{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a689ab31-6ba5-5496-bd6d-5244c5d94f20",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/platform-browser-dynamic",
      "purl": "pkg:npm/%40angular/platform-browser-dynamic@12.2.17-tuxcare.1",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/platform-browser-dynamic@12.2.17-tuxcare.1",
      "version": "12.2.17-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@12.2.17-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:de51c81e-e75e-5a2e-944f-04a72f364caa",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 12.2.17-tuxcare.1 of @angular/platform-browser-dynamic, and is fixed in 12.2.17-tuxcare.8."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@12.2.17-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9bc5963c-581f-5581-9f14-7facc9e4b8f2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66412 affects version 12.2.17-tuxcare.1 of @angular/platform-browser-dynamic, and is fixed in 12.2.17-tuxcare.2."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@12.2.17-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0dea91b9-00c2-5b6f-8afb-1e46a212ab1d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22610 affects version 12.2.17-tuxcare.1 of @angular/platform-browser-dynamic, and is fixed in 12.2.17-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@12.2.17-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c4b5c213-6aab-5ffe-a9af-34a89001e2cf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 12.2.17-tuxcare.1 of @angular/platform-browser-dynamic, and is fixed in 12.2.17-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@12.2.17-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e4e10fbb-7aa7-5ad0-aa95-aafc44d335b5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 12.2.17-tuxcare.1 of @angular/platform-browser-dynamic, and is fixed in 12.2.17-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@12.2.17-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d19b179a-8195-542f-bba0-8022ced1fa33",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 12.2.17-tuxcare.1 of @angular/platform-browser-dynamic, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@12.2.17-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6ba554b9-2623-556c-84b2-ae30039af716",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 12.2.17-tuxcare.1 of @angular/platform-browser-dynamic, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@12.2.17-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1b89788f-3d70-51ed-938d-dc51c2f6b208",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 12.2.17-tuxcare.1 of @angular/platform-browser-dynamic, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@12.2.17-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5d0739c4-c87b-5768-9a1a-89f91ee0248b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 12.2.17-tuxcare.1 of @angular/platform-browser-dynamic, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@12.2.17-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a7aecf67-5b6d-5580-86c0-3bea40a9eb05",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 12.2.17-tuxcare.1 of @angular/platform-browser-dynamic, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@12.2.17-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:82f89ca6-5069-5d41-811b-5a69c207cc48",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 12.2.17-tuxcare.1 of @angular/platform-browser-dynamic, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@12.2.17-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c2ac8dc7-3781-586c-bff2-48b4382cead7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 12.2.17-tuxcare.1 of @angular/platform-browser-dynamic, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@12.2.17-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:24b9cb4a-461e-5d30-8c66-53496f19a79d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 12.2.17-tuxcare.1 of @angular/platform-browser-dynamic, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@12.2.17-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a1a3a29e-1cef-5041-b2d8-6f7b144b791f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 12.2.17-tuxcare.1 of @angular/platform-browser-dynamic, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@12.2.17-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:07651c31-8698-546f-ac46-f83acd47b4ab",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 12.2.17-tuxcare.1 of @angular/platform-browser-dynamic, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@12.2.17-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4a2c7a3d-80df-5fdd-b617-2917758089b4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 12.2.17-tuxcare.1 of @angular/platform-browser-dynamic, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@12.2.17-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:69e80e92-b136-5c09-b683-7b897563cb94",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 12.2.17-tuxcare.1 of @angular/platform-browser-dynamic, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@12.2.17-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:54a68640-234b-5461-84e7-90acb6a355f8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 12.2.17-tuxcare.1 of @angular/platform-browser-dynamic, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@12.2.17-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b92ffb29-b3a2-52a5-a006-20c9baff1fc5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 12.2.17-tuxcare.1 of @angular/platform-browser-dynamic, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@12.2.17-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f9634424-d4ab-5a36-8e46-3f0b5d613c5b",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 12.2.17-tuxcare.1 of @angular/platform-browser-dynamic. not_affected \u2014 Angular 12.2.17 does not contain the HttpTransferCache feature affected by CVE-2026-68945. HttpTransferCache, which caches HTTP requests during Server-Side Rendering (SSR), was first introduced in Angular 16.0.0\u2014approximately 4 major versions after the target version. The vulnerability concerns cache-key collision when repeated HTTP parameters are serialized, but since the entire HttpTransferCa...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@12.2.17-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8c6548bf-39e0-5cc1-b9c6-504887f17180",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 12.2.17-tuxcare.1 of @angular/platform-browser-dynamic, and is fixed in 12.2.17-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@12.2.17-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a8586f2a-8e17-598c-a372-a8abc402f84c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 12.2.17-tuxcare.1 of @angular/platform-browser-dynamic, and is fixed in 12.2.17-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@12.2.17-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2354263b-4045-589f-ac79-fdb11ee3f5a4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88056 affects version 12.2.17-tuxcare.1 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@12.2.17-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b143e801-e32d-58f7-9aeb-4552d016bc6c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 12.2.17-tuxcare.1 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@12.2.17-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:23f0c244-5460-5f67-a8df-771f18aafa45",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 12.2.17-tuxcare.1 of @angular/platform-browser-dynamic. not_affected \u2014 Angular 12.2.17-tuxcare.9 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, withRequestsMadeViaParent(), and provideClientHydration() features which were introduced in Angular 16.0.0. This version uses the older module-based HttpClientModule system and lacks the entire SSR hydration transfer-cache infrastructure. The vulnerable code pattern described in the CVE do...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@12.2.17-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:337bc3f8-8a56-57f7-837d-6aec7422888f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 12.2.17-tuxcare.1 of @angular/platform-browser-dynamic."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/platform-browser-dynamic@12.2.17-tuxcare.1"
    }
  ]
}