{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:fbc3b591-7916-5ccd-ad64-dbd8679864a1",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/platform-server",
      "purl": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.6",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.6",
      "version": "18.2.14-tuxcare.6",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6f163dfb-cf90-511a-b1e2-9b6891b60f5f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.2.14-tuxcare.6 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:21f5ad0a-f0a2-5c1e-bcc1-3c62b167a0aa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 18.2.14-tuxcare.6 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:00859917-8066-553a-80e6-2072ce24f854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 18.2.14-tuxcare.6 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:36b72b2c-4930-5372-8280-a274514741c2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 18.2.14-tuxcare.6 of @angular/platform-server, and is fixed in 18.2.14-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1c932497-adbf-541d-a7a7-183e7da49730",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 18.2.14-tuxcare.6 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:79ab2ada-02c5-5ff4-b6e0-2a8d92ed776a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 18.2.14-tuxcare.6 of @angular/platform-server, and is fixed in 18.2.14-tuxcare.10."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:3a8e4a39-dd68-5ac9-b753-b4aff3b37d73",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 18.2.14-tuxcare.6 of @angular/platform-server, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1b279173-ad40-5f4f-8978-5ead534bcbe0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 18.2.14-tuxcare.6 of @angular/platform-server, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c967b76d-cd09-54ef-9e10-078743b973b1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 18.2.14-tuxcare.6 of @angular/platform-server, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d97f4443-c875-52d3-9a51-d092d1923832",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 18.2.14-tuxcare.6 of @angular/platform-server, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:8076407a-2ff0-50ef-86e5-f0c5608e33c3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 18.2.14-tuxcare.6 of @angular/platform-server, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:0325c2e6-27bf-5819-b3fc-8fe44dcee915",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 18.2.14-tuxcare.6 of @angular/platform-server, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f28adf53-3ea8-5804-85a9-ac711291fc9c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 18.2.14-tuxcare.6 of @angular/platform-server, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a8f69407-5bd2-517c-bc94-17bd8c0a8651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 18.2.14-tuxcare.6 of @angular/platform-server, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:66d4f7c9-b703-5aac-b467-9a1b9ab2d543",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 18.2.14-tuxcare.6 of @angular/platform-server, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:74793ab5-6f2a-5c57-9368-bce23b4a79f8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 18.2.14-tuxcare.6 of @angular/platform-server, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:792f2e28-615f-5086-a2e8-a1de2a06218d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 18.2.14-tuxcare.6 of @angular/platform-server, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d8a0999e-2476-5d53-9961-10def56f1f51",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 18.2.14-tuxcare.6 of @angular/platform-server, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:7e3dbf2a-a525-57c8-800b-27b7c4837dc9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 18.2.14-tuxcare.6 of @angular/platform-server, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:64c367d7-e0c5-5328-bac6-655991495890",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 18.2.14-tuxcare.6 of @angular/platform-server, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:9b8d63c7-4c40-5695-9371-1a898b46cdaf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 18.2.14-tuxcare.6 of @angular/platform-server, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:870d1f93-0a84-5514-aae4-b17feb8ca0af",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 18.2.14-tuxcare.6 of @angular/platform-server, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:8fe64992-6414-54d8-98e4-28ca31d0372e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 18.2.14-tuxcare.6 of @angular/platform-server, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c2f20baf-b062-593e-b764-e54e01b56857",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 18.2.14-tuxcare.6 of @angular/platform-server. not_affected \u2014 The target version 18.2.14-tuxcare.13 is NOT affected by CVE-2026-88056. The vulnerable code pattern (calling String.prototype.trim() on URL strings before resolution) was never present in this version. The target uses a refactored parseUrl() implementation introduced via commit 49a60f6045 (May 2026) that correctly handles Unicode whitespace by percent-encoding it rather than stripping it, main...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:906d179c-cdb8-5329-b498-d287b7417fa6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 18.2.14-tuxcare.6 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c7ec80de-d022-5578-8a2e-a2ec42632572",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 18.2.14-tuxcare.6 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a2f37eea-1323-5be0-a0d4-c39f3f045ea7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 18.2.14-tuxcare.6 of @angular/platform-server."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.6"
    }
  ]
}