{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e557d237-55d9-505c-82a5-768b86f076a0",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/language-service",
      "purl": "pkg:npm/%40angular/language-service@8.2.14-tuxcare.1",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/language-service@8.2.14-tuxcare.1",
      "version": "8.2.14-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6e7dc4f7-9041-5da1-9cb0-2c89d3d7e26b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-4231 affects version 8.2.14-tuxcare.1 of @angular/language-service, and is fixed in 8.2.14-tuxcare.5."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:78534b5d-c39f-5c18-a9ab-86a57ff8f6f6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 8.2.14-tuxcare.1 of @angular/language-service, and is fixed in 8.2.14-tuxcare.10."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:72c159e7-f0f8-5ac1-8575-7dc7cff115c1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66412 affects version 8.2.14-tuxcare.1 of @angular/language-service, and is fixed in 8.2.14-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:42f8b049-0c7b-529a-b789-d71fa0f65b98",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22610 affects version 8.2.14-tuxcare.1 of @angular/language-service, and is fixed in 8.2.14-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9fd18fda-0d84-5ed5-bd3f-49ec8c2c4e40",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 8.2.14-tuxcare.1 of @angular/language-service, and is fixed in 8.2.14-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:117a4a57-af36-564e-8a5b-f66bea4109cb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 8.2.14-tuxcare.1 of @angular/language-service, and is fixed in 8.2.14-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:49055a20-128e-5fab-acb9-546cc1bfd532",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 8.2.14-tuxcare.1 of @angular/language-service, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5581b810-9edd-55d8-a3d0-5d0d7834bc1b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 8.2.14-tuxcare.1 of @angular/language-service, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:66b92422-6704-50c5-b2f6-c85c80469060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 8.2.14-tuxcare.1 of @angular/language-service, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1200110b-09e2-561c-9de2-ea3bd8ab1008",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 8.2.14-tuxcare.1 of @angular/language-service, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:44de56ce-4a5c-5e88-8986-d1ff1f4edace",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 8.2.14-tuxcare.1 of @angular/language-service, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fb894ae9-3a1e-5afa-abf8-ff35894ced45",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 8.2.14-tuxcare.1 of @angular/language-service, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c4110d71-6299-5f2e-9767-266ef9b03e11",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 8.2.14-tuxcare.1 of @angular/language-service, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8ed62fdb-6c1f-5a2c-8f8a-3c9c6c6861f8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 8.2.14-tuxcare.1 of @angular/language-service, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:855c67b4-7fc4-5dce-88e2-c56ea791ed9a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 8.2.14-tuxcare.1 of @angular/language-service, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:eba5e679-e8b8-5112-be7f-1a8c052aaeea",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 8.2.14-tuxcare.1 of @angular/language-service, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:544b05c4-c6b4-5bf4-81ad-890f8e00fa3d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 8.2.14-tuxcare.1 of @angular/language-service, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3bb22bbc-e83e-5fea-8915-bfbf9db9172d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 8.2.14-tuxcare.1 of @angular/language-service, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5483a00e-584f-505b-85cb-3d62c817d9f3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 8.2.14-tuxcare.1 of @angular/language-service, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:829f1487-cbfc-51ec-913e-59528487b828",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 8.2.14-tuxcare.1 of @angular/language-service, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:97fd0660-bf3b-5bae-96c5-5b889002cb74",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 8.2.14-tuxcare.1 of @angular/language-service. not_affected \u2014 Angular 8.2.14 is NOT affected by CVE-2026-68945. The vulnerability exists in HttpTransferCache, a feature that automatically caches HTTP requests during SSR for client hydration. HttpTransferCache was introduced in Angular v16+ and does not exist in version 8.2.14. This version has only a manual TransferState key-value store with no automatic HttpClient integration, and no HTTP caching mechani...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d8fc52e7-579e-5538-9f57-49972f63b21f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 8.2.14-tuxcare.1 of @angular/language-service, and is fixed in 8.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8d77652c-215f-571f-a35f-60d2bb1e1c5f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 8.2.14-tuxcare.1 of @angular/language-service, and is fixed in 8.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1e1e88a0-6b38-5507-9ce3-a2a8ff667341",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 8.2.14-tuxcare.1 of @angular/language-service. not_affected \u2014 Angular 8.2.14 is NOT AFFECTED by CVE-2026-88056. The vulnerability requires a sophisticated URL resolution utility (`parseUrl` in `packages/platform-server/src/url.ts`) that calls `String.prototype.trim()` to strip Unicode whitespace, creating a discrepancy with WHATWG URL validation. This architecture was introduced in Angular v12+ (circa 2026 as TuxCare backports). Angular 8.2.14 (released N...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f46bd43a-199e-588a-92d7-b95b2be97268",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 8.2.14-tuxcare.1 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4597c594-b576-5747-a2fa-1f6c82082add",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 8.2.14-tuxcare.1 of @angular/language-service. not_affected \u2014 Angular v8.2.14 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, provideClientHydration(), and withRequestsMadeViaParent() \u2014 all features that do not exist in this version. These features were introduced in Angular v16 (per patches/CVE-2026-50170.patch and patches/CVE-2026-54266.patch). The target uses the legacy NgModule-based HttpClientModule without automatic ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:bbcaf5a9-60b3-577f-a6c1-3bce34f44857",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 8.2.14-tuxcare.1 of @angular/language-service."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/language-service@8.2.14-tuxcare.1"
    }
  ]
}