{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:bbfa86b3-7db9-5e6b-948e-60dabe0a383a",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/forms",
      "purl": "pkg:npm/%40angular/forms@17.1.0-tuxcare.2",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.2",
      "version": "17.1.0-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e8380336-e46d-5a2b-b523-e6a78951c7c4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.1.0-tuxcare.2 of @angular/forms."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:84ad3b9e-a664-5176-bd14-c4ceaa5dfee0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.1.0-tuxcare.2 of @angular/forms."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:54c24b90-9b1a-583a-9bee-e7ae730e6e39",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66412 affects version 17.1.0-tuxcare.2 of @angular/forms, and is fixed in 17.1.0-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:577aad7e-d643-5931-b042-13fb8f0c5aea",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.1.0-tuxcare.2 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:62c19e37-0b18-5472-936f-31f2f0002280",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.1.0-tuxcare.2 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7aff80e8-30e9-5691-936f-159a59810fad",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.1.0-tuxcare.2 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7f449028-de3d-5305-93b8-d60eca29f266",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 17.1.0-tuxcare.2 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0e317652-99b7-5b3e-9532-a05c7284e447",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 17.1.0-tuxcare.2 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:792d5e8d-930a-5913-9887-c1d641bbcc8d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 17.1.0-tuxcare.2 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:80804df4-2b16-586b-89a8-e6445545dd8c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 17.1.0-tuxcare.2 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:bb492dd8-c54d-525f-baa1-a496839aa35a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 17.1.0-tuxcare.2 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2e0eb690-2d3e-5903-9601-354ce9350406",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 17.1.0-tuxcare.2 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:900f06a2-482b-518a-a0ef-212d3826e0c4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 17.1.0-tuxcare.2 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e1d3ddb2-b502-55a0-83b6-94cd7a56c582",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 17.1.0-tuxcare.2 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d560d603-140c-55e3-bc67-be2a6220614d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 17.1.0-tuxcare.2 of @angular/forms, and is fixed in 17.1.0-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e8310e91-1b1d-57c0-b2fd-ebd8464b7606",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 17.1.0-tuxcare.2 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:aeecbbba-29e4-508e-93b2-5ba9f57eed6f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 17.1.0-tuxcare.2 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7cf7fdf6-428b-5bea-a20a-7036d2fead5a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 17.1.0-tuxcare.2 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f7917fe1-9066-5fb4-9008-489fa111b284",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 17.1.0-tuxcare.2 of @angular/forms. not_affected \u2014 Angular v17.1.0 does not have the TwoWayProperty IR operation that is the subject of CVE-2026-54265. Two-way bindings are desugared into separate property and event bindings before template pipeline processing, with the property half using the same parsePropertyBinding() code path as one-way property bindings, which are properly sanitized.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:813f3229-d411-5cae-ba29-b5cf0c7be8b8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 17.1.0-tuxcare.2 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c697ece7-633e-58d6-afec-7e1043816a8e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 17.1.0-tuxcare.2 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3305c486-c6a1-59f8-9a2d-67b4fc7e4401",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 17.1.0-tuxcare.2 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e6936150-a7fb-5a10-82cc-a01cc6a5a00a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 17.1.0-tuxcare.2 of @angular/forms, and is fixed in 17.1.0-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:90b7bf14-52c2-5e9e-b0d8-5a366fb63ab4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 17.1.0-tuxcare.2 of @angular/forms, and is fixed in 17.1.0-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:71e7a351-f5e8-5b6a-b9a5-e5e4353545f5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 17.1.0-tuxcare.2 of @angular/forms, and is fixed in 17.1.0-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:6d2460d8-1898-5d1b-a6d7-7963447752a7",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.1.0-tuxcare.2 of @angular/forms. not_affected \u2014 Angular 17.1.0 was never vulnerable to CVE-2026-88056. The vulnerability exists only in newer Angular versions (v18+, v19+, v20+ before fixes) where a url.ts file with a parseUrl function that uses String.prototype.trim() was introduced. Angular 17.1.0 does not have this file in the upstream release. TuxCare created url.ts for their 17.1.0 fork (commit e06d36f339 by ejarocki@cloudlinux.com) but...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:38b5d237-e9c9-5ffb-ba22-f7199a170387",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 17.1.0-tuxcare.2 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:aeac362e-1f31-5e58-979d-d4bbdc15b8c3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 17.1.0-tuxcare.2 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:bcab6a3e-af7b-547d-99d0-81fbd8cd736e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 17.1.0-tuxcare.2 of @angular/forms."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.2"
    }
  ]
}