{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:77b7dcfc-006a-588a-a645-c28887d87639",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/platform-browser-dynamic",
      "purl": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.4",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.4",
      "version": "17.3.12-tuxcare.4",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a5887216-dddc-5e49-9cb4-c2b59d2e785e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.3.12-tuxcare.4 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:8c5c7cc6-649e-51f7-a511-406bd374bc91",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.3.12-tuxcare.4 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e8c55b8c-37af-5084-a64a-6892fcfce1e3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66412 affects version 17.3.12-tuxcare.4 of @angular/platform-browser-dynamic, and is fixed in 17.3.12-tuxcare.5."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:fa81a297-388c-5fad-9d68-d0c039cddc2a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22610 affects version 17.3.12-tuxcare.4 of @angular/platform-browser-dynamic, and is fixed in 17.3.12-tuxcare.5."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:de8163c5-b02d-51c7-a0d9-52657bdbcaa3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 17.3.12-tuxcare.4 of @angular/platform-browser-dynamic, and is fixed in 17.3.12-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:3c974772-f629-590b-89f7-5f925816c29d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32635 affects version 17.3.12-tuxcare.4 of @angular/platform-browser-dynamic, and is fixed in 17.3.12-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:8950aeb8-df4b-52e4-8fa0-46cfb7aa3500",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 17.3.12-tuxcare.4 of @angular/platform-browser-dynamic, and is fixed in 17.3.12-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:1be3de42-e58a-506b-92e0-640981c4b70d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 17.3.12-tuxcare.4 of @angular/platform-browser-dynamic, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:bea6b64f-9f79-5229-82ea-408d06725b8b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 17.3.12-tuxcare.4 of @angular/platform-browser-dynamic, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:3c2002b5-f0c6-5fae-af71-7d628d6154e4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 17.3.12-tuxcare.4 of @angular/platform-browser-dynamic, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:0c1d0ee3-ba35-5f6a-a1c2-11faca47dd2d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 17.3.12-tuxcare.4 of @angular/platform-browser-dynamic, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a8327326-02b2-5818-893a-c7a6086fb671",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 17.3.12-tuxcare.4 of @angular/platform-browser-dynamic, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:f8c86876-460f-5f06-ab74-fa96d215620b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 17.3.12-tuxcare.4 of @angular/platform-browser-dynamic, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:f20da005-d6ac-523c-9553-ac6d54f63c15",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 17.3.12-tuxcare.4 of @angular/platform-browser-dynamic, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:77aec85f-2e26-522c-97d2-2f627f48412b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 17.3.12-tuxcare.4 of @angular/platform-browser-dynamic, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:8c11ffed-7286-57ae-ba34-670a7ff47016",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 17.3.12-tuxcare.4 of @angular/platform-browser-dynamic, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:2d088337-1a33-50d6-bbfc-96edab567aa4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 17.3.12-tuxcare.4 of @angular/platform-browser-dynamic, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e2ff3921-3b42-5413-be67-c8eef027ef8d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 17.3.12-tuxcare.4 of @angular/platform-browser-dynamic, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:34370d8d-0587-5e5a-ac61-f37baa7340cd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 17.3.12-tuxcare.4 of @angular/platform-browser-dynamic, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:1a971ac9-f6e2-50be-ac39-d15675c71527",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 17.3.12-tuxcare.4 of @angular/platform-browser-dynamic, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:2dbb705f-303a-5657-9759-337c7bd50f54",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 17.3.12-tuxcare.4 of @angular/platform-browser-dynamic, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:4002a0ac-31ab-55f9-bb5c-0e5cdf9e85af",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 17.3.12-tuxcare.4 of @angular/platform-browser-dynamic, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:bb5cff38-1c89-5a41-a464-717a5a03d408",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 17.3.12-tuxcare.4 of @angular/platform-browser-dynamic, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:7933d77e-55a2-5a3e-8f7b-0223c24cc0f4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 17.3.12-tuxcare.4 of @angular/platform-browser-dynamic, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:695c84fe-975c-53e7-b352-f90211e99dfa",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.3.12-tuxcare.4 of @angular/platform-browser-dynamic. not_affected \u2014 Version 17.3.12 is not affected by CVE-2026-88056. The vulnerability involves String.prototype.trim() being applied during URL resolution in Angular's platform-server, converting validated same-origin URLs with Unicode whitespace into cross-origin protocol-relative URLs, leading to SSRF. This vulnerable code pattern was introduced in newer Angular versions (v20+) and does not exist in version 1...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e896109b-b42d-566f-866d-f64764ee6c0a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 17.3.12-tuxcare.4 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:714ef87b-ceb9-50eb-bb4f-6572ef8a59bf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 17.3.12-tuxcare.4 of @angular/platform-browser-dynamic."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:9d8addac-3a95-505e-944b-5f507e3702af",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 17.3.12-tuxcare.4 of @angular/platform-browser-dynamic."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/platform-browser-dynamic@17.3.12-tuxcare.4"
    }
  ]
}