{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:59093c82-dd6f-5d8c-a3dd-01b571b45a5e",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/service-worker",
      "purl": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.5",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.5",
      "version": "8.2.14-tuxcare.5",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e9fc3fa3-c218-5fea-8fa6-5b8336d29bc0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 8.2.14-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:6cdb4d95-3308-558c-af1e-a4f677ba6e69",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 8.2.14-tuxcare.5 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.10."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5642bf44-c9db-5572-80ac-7cef13c24cf4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 8.2.14-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:df2dac52-4939-569d-878e-f4d3cd0e3718",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 8.2.14-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7624eab7-2f2f-5614-ac0b-c39ade27e05a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 8.2.14-tuxcare.5 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:312b3b5a-559c-5048-881a-844bbfcb2b69",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 8.2.14-tuxcare.5 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a016c074-7471-5e80-a468-fdccf76ed509",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 8.2.14-tuxcare.5 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0b993179-0462-5e7e-9a80-dcc772f3883c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 8.2.14-tuxcare.5 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ceaf54ea-5086-55c7-aee7-772ae0b7a21e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 8.2.14-tuxcare.5 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4d2a6169-7943-5e9e-b3d9-a2c883b732b8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 8.2.14-tuxcare.5 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e52f8382-dfa1-503e-8e83-652a21daeef1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 8.2.14-tuxcare.5 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:310f1008-9dd1-57c0-b399-44aef46ed550",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 8.2.14-tuxcare.5 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:04cacd61-6d9a-5583-86b7-d509f5651993",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 8.2.14-tuxcare.5 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8b7db823-3800-588b-b68f-061d2ade34d4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 8.2.14-tuxcare.5 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:79c1f79c-1282-55e3-93b2-a4cd9c34815c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 8.2.14-tuxcare.5 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7bf4084f-41c6-5d7a-960a-628826bc4972",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 8.2.14-tuxcare.5 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:71c19efc-c242-5bff-8967-8f48f12f5527",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 8.2.14-tuxcare.5 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8400de5d-0a9b-5177-bc45-e31b7e2e4de7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 8.2.14-tuxcare.5 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0e9a1101-da3a-5c53-9c0b-08f63d6d61ac",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 8.2.14-tuxcare.5 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9229a374-cbe6-5136-8165-f0a1fba03ad2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 8.2.14-tuxcare.5 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:22c4c2c2-9d32-52ab-8b28-5e3c209f4015",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 8.2.14-tuxcare.5 of @angular/service-worker. not_affected \u2014 Angular 8.2.14 is NOT affected by CVE-2026-68945. The vulnerability exists in HttpTransferCache, a feature that automatically caches HTTP requests during SSR for client hydration. HttpTransferCache was introduced in Angular v16+ and does not exist in version 8.2.14. This version has only a manual TransferState key-value store with no automatic HttpClient integration, and no HTTP caching mechani...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:da660b45-2c50-5bf7-968e-64183a10caf9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 8.2.14-tuxcare.5 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ceb00b56-afc0-5d61-b0b3-69b8fcc3db20",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 8.2.14-tuxcare.5 of @angular/service-worker, and is fixed in 8.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:64df6b54-962f-5cd7-a7b2-19c1118120c3",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 8.2.14-tuxcare.5 of @angular/service-worker. not_affected \u2014 Angular 8.2.14 is NOT AFFECTED by CVE-2026-88056. The vulnerability requires a sophisticated URL resolution utility (`parseUrl` in `packages/platform-server/src/url.ts`) that calls `String.prototype.trim()` to strip Unicode whitespace, creating a discrepancy with WHATWG URL validation. This architecture was introduced in Angular v12+ (circa 2026 as TuxCare backports). Angular 8.2.14 (released N...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b2e5dcd0-6d05-51be-a22b-d56847cfa14b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 8.2.14-tuxcare.5 of @angular/service-worker."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5c10a83f-e466-5f67-9636-1e77579bae0e",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 8.2.14-tuxcare.5 of @angular/service-worker. not_affected \u2014 Angular v8.2.14 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, provideClientHydration(), and withRequestsMadeViaParent() \u2014 all features that do not exist in this version. These features were introduced in Angular v16 (per patches/CVE-2026-50170.patch and patches/CVE-2026-54266.patch). The target uses the legacy NgModule-based HttpClientModule without automatic ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:aad5f91f-f718-507b-b9a3-35ee64c6b5ae",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 8.2.14-tuxcare.5 of @angular/service-worker."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/service-worker@8.2.14-tuxcare.5"
    }
  ]
}