{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d3198069-7069-5ae4-a604-a17a10bc88aa",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/upgrade",
      "purl": "pkg:npm/%40angular/upgrade@12.2.17-tuxcare.4",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/upgrade@12.2.17-tuxcare.4",
      "version": "12.2.17-tuxcare.4",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:61ca05f2-94c5-5624-aed6-6121ae091dc3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 12.2.17-tuxcare.4 of @angular/upgrade, and is fixed in 12.2.17-tuxcare.8."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:82ba32e9-c24a-5f27-824f-251258c423f5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 12.2.17-tuxcare.4 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:3a770248-69e0-5a16-9744-e8f0aeabf477",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 12.2.17-tuxcare.4 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:6638a8e1-427b-5bae-851f-337b55545ad7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 12.2.17-tuxcare.4 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:968562c8-25a6-5b9e-9b4b-181002b64e3a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 12.2.17-tuxcare.4 of @angular/upgrade, and is fixed in 12.2.17-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:66de3ae4-2174-5d73-b6c0-0d2776572443",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 12.2.17-tuxcare.4 of @angular/upgrade, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:2e132afa-eda0-5f21-ac6d-63705799a134",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 12.2.17-tuxcare.4 of @angular/upgrade, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:abce63b5-12aa-54c4-8d64-58ed995e4827",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 12.2.17-tuxcare.4 of @angular/upgrade, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:9b62d621-50d8-55f3-b56a-e8aa4978af55",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 12.2.17-tuxcare.4 of @angular/upgrade, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:0c0dcb7b-eb00-5ff7-95e1-4d240c103eaa",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 12.2.17-tuxcare.4 of @angular/upgrade, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:98325eba-3146-503e-abc8-44960d67fb6e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 12.2.17-tuxcare.4 of @angular/upgrade, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:48d8814a-31aa-5c48-aed7-5407a50fd4f8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 12.2.17-tuxcare.4 of @angular/upgrade, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:c60c9922-5ff2-5685-b05c-81e6a1893733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 12.2.17-tuxcare.4 of @angular/upgrade, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:8a6d6f4e-e68f-55b2-9fef-df7f7ab8ab90",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 12.2.17-tuxcare.4 of @angular/upgrade, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:49047500-cb9a-511b-888c-6ad0c108cdc8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 12.2.17-tuxcare.4 of @angular/upgrade, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:2288f9a1-65e4-50b2-b792-1746789612e8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 12.2.17-tuxcare.4 of @angular/upgrade, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:4b33b4b5-873d-5627-960a-955054d454ba",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 12.2.17-tuxcare.4 of @angular/upgrade, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:048b15a3-d1c9-5028-b30a-d91e9b425c4e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 12.2.17-tuxcare.4 of @angular/upgrade, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:9e8f226c-c86c-5653-bd9f-b8a0eb7ba8e5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 12.2.17-tuxcare.4 of @angular/upgrade, and is fixed in 12.2.17-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:cc32f128-2ec6-55bb-86ad-873594d04f54",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 12.2.17-tuxcare.4 of @angular/upgrade. not_affected \u2014 Angular 12.2.17 does not contain the HttpTransferCache feature affected by CVE-2026-68945. HttpTransferCache, which caches HTTP requests during Server-Side Rendering (SSR), was first introduced in Angular 16.0.0\u2014approximately 4 major versions after the target version. The vulnerability concerns cache-key collision when repeated HTTP parameters are serialized, but since the entire HttpTransferCa...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:1737a522-4ee1-5c97-bbe6-537fa48a9f36",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 12.2.17-tuxcare.4 of @angular/upgrade, and is fixed in 12.2.17-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:efee8fa4-f382-597f-87d7-98b3f08797ab",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 12.2.17-tuxcare.4 of @angular/upgrade, and is fixed in 12.2.17-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:049f3606-eb6d-5b2d-a0a9-878effffe8e5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88056 affects version 12.2.17-tuxcare.4 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:0d5c84c2-d3c3-5f6f-ab5c-d87858c464cf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 12.2.17-tuxcare.4 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:9ac95b84-b7c2-59ac-9f49-d0e6bcf0f2c8",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 12.2.17-tuxcare.4 of @angular/upgrade. not_affected \u2014 Angular 12.2.17-tuxcare.9 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, withRequestsMadeViaParent(), and provideClientHydration() features which were introduced in Angular 16.0.0. This version uses the older module-based HttpClientModule system and lacks the entire SSR hydration transfer-cache infrastructure. The vulnerable code pattern described in the CVE do...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@12.2.17-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:fe9f00a9-b5eb-54f7-a095-d1939467b01d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 12.2.17-tuxcare.4 of @angular/upgrade."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/upgrade@12.2.17-tuxcare.4"
    }
  ]
}