{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d8d30a93-488d-54f9-8383-402f5dd03efa",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/platform-server",
      "purl": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.7",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.7",
      "version": "18.2.14-tuxcare.7",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:fe4f8dd9-ae7d-5fb0-ad1a-44b786187d3b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.2.14-tuxcare.7 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:2ab95f43-570d-590b-bf82-7dd97cfee1e9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 18.2.14-tuxcare.7 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:22e04cdc-3cb1-5fb9-bbdf-ff4aa8155e3f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 18.2.14-tuxcare.7 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:a6e4957e-137c-5b34-8683-ab9207d631e1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 18.2.14-tuxcare.7 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:668eecfa-92cc-5ded-a2dc-18b9e64b445f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 18.2.14-tuxcare.7 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:b447b1fe-0999-540b-8bb2-a8208fe66ee4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 18.2.14-tuxcare.7 of @angular/platform-server, and is fixed in 18.2.14-tuxcare.10."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:a43ae17d-52d7-5920-8e96-6d44f6ade46f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 18.2.14-tuxcare.7 of @angular/platform-server, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:477cb7e9-e174-5e08-947a-22ea9dcdc5d8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 18.2.14-tuxcare.7 of @angular/platform-server, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:1681df14-f702-5dc2-b4ba-2e1f21bed66b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 18.2.14-tuxcare.7 of @angular/platform-server, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:6b4a6411-c627-566a-b5ae-75bbf248711c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 18.2.14-tuxcare.7 of @angular/platform-server, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:7818db9a-3fb4-5270-98b7-b8a0c7f016aa",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 18.2.14-tuxcare.7 of @angular/platform-server, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:c609a85c-79cb-50c6-8a52-f621543056a3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 18.2.14-tuxcare.7 of @angular/platform-server, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:4b3acb90-eb31-5ad9-910a-87d75d4ae7e4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 18.2.14-tuxcare.7 of @angular/platform-server, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:15bb52a2-b0aa-5b0d-a55b-6a2c996af7ea",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 18.2.14-tuxcare.7 of @angular/platform-server, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:0eb5be1a-1719-52e8-ba9a-073bf24cedbc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 18.2.14-tuxcare.7 of @angular/platform-server, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:5fcd5311-9e82-5fe4-a9a1-3a349a220fdc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 18.2.14-tuxcare.7 of @angular/platform-server, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:28f08576-3caf-53fc-aca8-7e71645a6ff6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 18.2.14-tuxcare.7 of @angular/platform-server, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:2cb65ac9-087a-5109-87cd-e7853721bdf2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 18.2.14-tuxcare.7 of @angular/platform-server, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:63c64788-7521-5670-8cb9-ab964200a0fb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 18.2.14-tuxcare.7 of @angular/platform-server, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:c4065678-07dc-59fc-8bb1-3f70f0cdf15f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 18.2.14-tuxcare.7 of @angular/platform-server, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:9a443e46-6a9f-5261-92c9-e7bbc7f26c46",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 18.2.14-tuxcare.7 of @angular/platform-server, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:882a04f6-d696-5135-a380-edac5a7a0dea",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 18.2.14-tuxcare.7 of @angular/platform-server, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:d60392e9-9103-53db-b128-dbcf0323227f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 18.2.14-tuxcare.7 of @angular/platform-server, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:3fb30e7d-8e7e-553d-b042-db3e70dfda64",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 18.2.14-tuxcare.7 of @angular/platform-server. not_affected \u2014 The target version 18.2.14-tuxcare.13 is NOT affected by CVE-2026-88056. The vulnerable code pattern (calling String.prototype.trim() on URL strings before resolution) was never present in this version. The target uses a refactored parseUrl() implementation introduced via commit 49a60f6045 (May 2026) that correctly handles Unicode whitespace by percent-encoding it rather than stripping it, main...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:570d0402-bc7a-56e0-8d85-47dc6904295d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 18.2.14-tuxcare.7 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:2d6e4ff5-854f-50e4-b815-9345647e5fd7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 18.2.14-tuxcare.7 of @angular/platform-server."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:a387945f-2b7d-532a-903e-b5b80303d775",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 18.2.14-tuxcare.7 of @angular/platform-server."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/platform-server@18.2.14-tuxcare.7"
    }
  ]
}