{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3d233ef8-31a4-5a4d-aa0e-dc3256fa1547",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/forms",
      "purl": "pkg:npm/%40angular/forms@13.4.0-tuxcare.2",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/forms@13.4.0-tuxcare.2",
      "version": "13.4.0-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@13.4.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:98af96d4-eea7-5d20-8d55-ee59131a9295",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 13.4.0-tuxcare.2 of @angular/forms, and is fixed in 13.4.0-tuxcare.8."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@13.4.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d97959be-d1b0-55bb-a65a-ed05c4329d51",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 13.4.0-tuxcare.2 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@13.4.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2dcb1536-f31f-5c5a-ad5c-ad8ce0c17fa0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22610 affects version 13.4.0-tuxcare.2 of @angular/forms, and is fixed in 13.4.0-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@13.4.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0e0fb4e7-191a-53a1-8ec8-6f09d19d51e0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 13.4.0-tuxcare.2 of @angular/forms, and is fixed in 13.4.0-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@13.4.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3d58dd7a-6b2b-5326-89ca-1e4bbd83408a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 13.4.0-tuxcare.2 of @angular/forms, and is fixed in 13.4.0-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@13.4.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6f86a7b3-38e7-5319-975b-58f630399bdb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 13.4.0-tuxcare.2 of @angular/forms, and is fixed in 13.4.0-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@13.4.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1661e09d-2a84-5f45-bf8e-85537e2ad2a4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 13.4.0-tuxcare.2 of @angular/forms, and is fixed in 13.4.0-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@13.4.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3bf6db68-2101-566a-ab40-6d2910a583e7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 13.4.0-tuxcare.2 of @angular/forms, and is fixed in 13.4.0-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@13.4.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e8bbbac4-5565-57d2-bcc3-5b090f4d1410",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 13.4.0-tuxcare.2 of @angular/forms, and is fixed in 13.4.0-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@13.4.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:386f3197-4c19-5b3e-8f60-e4718faa9bfa",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 13.4.0-tuxcare.2 of @angular/forms, and is fixed in 13.4.0-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@13.4.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:29d116fc-e876-5f91-b2f6-ddec82aba065",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 13.4.0-tuxcare.2 of @angular/forms, and is fixed in 13.4.0-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@13.4.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0f79638f-4637-51d0-bd3e-5467eed0c3e5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 13.4.0-tuxcare.2 of @angular/forms, and is fixed in 13.4.0-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@13.4.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ac030f2c-27b2-5157-a4fe-e53c3a50dfb1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 13.4.0-tuxcare.2 of @angular/forms, and is fixed in 13.4.0-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@13.4.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:bdaeec83-1272-59da-9566-709a0866afde",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 13.4.0-tuxcare.2 of @angular/forms, and is fixed in 13.4.0-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@13.4.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:af9bf8e6-8ad9-5688-8fea-4443c35fd99a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 13.4.0-tuxcare.2 of @angular/forms, and is fixed in 13.4.0-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@13.4.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ffeb2096-0ab9-57f9-a1cc-aa3feb078318",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 13.4.0-tuxcare.2 of @angular/forms, and is fixed in 13.4.0-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@13.4.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6b617111-1da3-5671-8ace-991638aae88c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 13.4.0-tuxcare.2 of @angular/forms, and is fixed in 13.4.0-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@13.4.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:cc9dfbb0-d5d1-596d-98d3-208adbd26fe7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 13.4.0-tuxcare.2 of @angular/forms, and is fixed in 13.4.0-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@13.4.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b9748d08-6669-5662-a55a-3213636a121b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 13.4.0-tuxcare.2 of @angular/forms, and is fixed in 13.4.0-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@13.4.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4c47792b-b224-5c5b-9169-503cdd39420c",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 13.4.0-tuxcare.2 of @angular/forms. not_affected \u2014 Angular v13.4.0 is NOT AFFECTED by CVE-2026-68945. The HttpTransferCache feature, which is the subject of this vulnerability, was introduced in Angular v16.0.0 and does not exist in v13.4.0. Without HttpTransferCache, the cache key collision vulnerability involving HttpParams serialization cannot occur. This assessment is consistent with two other HttpTransferCache CVEs (CVE-2026-54266 and CVE-...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@13.4.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:a716c2c8-5047-5fcc-a257-1ccb4531b922",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 13.4.0-tuxcare.2 of @angular/forms, and is fixed in 13.4.0-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@13.4.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6cdbe4d4-d815-581e-808a-a3706fc37c70",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 13.4.0-tuxcare.2 of @angular/forms, and is fixed in 13.4.0-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@13.4.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:77e63f65-b9af-536d-902d-641e50457ba8",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 13.4.0-tuxcare.2 of @angular/forms. not_affected \u2014 Angular version 13.4.0 is not affected by CVE-2026-88056. The vulnerable code pattern (String.prototype.trim() on URL strings in parseUrl) never existed in this version. The url.ts file was created by TuxCare in June 2026 (commit 0a33393ba5) with a safe implementation that preserves Unicode whitespace, preventing the attack vector described in the CVE. The vulnerability was introduced and fixed...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@13.4.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:bd0a1902-0b29-5f81-a458-c5ab74c2e2f4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 13.4.0-tuxcare.2 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@13.4.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7127f91a-1178-5b84-afbb-85e7c3d76dc2",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 13.4.0-tuxcare.2 of @angular/forms. not_affected \u2014 Angular 13.4.0 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache and hierarchical HttpClient delegation (withRequestsMadeViaParent()), features that were introduced in Angular 16.0.0. These features do not exist in Angular 13.4.0, making the attack vector impossible. This assessment is consistent with the repository's own documentation of related CVE-2026-50170, wh...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@13.4.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c3538543-9837-5fd3-be0b-67bee25a9ace",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 13.4.0-tuxcare.2 of @angular/forms."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/forms@13.4.0-tuxcare.2"
    }
  ]
}