{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a14ace58-c70d-5cbb-bbd0-eee53a6474d8",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/platform-server",
      "purl": "pkg:npm/%40angular/platform-server@17.3.12-tuxcare.11",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/platform-server@17.3.12-tuxcare.11",
      "version": "17.3.12-tuxcare.11",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@17.3.12-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:e5d20bb0-45c1-5171-8702-acdb6bece3cd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.3.12-tuxcare.11 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@17.3.12-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:b4126cac-d8a9-5904-a336-2c9788902774",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.3.12-tuxcare.11 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@17.3.12-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:37044c4e-5a31-52a4-a6a0-f149ee310fb5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.3.12-tuxcare.11 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@17.3.12-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:42b1b3cb-a1de-5bb7-8e62-2ebd98e74253",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.3.12-tuxcare.11 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@17.3.12-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:0d1eb161-fe24-5292-ad05-b28dc5c0aef8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.3.12-tuxcare.11 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@17.3.12-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:e24b09b0-2577-59a0-be05-6c0099a8484f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.3.12-tuxcare.11 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@17.3.12-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:e9afdcb3-4bdf-5edc-b21a-2d960d55606c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 17.3.12-tuxcare.11 of @angular/platform-server, and is fixed in 17.3.12-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@17.3.12-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:f4a650fc-6740-51f3-a5a2-bb59d581ddf5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 17.3.12-tuxcare.11 of @angular/platform-server, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@17.3.12-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:ada8b28c-624a-564f-89b2-9b5848e02b7c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 17.3.12-tuxcare.11 of @angular/platform-server, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@17.3.12-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:42aeb5e7-9b7b-59bf-ae1b-f24c9de70827",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 17.3.12-tuxcare.11 of @angular/platform-server, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@17.3.12-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:c2ebc461-af04-598d-9e98-24c0366878de",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 17.3.12-tuxcare.11 of @angular/platform-server, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@17.3.12-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:d46556a5-26c9-58d7-94cb-7004eaadf1c6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 17.3.12-tuxcare.11 of @angular/platform-server, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@17.3.12-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:4270710c-b157-5671-bf4e-ef25dd2a7a12",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 17.3.12-tuxcare.11 of @angular/platform-server, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@17.3.12-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:ad0d2364-5aae-5063-839a-81a6227c925c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 17.3.12-tuxcare.11 of @angular/platform-server, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@17.3.12-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:a912edb4-9bb1-55b1-9d96-95d2fcf1a4e7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 17.3.12-tuxcare.11 of @angular/platform-server, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@17.3.12-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:4d7d459e-c45d-5def-8bcf-0367dcab284a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 17.3.12-tuxcare.11 of @angular/platform-server, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@17.3.12-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:6292fb90-9138-596d-9585-2813f6604e73",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 17.3.12-tuxcare.11 of @angular/platform-server, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@17.3.12-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:89a829c9-540e-530d-8019-d4878b79cb2c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 17.3.12-tuxcare.11 of @angular/platform-server, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@17.3.12-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:e51f3224-a94b-55ca-b7e7-58bda638b1a4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 17.3.12-tuxcare.11 of @angular/platform-server, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@17.3.12-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:20c59d07-eb04-51b9-bc9d-b0628e30e97c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 17.3.12-tuxcare.11 of @angular/platform-server, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@17.3.12-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:a6baef4d-e1c4-55d6-a715-5a3943765496",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 17.3.12-tuxcare.11 of @angular/platform-server, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@17.3.12-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:ac6ed745-9eb6-56d7-9fb7-47197ff24104",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 17.3.12-tuxcare.11 of @angular/platform-server, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@17.3.12-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:68793663-2bdf-5c97-96be-4435fb142f03",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 17.3.12-tuxcare.11 of @angular/platform-server, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@17.3.12-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:cdd9c596-f45f-5631-b87d-1c684229d370",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 17.3.12-tuxcare.11 of @angular/platform-server, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@17.3.12-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:d815c337-ff3c-51b7-9740-2fb5740ca05c",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.3.12-tuxcare.11 of @angular/platform-server. not_affected \u2014 Version 17.3.12 is not affected by CVE-2026-88056. The vulnerability involves String.prototype.trim() being applied during URL resolution in Angular's platform-server, converting validated same-origin URLs with Unicode whitespace into cross-origin protocol-relative URLs, leading to SSRF. This vulnerable code pattern was introduced in newer Angular versions (v20+) and does not exist in version 1...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@17.3.12-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:2c096970-95a8-57f8-88bf-feab2069af7e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 17.3.12-tuxcare.11 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@17.3.12-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:e8abadfe-ad8a-5a07-911e-11afb483636f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 17.3.12-tuxcare.11 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@17.3.12-tuxcare.11"
        }
      ],
      "bom-ref": "urn:uuid:13920666-8f17-53da-b754-077670d7c04c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 17.3.12-tuxcare.11 of @angular/platform-server."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/platform-server@17.3.12-tuxcare.11"
    }
  ]
}