{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:bca4f765-5355-5c13-ae56-5aaf3ef1014d",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/platform-browser",
      "purl": "pkg:npm/%40angular/platform-browser@16.2.12-tuxcare.9",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/platform-browser@16.2.12-tuxcare.9",
      "version": "16.2.12-tuxcare.9",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:93e69865-d00c-5eb1-a7a8-7ebb151efaea",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 16.2.12-tuxcare.9 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:59f71b12-4862-5e74-9f8d-9dc1fbe1fc27",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 16.2.12-tuxcare.9 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:d56f873c-06b5-50f8-80fc-83686e92873d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 16.2.12-tuxcare.9 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:425c8631-aba8-569c-aef5-bbf7f79b2ae3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 16.2.12-tuxcare.9 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:eacccd6f-849b-59f5-a6fb-abe396d13e8b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 16.2.12-tuxcare.9 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:bb3b6f37-7fc6-5a49-b0ab-05676698ecc3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 16.2.12-tuxcare.9 of @angular/platform-browser, and is fixed in 16.2.12-tuxcare.10."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:ee8653cf-f4aa-5991-ae26-dc6bf7bdc5dd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 16.2.12-tuxcare.9 of @angular/platform-browser, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:bb47998b-4d02-5133-9d7b-ccd2d3e322c2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 16.2.12-tuxcare.9 of @angular/platform-browser, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:7d7f6fec-72a2-56c6-b7b7-0e1abc8dec4c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 16.2.12-tuxcare.9 of @angular/platform-browser, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:94e7b826-ab8b-5113-b54b-b94b87976006",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 16.2.12-tuxcare.9 of @angular/platform-browser, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:3cbc76af-a018-580b-a578-85e7ecbab78a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 16.2.12-tuxcare.9 of @angular/platform-browser, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:b850a4b5-b023-5138-abc5-b0836373bc6b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 16.2.12-tuxcare.9 of @angular/platform-browser, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:08954fda-ac6b-5e5d-b5e9-f6a99aca87f0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 16.2.12-tuxcare.9 of @angular/platform-browser, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:8c3e5ea8-0c36-5cb0-828e-d4bfea9dede2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 16.2.12-tuxcare.9 of @angular/platform-browser, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:2a7db8f6-8996-5b22-b825-e0ff1571088f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 16.2.12-tuxcare.9 of @angular/platform-browser, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:0801553e-69a3-5449-a630-230c3ca4555b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 16.2.12-tuxcare.9 of @angular/platform-browser, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:2bb06988-d4cb-5173-801a-c6e4cf4b810e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 16.2.12-tuxcare.9 of @angular/platform-browser, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:3109d4ff-d97a-5f45-823d-a8ada4810311",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 16.2.12-tuxcare.9 of @angular/platform-browser, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:ea3d5209-07f0-5df4-af39-076b8f2d7e49",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 16.2.12-tuxcare.9 of @angular/platform-browser, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:84bff6ea-6a1c-502d-a1e0-09ae4969babd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 16.2.12-tuxcare.9 of @angular/platform-browser, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:ae2f58fd-8096-57de-9540-b2ea5c86037d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 16.2.12-tuxcare.9 of @angular/platform-browser, and is fixed in 16.2.12-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:c0958724-d3ed-5b44-a4d4-f3357e16ab76",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 16.2.12-tuxcare.9 of @angular/platform-browser, and is fixed in 16.2.12-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:969cd588-b22d-54c6-bd7c-f9e2b8a99f25",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 16.2.12-tuxcare.9 of @angular/platform-browser, and is fixed in 16.2.12-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:9abbcc0b-a13f-5263-963b-f702b2bd1d00",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 16.2.12-tuxcare.9 of @angular/platform-browser. not_affected \u2014 CVE-2026-88056 affects Angular versions 20.3.x, 21.2.x, and 22.x where a refactored URL parsing utility added String.prototype.trim() that strips Unicode whitespace, enabling SSRF bypasses. The target (Angular 16.2.12-tuxcare.12) is based on Angular 16.2.x architecture, which predates the vulnerable code pattern entirely. TuxCare created url.ts fresh on June 24, 2026 for CVE-2026-50168, modelin...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:e710088a-2082-5e91-b0e4-c438b7157d3b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 16.2.12-tuxcare.9 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:f177d57d-1be6-545b-b810-92db0586bc87",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 16.2.12-tuxcare.9 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@16.2.12-tuxcare.9"
        }
      ],
      "bom-ref": "urn:uuid:094e4079-4dd6-5bc9-88c4-3b14f326f4be",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 16.2.12-tuxcare.9 of @angular/platform-browser."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/platform-browser@16.2.12-tuxcare.9"
    }
  ]
}