{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f6b048fa-8c1f-5379-bec8-10977950bf32",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/service-worker",
      "purl": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.13",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.13",
      "version": "17.3.12-tuxcare.13",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:5cd3834b-4be4-5a30-905a-b01d67c6d864",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.3.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:e26f966e-51f0-5436-b955-4b0002b6be1a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.3.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:899a1d4a-1d4f-5cac-90d4-daf8748385e8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.3.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:d17549c3-15d2-53e3-a423-4661cb5b7eb1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.3.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:2b54bde4-989d-5347-93e7-5dd13d5e8bef",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.3.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:d334a54d-ff7a-5ef8-b0a9-d21a88a5abbf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.3.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:0cf106d0-37d6-5b4f-8021-b8ba6972796a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 17.3.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:6b8e471d-b8ec-5a4f-ad92-4e1d6f03e4e3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 17.3.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:5bfc4e2a-3d26-5e78-a1d7-6e46074f7869",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 17.3.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:d63e2715-4942-5486-9321-09b59655d39d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 17.3.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:416d2251-378e-52bd-b869-b4b270167380",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 17.3.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:c05f5e96-8701-5980-be54-9dcf0c120e2e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 17.3.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:7308b004-bd12-5544-bcab-214c79026123",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 17.3.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:040fc2ac-6c4f-520f-9d67-b20916a1abf6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 17.3.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:aca905b8-3dbc-5b40-bf9e-5c7bfac54d39",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 17.3.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:f12dcaf8-0992-5930-aeb3-c665d4040b39",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 17.3.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:3ada335e-9e9f-5dca-b875-882740c0f5b3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 17.3.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:f0ba56a9-81f3-5478-84be-1bbee45de459",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 17.3.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:32204327-d1b0-51af-860f-9debbc5baad6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 17.3.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:b2c10d65-4259-5a0c-9add-1b0037270280",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 17.3.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:b8757af3-c5fa-5105-ae63-6960479ab6e7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 17.3.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:81c3ffd3-b440-55f3-b16f-49c39cc0fd8e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 17.3.12-tuxcare.13 of @angular/service-worker, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:3ef23904-5d35-54aa-8a95-88ae4c131d17",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 17.3.12-tuxcare.13 of @angular/service-worker, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:b43b1b80-260b-5641-9fd8-38e1b4320d1a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 17.3.12-tuxcare.13 of @angular/service-worker, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:0c79cccd-0c74-5cdc-9f87-6452fac0bc63",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.3.12-tuxcare.13 of @angular/service-worker. not_affected \u2014 Version 17.3.12 is not affected by CVE-2026-88056. The vulnerability involves String.prototype.trim() being applied during URL resolution in Angular's platform-server, converting validated same-origin URLs with Unicode whitespace into cross-origin protocol-relative URLs, leading to SSRF. This vulnerable code pattern was introduced in newer Angular versions (v20+) and does not exist in version 1...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:6f0881de-7acd-5c5d-80e6-faf01f1c722d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 17.3.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:c2e02986-841e-5df3-9ebc-4696d6dc5b94",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 17.3.12-tuxcare.13 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.13"
        }
      ],
      "bom-ref": "urn:uuid:7b8a90fb-408c-58b3-bb5b-d959f2feed8c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 17.3.12-tuxcare.13 of @angular/service-worker."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/service-worker@17.3.12-tuxcare.13"
    }
  ]
}