{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:87b23a8c-6c80-589a-beca-b5c6fd7ecb3b",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/platform-browser",
      "purl": "pkg:npm/%40angular/platform-browser@12.2.17-tuxcare.2",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/platform-browser@12.2.17-tuxcare.2",
      "version": "12.2.17-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@12.2.17-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:cdaea896-70a9-5695-8c88-cb308cd0d955",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 12.2.17-tuxcare.2 of @angular/platform-browser, and is fixed in 12.2.17-tuxcare.8."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@12.2.17-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:69647099-679f-5095-8a2f-47044ece80db",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 12.2.17-tuxcare.2 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@12.2.17-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:97782c92-9aaa-53e1-98ef-03fce329c598",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22610 affects version 12.2.17-tuxcare.2 of @angular/platform-browser, and is fixed in 12.2.17-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@12.2.17-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f5fb30ed-2e39-5e29-8887-5e781b45332b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 12.2.17-tuxcare.2 of @angular/platform-browser, and is fixed in 12.2.17-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@12.2.17-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:72694c77-4c49-50b4-9bb8-54463eb4dc82",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 12.2.17-tuxcare.2 of @angular/platform-browser, and is fixed in 12.2.17-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@12.2.17-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:590f438a-a0ab-5c87-b173-429d00b99d2f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 12.2.17-tuxcare.2 of @angular/platform-browser, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@12.2.17-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d400a1b8-a3f7-59bd-b2fd-befa24e716d5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 12.2.17-tuxcare.2 of @angular/platform-browser, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@12.2.17-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:31a469f3-2904-5ec5-b0b2-1a39c3063c2b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 12.2.17-tuxcare.2 of @angular/platform-browser, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@12.2.17-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b2185efb-afdd-5baf-9cef-c189f7a218f5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 12.2.17-tuxcare.2 of @angular/platform-browser, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@12.2.17-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:90964150-a21b-5ada-bf1e-60cf6ea69a04",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 12.2.17-tuxcare.2 of @angular/platform-browser, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@12.2.17-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:87a7b87c-026a-5670-a518-d22bc4a4ed52",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 12.2.17-tuxcare.2 of @angular/platform-browser, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@12.2.17-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:d4f4d749-c622-5b8e-a0fe-ddabaa897a96",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 12.2.17-tuxcare.2 of @angular/platform-browser, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@12.2.17-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c9077b65-bbe7-50ee-bfc1-515f972f221c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 12.2.17-tuxcare.2 of @angular/platform-browser, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@12.2.17-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e3e43331-2800-549d-a5f9-7e1934426648",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 12.2.17-tuxcare.2 of @angular/platform-browser, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@12.2.17-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5718ae17-edb2-5eeb-a370-8b67e341b3bb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 12.2.17-tuxcare.2 of @angular/platform-browser, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@12.2.17-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f751ab86-6461-5405-9328-82d145881216",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 12.2.17-tuxcare.2 of @angular/platform-browser, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@12.2.17-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:73adc958-0114-5c07-a65f-88bad597a36e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 12.2.17-tuxcare.2 of @angular/platform-browser, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@12.2.17-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:169284f3-358b-5af5-92b3-14e40557a09e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 12.2.17-tuxcare.2 of @angular/platform-browser, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@12.2.17-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:28c7765d-f072-5fcb-baa0-add82c7b45d8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 12.2.17-tuxcare.2 of @angular/platform-browser, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@12.2.17-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:5ffc26b7-b184-5aff-a277-286039e13a9b",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 12.2.17-tuxcare.2 of @angular/platform-browser. not_affected \u2014 Angular 12.2.17 does not contain the HttpTransferCache feature affected by CVE-2026-68945. HttpTransferCache, which caches HTTP requests during Server-Side Rendering (SSR), was first introduced in Angular 16.0.0\u2014approximately 4 major versions after the target version. The vulnerability concerns cache-key collision when repeated HTTP parameters are serialized, but since the entire HttpTransferCa...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@12.2.17-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:f5a095ef-1f03-5f25-812c-2ed1f6336a64",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 12.2.17-tuxcare.2 of @angular/platform-browser, and is fixed in 12.2.17-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@12.2.17-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0eaaf7fb-2e09-5796-81d7-2e0836ef83be",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 12.2.17-tuxcare.2 of @angular/platform-browser, and is fixed in 12.2.17-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@12.2.17-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:de69d413-a8d8-5866-a150-b95e15f2a8cf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88056 affects version 12.2.17-tuxcare.2 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@12.2.17-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e1741197-ed8b-5001-9b53-0af67ef8a98f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 12.2.17-tuxcare.2 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@12.2.17-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:2bcc9803-f682-5080-96db-40043e399df7",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 12.2.17-tuxcare.2 of @angular/platform-browser. not_affected \u2014 Angular 12.2.17-tuxcare.9 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, withRequestsMadeViaParent(), and provideClientHydration() features which were introduced in Angular 16.0.0. This version uses the older module-based HttpClientModule system and lacks the entire SSR hydration transfer-cache infrastructure. The vulnerable code pattern described in the CVE do...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@12.2.17-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3c3da77d-133a-5668-ad6a-7905b80c1bbb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 12.2.17-tuxcare.2 of @angular/platform-browser."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/platform-browser@12.2.17-tuxcare.2"
    }
  ]
}