{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a11438e7-98cc-5c49-bcb7-04d1b95df952",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/platform-webworker",
      "purl": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.4",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.4",
      "version": "8.2.14-tuxcare.4",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:f905a28d-2fd4-5361-8d45-aac8edef2693",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-4231 affects version 8.2.14-tuxcare.4 of @angular/platform-webworker, and is fixed in 8.2.14-tuxcare.5."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:ac85d5c9-830b-5128-8ec0-1e873c2ffc53",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 8.2.14-tuxcare.4 of @angular/platform-webworker, and is fixed in 8.2.14-tuxcare.10."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:cdb50c68-fcce-57ee-b477-953e4d2a21ea",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 8.2.14-tuxcare.4 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:43f70abb-9705-5443-8c40-d790a02856dc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 8.2.14-tuxcare.4 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:2556fb0d-fcd6-5a5d-8d6e-4a465450e1cc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 8.2.14-tuxcare.4 of @angular/platform-webworker, and is fixed in 8.2.14-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:2ad24be6-97ab-5ecf-b0a2-49b0427d3629",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 8.2.14-tuxcare.4 of @angular/platform-webworker, and is fixed in 8.2.14-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:fee6d26a-09de-5336-a9e2-e96654b23145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 8.2.14-tuxcare.4 of @angular/platform-webworker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:7f4cd0fa-6820-5797-879f-b56a22448755",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 8.2.14-tuxcare.4 of @angular/platform-webworker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:018268a3-f7da-5f6e-a861-a45d1aba0e40",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 8.2.14-tuxcare.4 of @angular/platform-webworker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:65c38cf3-e6c5-5727-9845-f6690fbe4a23",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 8.2.14-tuxcare.4 of @angular/platform-webworker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:f829d9ea-9564-54d4-9b50-4136d0d23034",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 8.2.14-tuxcare.4 of @angular/platform-webworker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:01de5bcc-2dff-5deb-86ae-bd582f342d43",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 8.2.14-tuxcare.4 of @angular/platform-webworker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:d2f5951a-f997-52b4-9d7f-94d032f6f2ff",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 8.2.14-tuxcare.4 of @angular/platform-webworker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:4737ebdd-d734-5a01-9253-4c5c8fd536db",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 8.2.14-tuxcare.4 of @angular/platform-webworker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:576665d2-819d-53af-b78e-0e4100f98f3a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 8.2.14-tuxcare.4 of @angular/platform-webworker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:05aac202-8c6b-5122-86fe-3ed41c977bc6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 8.2.14-tuxcare.4 of @angular/platform-webworker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:7c0bb4a3-f92e-55ea-acd9-0713098c4631",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 8.2.14-tuxcare.4 of @angular/platform-webworker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:145cb882-5365-5667-832a-7e542efa3e81",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 8.2.14-tuxcare.4 of @angular/platform-webworker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:f385b88a-599b-5da1-a1c3-77375aa9db93",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 8.2.14-tuxcare.4 of @angular/platform-webworker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:1c34a12a-ec3a-5a94-acb8-b70fbfaea3d0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 8.2.14-tuxcare.4 of @angular/platform-webworker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:7658fb28-5b17-5c75-8996-25bb868159a7",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 8.2.14-tuxcare.4 of @angular/platform-webworker. not_affected \u2014 Angular 8.2.14 is NOT affected by CVE-2026-68945. The vulnerability exists in HttpTransferCache, a feature that automatically caches HTTP requests during SSR for client hydration. HttpTransferCache was introduced in Angular v16+ and does not exist in version 8.2.14. This version has only a manual TransferState key-value store with no automatic HttpClient integration, and no HTTP caching mechani...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:4fe6cccd-f400-5b04-b92c-ed278aae179c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 8.2.14-tuxcare.4 of @angular/platform-webworker, and is fixed in 8.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:bbd70b34-ee10-5866-a153-614981f303ce",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 8.2.14-tuxcare.4 of @angular/platform-webworker, and is fixed in 8.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:73cc9e7b-0c17-566d-9a9b-acac0171760f",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 8.2.14-tuxcare.4 of @angular/platform-webworker. not_affected \u2014 Angular 8.2.14 is NOT AFFECTED by CVE-2026-88056. The vulnerability requires a sophisticated URL resolution utility (`parseUrl` in `packages/platform-server/src/url.ts`) that calls `String.prototype.trim()` to strip Unicode whitespace, creating a discrepancy with WHATWG URL validation. This architecture was introduced in Angular v12+ (circa 2026 as TuxCare backports). Angular 8.2.14 (released N...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:6a73d917-8841-5984-a406-11fba8c4719a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 8.2.14-tuxcare.4 of @angular/platform-webworker."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:49396e57-304f-5a12-bf6a-2502cd6fe786",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 8.2.14-tuxcare.4 of @angular/platform-webworker. not_affected \u2014 Angular v8.2.14 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, provideClientHydration(), and withRequestsMadeViaParent() \u2014 all features that do not exist in this version. These features were introduced in Angular v16 (per patches/CVE-2026-50170.patch and patches/CVE-2026-54266.patch). The target uses the legacy NgModule-based HttpClientModule without automatic ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a746753b-9796-5dbc-9e68-bd4c3b784a7a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 8.2.14-tuxcare.4 of @angular/platform-webworker."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/platform-webworker@8.2.14-tuxcare.4"
    }
  ]
}