{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:dbc949ea-7c25-52c3-a6e6-f254395234f7",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/service-worker",
      "purl": "pkg:npm/%40angular/service-worker@18.2.14-tuxcare.7",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/service-worker@18.2.14-tuxcare.7",
      "version": "18.2.14-tuxcare.7",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:16979991-6351-58ce-951e-68d00373cc1e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.2.14-tuxcare.7 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:7e3bb45d-a1fd-5936-8626-ee1f4d030236",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 18.2.14-tuxcare.7 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:a3719b31-b679-562e-92f7-4e7ac3e08dfd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 18.2.14-tuxcare.7 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:34673b8e-48a7-5d4c-84db-76f705dbe548",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 18.2.14-tuxcare.7 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:3199ef3c-12ca-54a1-ae26-6ef4107e9db3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 18.2.14-tuxcare.7 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:a3649857-4277-5e80-a381-57fa7b3fa186",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 18.2.14-tuxcare.7 of @angular/service-worker, and is fixed in 18.2.14-tuxcare.10."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:088b066a-9123-5951-9576-7be84b6e0961",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 18.2.14-tuxcare.7 of @angular/service-worker, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:7e880294-c54f-5e9d-a73b-57ab627e3502",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 18.2.14-tuxcare.7 of @angular/service-worker, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:85f07a69-b8b9-5f49-bcf4-fe4718a1e453",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 18.2.14-tuxcare.7 of @angular/service-worker, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:feb9f567-b95f-5e44-a855-6df57e5fe3b4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 18.2.14-tuxcare.7 of @angular/service-worker, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:04cc6d20-a235-5588-9858-2262530cf8c9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 18.2.14-tuxcare.7 of @angular/service-worker, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:dd70594c-758b-5325-a30b-41696c85f53c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 18.2.14-tuxcare.7 of @angular/service-worker, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:e5a0c9f1-c40c-5e99-9c5f-6c04d354af30",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 18.2.14-tuxcare.7 of @angular/service-worker, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:df9e2999-5839-54d1-b0ed-6bb417c8aaa6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 18.2.14-tuxcare.7 of @angular/service-worker, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:6e961be2-7cf3-5c17-9454-06df199cd0b6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 18.2.14-tuxcare.7 of @angular/service-worker, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:7374bd1b-c345-5f3a-bc6d-c3766bd19028",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 18.2.14-tuxcare.7 of @angular/service-worker, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:0d818016-6ae9-5caa-9e5e-dd117c8766ef",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 18.2.14-tuxcare.7 of @angular/service-worker, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:8cad174f-1dc8-5830-8267-d054feee408c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 18.2.14-tuxcare.7 of @angular/service-worker, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:00280176-4d93-5d52-9d7c-22c3587bedd8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 18.2.14-tuxcare.7 of @angular/service-worker, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:43702362-0f4b-5034-87e9-3178dcdc0a04",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 18.2.14-tuxcare.7 of @angular/service-worker, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:ff5f3006-b1b3-5162-afb9-a9a1db17f9be",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 18.2.14-tuxcare.7 of @angular/service-worker, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:6a2be29f-d66f-511d-9be1-1172c8126f2a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 18.2.14-tuxcare.7 of @angular/service-worker, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:74418246-1a96-5b34-a648-868edeca62fe",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 18.2.14-tuxcare.7 of @angular/service-worker, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:edccc752-2837-500b-8380-274c070f60d3",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 18.2.14-tuxcare.7 of @angular/service-worker. not_affected \u2014 The target version 18.2.14-tuxcare.13 is NOT affected by CVE-2026-88056. The vulnerable code pattern (calling String.prototype.trim() on URL strings before resolution) was never present in this version. The target uses a refactored parseUrl() implementation introduced via commit 49a60f6045 (May 2026) that correctly handles Unicode whitespace by percent-encoding it rather than stripping it, main...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:c9fd6b2c-13f0-55ba-a87f-9ac2ac4b20cb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 18.2.14-tuxcare.7 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:db8b0b2b-be6b-5c1c-beb3-c510f8807afc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 18.2.14-tuxcare.7 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@18.2.14-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:f2bd1e0d-7b52-52b2-a15e-aa19b625b710",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 18.2.14-tuxcare.7 of @angular/service-worker."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/service-worker@18.2.14-tuxcare.7"
    }
  ]
}