{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:8366b128-5a98-5d0b-8618-01f728c3c75d",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/forms",
      "purl": "pkg:npm/%40angular/forms@17.3.12-tuxcare.9",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/forms@17.3.12-tuxcare.9",
      "version": "17.3.12-tuxcare.9",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:4e33ea42-8c46-5774-896b-d5ed250d0dc9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.3.12-tuxcare.9 of @angular/forms."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:a469bcdb-c6e2-52b5-992b-4c390dcd98f8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.3.12-tuxcare.9 of @angular/forms."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:ad2786bc-6df7-5b07-8160-599b36ab30cd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.3.12-tuxcare.9 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:fc9cf7cb-2c93-5679-b3b0-d8fd2eb5f594",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.3.12-tuxcare.9 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:74caba1c-7d4f-5b70-8f90-507a49916a68",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.3.12-tuxcare.9 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:2414ca56-1a2c-5371-bf7b-fc28f62d29ed",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.3.12-tuxcare.9 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:9ea4517e-eb7f-5a78-a0b2-b1e44c100a12",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 17.3.12-tuxcare.9 of @angular/forms, and is fixed in 17.3.12-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:b14c05c8-1fb5-5010-addd-b10bcf38d101",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 17.3.12-tuxcare.9 of @angular/forms, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:30d899a6-0021-584d-8e9a-4001018d7ce5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 17.3.12-tuxcare.9 of @angular/forms, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:e3f5e670-9076-5200-9da9-f0c10cb74b4e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 17.3.12-tuxcare.9 of @angular/forms, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:b494803c-572d-57e9-b745-0877f33d447d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 17.3.12-tuxcare.9 of @angular/forms, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:9a5d181c-e068-5351-b790-130d49b63cba",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 17.3.12-tuxcare.9 of @angular/forms, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:5a9aaee0-705f-5147-aa57-3c56386610f4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 17.3.12-tuxcare.9 of @angular/forms, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:a6c476e0-b22e-5d09-bc8f-b602d64222b6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 17.3.12-tuxcare.9 of @angular/forms, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:bc382640-9ba1-572d-a3cb-e59bc94d2a5f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 17.3.12-tuxcare.9 of @angular/forms, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:f9ca1d60-26f1-5a58-8803-a046cef541e8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 17.3.12-tuxcare.9 of @angular/forms, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:641efd2d-f9e6-5568-aee9-5b6280db1cf1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 17.3.12-tuxcare.9 of @angular/forms, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:b37836fd-d747-5d05-a075-f0fd84a570aa",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 17.3.12-tuxcare.9 of @angular/forms, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:67eac1c5-c8cb-5ec5-b9b4-d1924dc64dc2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 17.3.12-tuxcare.9 of @angular/forms, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:b4f171d3-0c23-5675-809e-cbfe149ee40a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 17.3.12-tuxcare.9 of @angular/forms, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:897eb8a7-383a-5bc2-8978-2ffd32b97604",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 17.3.12-tuxcare.9 of @angular/forms, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:53275c4a-18dd-54ab-a38d-1431380257d1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 17.3.12-tuxcare.9 of @angular/forms, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:b7b36d8b-6faf-5ec1-b3ce-5bb2dda0a265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 17.3.12-tuxcare.9 of @angular/forms, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:82aa8444-6d86-5398-a352-100ce9526e78",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 17.3.12-tuxcare.9 of @angular/forms, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:45383d84-8508-5090-80a3-5fa8a1436180",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.3.12-tuxcare.9 of @angular/forms. not_affected \u2014 Version 17.3.12 is not affected by CVE-2026-88056. The vulnerability involves String.prototype.trim() being applied during URL resolution in Angular's platform-server, converting validated same-origin URLs with Unicode whitespace into cross-origin protocol-relative URLs, leading to SSRF. This vulnerable code pattern was introduced in newer Angular versions (v20+) and does not exist in version 1...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:c07527fb-b9be-5785-ad22-6be4f854c8a5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 17.3.12-tuxcare.9 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:3b1e3a22-157e-5c13-893a-0044dbe3cbd3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 17.3.12-tuxcare.9 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:f214c1a6-f50b-58db-a261-7e25e8580aac",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 17.3.12-tuxcare.9 of @angular/forms."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/forms@17.3.12-tuxcare.9"
    }
  ]
}