{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b1ce8b10-4448-5606-905b-92662334c4cf",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/service-worker",
      "purl": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.4",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.4",
      "version": "8.2.14-tuxcare.4",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:c049df27-7b31-5ad0-8739-cbb3f918f62c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-4231 affects version 8.2.14-tuxcare.4 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.5."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:d8156294-445d-521e-822a-224f312a1687",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 8.2.14-tuxcare.4 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.10."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:fed4220b-a84c-5e52-b6dd-9e8f4829ba7b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 8.2.14-tuxcare.4 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:5c69beb2-a1b7-59f9-97cd-58ddb505b391",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 8.2.14-tuxcare.4 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:664559df-8cc3-579f-8d58-7bf6e1acd67b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 8.2.14-tuxcare.4 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:396b08e5-d2f2-5b43-95f9-bf826db2877b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 8.2.14-tuxcare.4 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:b01129a9-f81f-5730-beb4-628179e06546",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 8.2.14-tuxcare.4 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:fd676327-b955-56d5-a87f-0d058542ee14",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 8.2.14-tuxcare.4 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:48e828fa-8e87-5f90-8861-3a1cb3f0a253",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 8.2.14-tuxcare.4 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:4099a53b-0b3e-5518-aaee-df2bf136dfc2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 8.2.14-tuxcare.4 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:43bd53ac-109f-5942-a311-b79ee68a44e4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 8.2.14-tuxcare.4 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:15ce662a-0da6-51eb-b21b-5bf0d36cdd44",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 8.2.14-tuxcare.4 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:460532d9-6285-51dc-8e63-2bdcb1d005e7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 8.2.14-tuxcare.4 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:1c1d46d1-725e-5068-96f5-d55728eb4df5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 8.2.14-tuxcare.4 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:197d0ea3-9b48-5279-9e56-74eef9483c04",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 8.2.14-tuxcare.4 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:302d1675-b91f-5490-b25a-2b66f7d795d9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 8.2.14-tuxcare.4 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:d57fef94-d619-5340-89a7-c8978d62e5de",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 8.2.14-tuxcare.4 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:842af269-fdfa-5755-a54a-026d18737c76",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 8.2.14-tuxcare.4 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:ad72d6d1-89f4-5456-ab03-5d90e1c5e9e6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 8.2.14-tuxcare.4 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:38bc2237-eacc-505e-bc52-6ac147d73300",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 8.2.14-tuxcare.4 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:9fd5b37e-03cd-5409-be97-7065e7d3695f",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 8.2.14-tuxcare.4 of @angular/service-worker. not_affected \u2014 Angular 8.2.14 is NOT affected by CVE-2026-68945. The vulnerability exists in HttpTransferCache, a feature that automatically caches HTTP requests during SSR for client hydration. HttpTransferCache was introduced in Angular v16+ and does not exist in version 8.2.14. This version has only a manual TransferState key-value store with no automatic HttpClient integration, and no HTTP caching mechani...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:3f045313-1a6b-5c26-b806-84add65007fd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 8.2.14-tuxcare.4 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:6df1f9e8-68c5-5a7f-8d18-70e877e7f9d9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 8.2.14-tuxcare.4 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:8614a00a-fe97-5ace-aa8c-a65ac7f3cc0c",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 8.2.14-tuxcare.4 of @angular/service-worker. not_affected \u2014 Angular 8.2.14 is NOT AFFECTED by CVE-2026-88056. The vulnerability requires a sophisticated URL resolution utility (`parseUrl` in `packages/platform-server/src/url.ts`) that calls `String.prototype.trim()` to strip Unicode whitespace, creating a discrepancy with WHATWG URL validation. This architecture was introduced in Angular v12+ (circa 2026 as TuxCare backports). Angular 8.2.14 (released N...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:576ecf38-df5d-5c86-aed7-8b37f4eed48e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 8.2.14-tuxcare.4 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:ca4f3b33-90c1-5f5f-b4bf-76d9160d0021",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 8.2.14-tuxcare.4 of @angular/service-worker. not_affected \u2014 Angular v8.2.14 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, provideClientHydration(), and withRequestsMadeViaParent() \u2014 all features that do not exist in this version. These features were introduced in Angular v16 (per patches/CVE-2026-50170.patch and patches/CVE-2026-54266.patch). The target uses the legacy NgModule-based HttpClientModule without automatic ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:623fd160-c2da-51d0-93de-41a2961989cb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 8.2.14-tuxcare.4 of @angular/service-worker."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.4"
    }
  ]
}