{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:687a3834-a5bd-5896-a354-2bfe3bb1f549",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/service-worker",
      "purl": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.2",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.2",
      "version": "8.2.14-tuxcare.2",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3783adce-0dd9-596f-8ea7-dd8747e019df",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-4231 affects version 8.2.14-tuxcare.2 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.5."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:b582001d-5f38-5e34-b776-a6b2136286bb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 8.2.14-tuxcare.2 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.10."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e8bef3e9-7ab1-5fb7-83fd-ccdc7d8bd452",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66412 affects version 8.2.14-tuxcare.2 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:7ea4ded5-34c8-512e-8b19-5768b3583214",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22610 affects version 8.2.14-tuxcare.2 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.3."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:991524d6-2d84-573e-a27c-1c528c02698c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 8.2.14-tuxcare.2 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e263fe00-a204-5939-b617-db517e566d1f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 8.2.14-tuxcare.2 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:35d2b363-9c58-52e4-8004-7da45a559aa5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 8.2.14-tuxcare.2 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:59e3e87b-f3f0-5e71-90b2-0a97e8fb5a10",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 8.2.14-tuxcare.2 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:68a4858e-44eb-50a3-a22d-5eef77f8acd5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 8.2.14-tuxcare.2 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:8f930d0e-f25d-5f2f-9aa7-ba69f4152fed",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 8.2.14-tuxcare.2 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:ecae6784-803c-50e0-9f4e-bd1a93fe4d7d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 8.2.14-tuxcare.2 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:01c3456c-4f5d-58f4-94e3-8c7985b076cc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 8.2.14-tuxcare.2 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1e235a2f-5057-5f6b-b607-1778be293ddc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 8.2.14-tuxcare.2 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:176a9ea8-d45a-558f-b908-affa050a1c36",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 8.2.14-tuxcare.2 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:34c4c340-aeae-5b1b-a890-4232e0a5f489",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 8.2.14-tuxcare.2 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c7dfc64a-00f9-5dbf-adce-c9426a8bb6f0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 8.2.14-tuxcare.2 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:c4d423ea-dff3-5ca4-a263-daac33423f7b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 8.2.14-tuxcare.2 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e5fbe431-5f60-57e4-9809-14d959f89eb3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 8.2.14-tuxcare.2 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:e8570c72-a1d8-559a-b551-68b462316c0b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 8.2.14-tuxcare.2 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3caf7773-fd6e-593f-b184-09aef1ac6bad",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 8.2.14-tuxcare.2 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:0907a17a-a4ea-50b2-8eab-28fafb4c67fd",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 8.2.14-tuxcare.2 of @angular/service-worker. not_affected \u2014 Angular 8.2.14 is NOT affected by CVE-2026-68945. The vulnerability exists in HttpTransferCache, a feature that automatically caches HTTP requests during SSR for client hydration. HttpTransferCache was introduced in Angular v16+ and does not exist in version 8.2.14. This version has only a manual TransferState key-value store with no automatic HttpClient integration, and no HTTP caching mechani...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:3e6e0104-7179-501c-a62e-85d5e3e2b95c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 8.2.14-tuxcare.2 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:92715da9-0fed-5242-a7d9-b84cb3037c53",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 8.2.14-tuxcare.2 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:825219ac-72d1-59d6-9e51-637cdb8fcd43",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 8.2.14-tuxcare.2 of @angular/service-worker. not_affected \u2014 Angular 8.2.14 is NOT AFFECTED by CVE-2026-88056. The vulnerability requires a sophisticated URL resolution utility (`parseUrl` in `packages/platform-server/src/url.ts`) that calls `String.prototype.trim()` to strip Unicode whitespace, creating a discrepancy with WHATWG URL validation. This architecture was introduced in Angular v12+ (circa 2026 as TuxCare backports). Angular 8.2.14 (released N...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:1e8a41eb-ca01-56b1-8131-281f7108155e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 8.2.14-tuxcare.2 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:78ca2726-3290-583f-a337-ef373a286909",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 8.2.14-tuxcare.2 of @angular/service-worker. not_affected \u2014 Angular v8.2.14 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, provideClientHydration(), and withRequestsMadeViaParent() \u2014 all features that do not exist in this version. These features were introduced in Angular v16 (per patches/CVE-2026-50170.patch and patches/CVE-2026-54266.patch). The target uses the legacy NgModule-based HttpClientModule without automatic ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.2"
        }
      ],
      "bom-ref": "urn:uuid:4187f278-e30c-5846-b45c-87bbb8c1a895",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 8.2.14-tuxcare.2 of @angular/service-worker."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.2"
    }
  ]
}