-e45c-5459-83f0-c7198e057210",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 12.2.17-tuxcare.3 of @angular/forms. not_affected \u2014 Angular 12.2.17 does not contain the HttpTransferCache feature affected by CVE-2026-68945. HttpTransferCache, which caches HTTP requests during Server-Side Rendering (SSR), was first introduced in Angular 16.0.0\u2014approximately 4 major versions after the target version. The vulnerability concerns cache-key collision when repeated HTTP parameters are serialized, but since the entire HttpTransferCa...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:195e1c3c-9c2a-5d3e-b18f-73f7ab843dad",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 12.2.17-tuxcare.3 of @angular/forms, and is fixed in 12.2.17-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:c8f1d366-ee2a-59e9-9ada-76c7cc176370",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 12.2.17-tuxcare.3 of @angular/forms, and is fixed in 12.2.17-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:582509fb-0ae1-5d7f-a2a0-097ea9637c81",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88056 affects version 12.2.17-tuxcare.3 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:e0223641-4b16-5953-9a48-95791a111075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 12.2.17-tuxcare.3 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:8ff410a1-6d9f-52b9-9e2f-1e7138ed2f6e",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 12.2.17-tuxcare.3 of @angular/forms. not_affected \u2014 Angular 12.2.17-tuxcare.9 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, withRequestsMadeViaParent(), and provideClientHydration() features which were introduced in Angular 16.0.0. This version uses the older module-based HttpClientModule system and lacks the entire SSR hydration transfer-cache infrastructure. The vulnerable code pattern described in the CVE do...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@12.2.17-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:a5c1bb13-d76a-5dcb-9635-8f8c4d8ddd83",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 12.2.17-tuxcare.3 of @angular/forms."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/forms@12.2.17-tuxcare.3"
    }
  ]
}