{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b499b501-b2f4-54e4-82cd-317bfdcefb62",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/platform-webworker",
      "purl": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.1",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.1",
      "version": "8.2.14-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:929d957e-9931-5eec-9f80-afe683886bc7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-4231 affects version 8.2.14-tuxcare.1 of @angular/platform-webworker, and is fixed in 8.2.14-tuxcare.5."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f45d1a69-0ae8-5021-be04-a273551f2a7f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 8.2.14-tuxcare.1 of @angular/platform-webworker, and is fixed in 8.2.14-tuxcare.10."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7b0ee52f-aa6c-5ba5-ac19-b133749f0ac5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66412 affects version 8.2.14-tuxcare.1 of @angular/platform-webworker, and is fixed in 8.2.14-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a75c5e3d-1352-557b-91ea-83f64c440e23",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22610 affects version 8.2.14-tuxcare.1 of @angular/platform-webworker, and is fixed in 8.2.14-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6b3b907b-aaa2-598c-acdc-0f34fc68f1cb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 8.2.14-tuxcare.1 of @angular/platform-webworker, and is fixed in 8.2.14-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b74e805a-dca7-5a56-b83f-e9cd5a22ca7d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 8.2.14-tuxcare.1 of @angular/platform-webworker, and is fixed in 8.2.14-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8dfb69c1-9c88-503d-87db-7af772f6d8b8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 8.2.14-tuxcare.1 of @angular/platform-webworker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a42221bf-7ac6-534b-aa29-3fe19971fa30",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 8.2.14-tuxcare.1 of @angular/platform-webworker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:193c61ce-caa2-566c-b25f-b22c7ffdbf2d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 8.2.14-tuxcare.1 of @angular/platform-webworker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:48d87a0f-6b4b-54d8-933a-354012aa3039",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 8.2.14-tuxcare.1 of @angular/platform-webworker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:69d2c111-ea0f-557b-9126-4fce18b9e151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 8.2.14-tuxcare.1 of @angular/platform-webworker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7f069a69-45c1-5725-88ed-efc8aa64b920",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 8.2.14-tuxcare.1 of @angular/platform-webworker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ccc18233-817c-5b4f-89e5-0a4b8e8cd1de",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 8.2.14-tuxcare.1 of @angular/platform-webworker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:51896ad6-f4c6-507d-9241-40ec2b9df73c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 8.2.14-tuxcare.1 of @angular/platform-webworker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:31d1c2e2-c74c-5d5c-9319-cc75103745d9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 8.2.14-tuxcare.1 of @angular/platform-webworker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:be6c4d7e-93a0-5aee-b3ba-cd76e7cb93de",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 8.2.14-tuxcare.1 of @angular/platform-webworker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f3f6d5bc-164e-5183-8e04-48d4188c8376",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 8.2.14-tuxcare.1 of @angular/platform-webworker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:dba3f3ad-9eb8-55e8-91ea-41b5007efadc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 8.2.14-tuxcare.1 of @angular/platform-webworker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d56f8758-221c-5c25-993f-751daafb6a76",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 8.2.14-tuxcare.1 of @angular/platform-webworker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:45894795-917d-5283-83bd-64dfeffa14fe",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 8.2.14-tuxcare.1 of @angular/platform-webworker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:469e3870-ef6f-5920-a28b-76702b0ad9f2",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 8.2.14-tuxcare.1 of @angular/platform-webworker. not_affected \u2014 Angular 8.2.14 is NOT affected by CVE-2026-68945. The vulnerability exists in HttpTransferCache, a feature that automatically caches HTTP requests during SSR for client hydration. HttpTransferCache was introduced in Angular v16+ and does not exist in version 8.2.14. This version has only a manual TransferState key-value store with no automatic HttpClient integration, and no HTTP caching mechani...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:470b92d3-f26d-53ab-8ce9-943bc5a7d247",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 8.2.14-tuxcare.1 of @angular/platform-webworker, and is fixed in 8.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:91590b23-36a0-5f89-b579-b32744b1503d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 8.2.14-tuxcare.1 of @angular/platform-webworker, and is fixed in 8.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5472ac3c-9c37-5909-96d0-740e7cb72f1a",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 8.2.14-tuxcare.1 of @angular/platform-webworker. not_affected \u2014 Angular 8.2.14 is NOT AFFECTED by CVE-2026-88056. The vulnerability requires a sophisticated URL resolution utility (`parseUrl` in `packages/platform-server/src/url.ts`) that calls `String.prototype.trim()` to strip Unicode whitespace, creating a discrepancy with WHATWG URL validation. This architecture was introduced in Angular v12+ (circa 2026 as TuxCare backports). Angular 8.2.14 (released N...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4ab797f3-7878-5096-a547-98c80e8e9783",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 8.2.14-tuxcare.1 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4b4df8f0-68ee-55a8-9aae-12ea5c5e1c5b",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 8.2.14-tuxcare.1 of @angular/platform-webworker. not_affected \u2014 Angular v8.2.14 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, provideClientHydration(), and withRequestsMadeViaParent() \u2014 all features that do not exist in this version. These features were introduced in Angular v16 (per patches/CVE-2026-50170.patch and patches/CVE-2026-54266.patch). The target uses the legacy NgModule-based HttpClientModule without automatic ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:94899775-5aeb-50ca-87c0-900be9907c2d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 8.2.14-tuxcare.1 of @angular/platform-webworker."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.1"
    }
  ]
}