{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:1b10e79b-0f5d-5e55-b6cf-103e39347c42",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/platform-browser",
      "purl": "pkg:npm/%40angular/platform-browser@8.2.14-tuxcare.6",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/platform-browser@8.2.14-tuxcare.6",
      "version": "8.2.14-tuxcare.6",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6573cb5d-581b-5590-8bd6-37ea7e9a4c0e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 8.2.14-tuxcare.6 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:242bd829-a4b8-5e3e-9ae7-469cea64691d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 8.2.14-tuxcare.6 of @angular/platform-browser, and is fixed in 8.2.14-tuxcare.10."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b7b82134-bd76-532b-9a15-264ca54d7ef1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 8.2.14-tuxcare.6 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:03160968-1d9d-5756-94fb-50a89a9fd9b4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 8.2.14-tuxcare.6 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:9e47aacb-a862-535d-81de-eb505b1cf303",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 8.2.14-tuxcare.6 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4521445a-7d5f-59ba-a2b8-fa7407e09fc3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 8.2.14-tuxcare.6 of @angular/platform-browser, and is fixed in 8.2.14-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:9e55c550-d72b-585d-ae91-f9f819792d8d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 8.2.14-tuxcare.6 of @angular/platform-browser, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1659c320-e072-5173-b919-8ec0ae472873",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 8.2.14-tuxcare.6 of @angular/platform-browser, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:af444de7-aa08-5b08-9bae-00e6c79bfc2e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 8.2.14-tuxcare.6 of @angular/platform-browser, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:687e5c88-3067-5648-afdb-a227934a3cf0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 8.2.14-tuxcare.6 of @angular/platform-browser, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a740b0be-1d7b-50f5-84e1-38a036dcc46c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 8.2.14-tuxcare.6 of @angular/platform-browser, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2c10a4a9-0685-53df-b3a9-0adfe1d2bafb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 8.2.14-tuxcare.6 of @angular/platform-browser, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:56451e99-3f0a-5fd5-a0af-d46715cf83ca",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 8.2.14-tuxcare.6 of @angular/platform-browser, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:989f74d1-75dc-5ce2-a03d-1d5b668c5240",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 8.2.14-tuxcare.6 of @angular/platform-browser, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f877c199-0522-562b-9df6-fcddeba1aa89",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 8.2.14-tuxcare.6 of @angular/platform-browser, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4078af67-f29b-5414-93d5-280a4ff0d08f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 8.2.14-tuxcare.6 of @angular/platform-browser, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:32e5b852-6c43-545f-b855-53bf04705e95",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 8.2.14-tuxcare.6 of @angular/platform-browser, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a6e43aaf-1216-533e-9ba0-028bb75609f6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 8.2.14-tuxcare.6 of @angular/platform-browser, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:5a38707f-710f-5826-8789-945bd407ef7f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 8.2.14-tuxcare.6 of @angular/platform-browser, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:7c2b63b1-af1c-535a-b5db-d06bfb8b2e86",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 8.2.14-tuxcare.6 of @angular/platform-browser, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:15808274-a91d-540c-8957-3d6258e6d36b",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 8.2.14-tuxcare.6 of @angular/platform-browser. not_affected \u2014 Angular 8.2.14 is NOT affected by CVE-2026-68945. The vulnerability exists in HttpTransferCache, a feature that automatically caches HTTP requests during SSR for client hydration. HttpTransferCache was introduced in Angular v16+ and does not exist in version 8.2.14. This version has only a manual TransferState key-value store with no automatic HttpClient integration, and no HTTP caching mechani...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c2a27915-cc0d-5cb3-b92b-de22b91dc5d7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 8.2.14-tuxcare.6 of @angular/platform-browser, and is fixed in 8.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:66eb7b38-2437-5060-8d97-367ebeb8ae26",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 8.2.14-tuxcare.6 of @angular/platform-browser, and is fixed in 8.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:8fa8c107-e2ea-51d8-aa66-3935ea37a48c",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 8.2.14-tuxcare.6 of @angular/platform-browser. not_affected \u2014 Angular 8.2.14 is NOT AFFECTED by CVE-2026-88056. The vulnerability requires a sophisticated URL resolution utility (`parseUrl` in `packages/platform-server/src/url.ts`) that calls `String.prototype.trim()` to strip Unicode whitespace, creating a discrepancy with WHATWG URL validation. This architecture was introduced in Angular v12+ (circa 2026 as TuxCare backports). Angular 8.2.14 (released N...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:31f3ff60-12b5-56d0-ad1f-370fc5ad77d8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 8.2.14-tuxcare.6 of @angular/platform-browser."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a4088bc0-062f-5cee-9cbe-118d0d645fcb",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 8.2.14-tuxcare.6 of @angular/platform-browser. not_affected \u2014 Angular v8.2.14 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, provideClientHydration(), and withRequestsMadeViaParent() \u2014 all features that do not exist in this version. These features were introduced in Angular v16 (per patches/CVE-2026-50170.patch and patches/CVE-2026-54266.patch). The target uses the legacy NgModule-based HttpClientModule without automatic ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-browser@8.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:fe42ad1b-549f-5afb-878e-790aa1c79559",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 8.2.14-tuxcare.6 of @angular/platform-browser."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/platform-browser@8.2.14-tuxcare.6"
    }
  ]
}