{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:50efe5fd-c200-5bc7-bd4c-22db34c87019",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/platform-webworker-dynamic",
      "purl": "pkg:npm/%40angular/platform-webworker-dynamic@8.2.14-tuxcare.7",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/platform-webworker-dynamic@8.2.14-tuxcare.7",
      "version": "8.2.14-tuxcare.7",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@8.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:4bcc9311-8e88-51d9-925b-9c5a3f849850",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 8.2.14-tuxcare.7 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@8.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:0446943f-3a1e-55b4-93a4-0807cac93db4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 8.2.14-tuxcare.7 of @angular/platform-webworker-dynamic, and is fixed in 8.2.14-tuxcare.10."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@8.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:9c3a5816-d392-5bde-b047-249d617e67fd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 8.2.14-tuxcare.7 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@8.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:369eb10e-ba55-5e59-9a7c-2b2db74b5a88",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 8.2.14-tuxcare.7 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@8.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:bdae7908-540e-561b-ab18-54ef8428f9b6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 8.2.14-tuxcare.7 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@8.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:674f83de-6a9a-55e9-b54d-87b90edf8a6d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 8.2.14-tuxcare.7 of @angular/platform-webworker-dynamic, and is fixed in 8.2.14-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@8.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:0e5a0c6e-7355-58e2-8930-2e1078bdbeda",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 8.2.14-tuxcare.7 of @angular/platform-webworker-dynamic, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@8.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:44340939-f9e4-5c1f-959c-2cb9e91f9c5c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 8.2.14-tuxcare.7 of @angular/platform-webworker-dynamic, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@8.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:686741b0-566e-54fd-b89f-69063805a78b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 8.2.14-tuxcare.7 of @angular/platform-webworker-dynamic, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@8.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:01518f8d-cf0a-5af2-b0c1-dd61d53e8634",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 8.2.14-tuxcare.7 of @angular/platform-webworker-dynamic, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@8.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:9730fbf5-df10-5329-b787-f7c5dccab7e4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 8.2.14-tuxcare.7 of @angular/platform-webworker-dynamic, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@8.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:2a0d631b-7ef1-55a6-9f55-678cb3ed4c1f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 8.2.14-tuxcare.7 of @angular/platform-webworker-dynamic, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@8.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:5da3e38d-ba3b-51bc-841b-acf3412fbe2c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 8.2.14-tuxcare.7 of @angular/platform-webworker-dynamic, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@8.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:22be7a15-1cc5-52c4-b927-4b1a3a0f08da",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 8.2.14-tuxcare.7 of @angular/platform-webworker-dynamic, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@8.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:37e93afb-7f9e-5478-8cde-83a2fae9baa4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 8.2.14-tuxcare.7 of @angular/platform-webworker-dynamic, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@8.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:101f86b1-4b6e-509b-8197-206220eb715a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 8.2.14-tuxcare.7 of @angular/platform-webworker-dynamic, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@8.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:fcca72eb-804a-53ae-b213-b36e512d5c51",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 8.2.14-tuxcare.7 of @angular/platform-webworker-dynamic, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@8.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:d1c0e254-47b1-5d29-9000-777098fee775",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 8.2.14-tuxcare.7 of @angular/platform-webworker-dynamic, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@8.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:59116d75-7f32-566c-9a75-da9bbeba5611",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 8.2.14-tuxcare.7 of @angular/platform-webworker-dynamic, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@8.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:849d6c81-b97d-5fe7-b390-e544a85ab729",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 8.2.14-tuxcare.7 of @angular/platform-webworker-dynamic, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@8.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:f3798f3d-65aa-5c39-9763-cfffc86c7258",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 8.2.14-tuxcare.7 of @angular/platform-webworker-dynamic. not_affected \u2014 Angular 8.2.14 is NOT affected by CVE-2026-68945. The vulnerability exists in HttpTransferCache, a feature that automatically caches HTTP requests during SSR for client hydration. HttpTransferCache was introduced in Angular v16+ and does not exist in version 8.2.14. This version has only a manual TransferState key-value store with no automatic HttpClient integration, and no HTTP caching mechani...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@8.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:f10560a5-28dc-55c6-a72d-09c25b4cc07d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 8.2.14-tuxcare.7 of @angular/platform-webworker-dynamic, and is fixed in 8.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@8.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:2c2e3a52-2cca-5d86-b0fd-f1104746e2ef",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 8.2.14-tuxcare.7 of @angular/platform-webworker-dynamic, and is fixed in 8.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@8.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:159f3679-c33a-5061-8346-fa5c0ae92b8c",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 8.2.14-tuxcare.7 of @angular/platform-webworker-dynamic. not_affected \u2014 Angular 8.2.14 is NOT AFFECTED by CVE-2026-88056. The vulnerability requires a sophisticated URL resolution utility (`parseUrl` in `packages/platform-server/src/url.ts`) that calls `String.prototype.trim()` to strip Unicode whitespace, creating a discrepancy with WHATWG URL validation. This architecture was introduced in Angular v12+ (circa 2026 as TuxCare backports). Angular 8.2.14 (released N...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@8.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:e1c0ffe1-017c-5f78-801c-c96717b5ed12",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 8.2.14-tuxcare.7 of @angular/platform-webworker-dynamic."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@8.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:ebe0eefb-b64a-525e-b6b4-e15e8d91cfd1",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 8.2.14-tuxcare.7 of @angular/platform-webworker-dynamic. not_affected \u2014 Angular v8.2.14 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, provideClientHydration(), and withRequestsMadeViaParent() \u2014 all features that do not exist in this version. These features were introduced in Angular v16 (per patches/CVE-2026-50170.patch and patches/CVE-2026-54266.patch). The target uses the legacy NgModule-based HttpClientModule without automatic ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker-dynamic@8.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:ff7ce9f6-2ad9-54af-9404-8a00e0cf160e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 8.2.14-tuxcare.7 of @angular/platform-webworker-dynamic."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/platform-webworker-dynamic@8.2.14-tuxcare.7"
    }
  ]
}