{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:03c80324-3cdb-5ef2-9f0a-4b2039bec7af",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/language-service",
      "purl": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.9",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.9",
      "version": "17.3.12-tuxcare.9",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:01ddaeef-3b5d-5a92-bc01-4ff08481523f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.3.12-tuxcare.9 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:76324620-d19f-5ce8-a02e-f57f7c697de1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.3.12-tuxcare.9 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:7390566b-a1f8-575e-9c60-b08dab169e69",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.3.12-tuxcare.9 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:dc9750a8-bf47-5e13-bbc4-5cc8201f7087",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.3.12-tuxcare.9 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:4d4fa3b6-b161-5909-b8b3-77f9575dea1f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.3.12-tuxcare.9 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:52182a41-2219-587b-8017-3b106b174924",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.3.12-tuxcare.9 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:dc5e1cb9-a40e-5e42-b7c7-146f4399878d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 17.3.12-tuxcare.9 of @angular/language-service, and is fixed in 17.3.12-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:72fac02b-6cfa-57b4-8ca5-91540927d91c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 17.3.12-tuxcare.9 of @angular/language-service, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:59e7ed6d-aa27-52b2-8a1d-832b351617d6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 17.3.12-tuxcare.9 of @angular/language-service, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:44ac29e3-7f8e-57a1-9d20-16d9d213d771",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 17.3.12-tuxcare.9 of @angular/language-service, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:1a166872-3658-5e3f-8b2a-a0cc968b0bd6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 17.3.12-tuxcare.9 of @angular/language-service, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:a5a63b55-128f-59a1-a1da-11a526e7e53c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 17.3.12-tuxcare.9 of @angular/language-service, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:15ae129c-a6ef-55cc-9fd7-cd32f5e48548",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 17.3.12-tuxcare.9 of @angular/language-service, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:af19c805-c2b2-528c-9605-f4c8297661a8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 17.3.12-tuxcare.9 of @angular/language-service, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:f17dd834-ab9d-57c7-9c71-a437cb7ddf77",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 17.3.12-tuxcare.9 of @angular/language-service, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:505ed9f1-ab18-5988-bd7d-d8ade37a4f4b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 17.3.12-tuxcare.9 of @angular/language-service, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:fc959342-e1d8-5514-a359-0b2dceab2ba5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 17.3.12-tuxcare.9 of @angular/language-service, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:efc03541-6825-58f3-ac95-cfe24bf9c992",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 17.3.12-tuxcare.9 of @angular/language-service, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:4e351f73-1cae-59d9-bc9e-0edf9c4847ee",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 17.3.12-tuxcare.9 of @angular/language-service, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:1b013831-f0d0-5ea1-9dcd-0c36970c6225",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 17.3.12-tuxcare.9 of @angular/language-service, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:99e92cbe-7cd2-5d28-9980-7d3d0844a6de",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 17.3.12-tuxcare.9 of @angular/language-service, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:e1de8612-3e4d-5f73-9556-e1a168e8e700",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 17.3.12-tuxcare.9 of @angular/language-service, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:57725ea3-b5a3-5084-9d30-7b768f7c780c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 17.3.12-tuxcare.9 of @angular/language-service, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:3f184c2d-6e4f-5ce9-a731-24f43f8ed8b2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 17.3.12-tuxcare.9 of @angular/language-service, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:4b5b30f4-5ba8-5c7a-99a4-2b9725f1efec",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.3.12-tuxcare.9 of @angular/language-service. not_affected \u2014 Version 17.3.12 is not affected by CVE-2026-88056. The vulnerability involves String.prototype.trim() being applied during URL resolution in Angular's platform-server, converting validated same-origin URLs with Unicode whitespace into cross-origin protocol-relative URLs, leading to SSRF. This vulnerable code pattern was introduced in newer Angular versions (v20+) and does not exist in version 1...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:5c5203d9-2047-59d4-9f5f-c6bc574afcaf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 17.3.12-tuxcare.9 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:9af2a0b5-85b9-52d1-aa7d-33a09fbb8d45",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 17.3.12-tuxcare.9 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:6459c1fc-7820-5bc9-a8c0-4d9058117bf1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 17.3.12-tuxcare.9 of @angular/language-service."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/language-service@17.3.12-tuxcare.9"
    }
  ]
}