{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4fc71fbe-d628-512c-9c7f-aa5494704edf",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/upgrade",
      "purl": "pkg:npm/%40angular/upgrade@16.2.12-tuxcare.1",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/upgrade@16.2.12-tuxcare.1",
      "version": "16.2.12-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@16.2.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:579f1d92-8c06-5fc4-8c6b-baef5bc1ab76",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59052 affects version 16.2.12-tuxcare.1 of @angular/upgrade, and is fixed in 16.2.12-tuxcare.2."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@16.2.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b13ae690-e4dc-5188-84ca-4d5968115ce9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66035 affects version 16.2.12-tuxcare.1 of @angular/upgrade, and is fixed in 16.2.12-tuxcare.2."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@16.2.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f28eb591-a75e-5578-97a8-db8e0127921f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66412 affects version 16.2.12-tuxcare.1 of @angular/upgrade, and is fixed in 16.2.12-tuxcare.5."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@16.2.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:751fe276-a518-5389-b8c1-a06b7fe0114c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22610 affects version 16.2.12-tuxcare.1 of @angular/upgrade, and is fixed in 16.2.12-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@16.2.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:cf4919b9-3ad1-52bd-86b1-4e44abad6770",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 16.2.12-tuxcare.1 of @angular/upgrade, and is fixed in 16.2.12-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@16.2.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:599f3df0-9962-5a51-9f5b-586f0784bb81",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 16.2.12-tuxcare.1 of @angular/upgrade, and is fixed in 16.2.12-tuxcare.10."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@16.2.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1e071e3e-61c1-5a51-9739-f0d549706191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 16.2.12-tuxcare.1 of @angular/upgrade, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@16.2.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:02d42351-d243-534c-9263-7c193231e802",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 16.2.12-tuxcare.1 of @angular/upgrade, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@16.2.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3310bc13-b155-5900-bdfb-1e886ead7352",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 16.2.12-tuxcare.1 of @angular/upgrade, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@16.2.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8252d4f0-cfcb-5f80-b416-14b69f0b4bf6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 16.2.12-tuxcare.1 of @angular/upgrade, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@16.2.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:56ca34e2-6461-5cd8-a584-02f1c94e2177",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 16.2.12-tuxcare.1 of @angular/upgrade, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@16.2.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:40173066-ed43-5c27-b93d-8abed90b58e4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 16.2.12-tuxcare.1 of @angular/upgrade, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@16.2.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:71ca1bd0-0631-5b84-9e2d-bf91ab751962",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 16.2.12-tuxcare.1 of @angular/upgrade, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@16.2.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:16444750-bb36-5a33-a233-fbea7c71e66b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 16.2.12-tuxcare.1 of @angular/upgrade, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@16.2.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fbc4d344-e46f-5275-a9bb-174750e07a7a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 16.2.12-tuxcare.1 of @angular/upgrade, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@16.2.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:ee7bf7a5-be47-534b-8a71-898306f8872e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 16.2.12-tuxcare.1 of @angular/upgrade, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@16.2.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:6d13bf49-8605-5038-840d-3ae33a60fd37",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 16.2.12-tuxcare.1 of @angular/upgrade, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@16.2.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7b35962e-1cf1-55ac-92c3-ac07461a610e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 16.2.12-tuxcare.1 of @angular/upgrade, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@16.2.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:db0f7de4-20ca-5ae1-be14-9c66085af736",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 16.2.12-tuxcare.1 of @angular/upgrade, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@16.2.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:615a364e-8245-551c-8129-730ba245c7c2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 16.2.12-tuxcare.1 of @angular/upgrade, and is fixed in 16.2.12-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@16.2.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f7df1383-ca84-5b1c-b798-e568baedb323",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 16.2.12-tuxcare.1 of @angular/upgrade, and is fixed in 16.2.12-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@16.2.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f5b40a57-4528-5979-9989-e2c08079fb24",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 16.2.12-tuxcare.1 of @angular/upgrade, and is fixed in 16.2.12-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@16.2.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b03a6618-eb45-57f3-b73a-8b6753bcbed6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 16.2.12-tuxcare.1 of @angular/upgrade, and is fixed in 16.2.12-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@16.2.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e6d263e8-d9c8-5278-9f29-d1668f4a5110",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 16.2.12-tuxcare.1 of @angular/upgrade. not_affected \u2014 CVE-2026-88056 affects Angular versions 20.3.x, 21.2.x, and 22.x where a refactored URL parsing utility added String.prototype.trim() that strips Unicode whitespace, enabling SSRF bypasses. The target (Angular 16.2.12-tuxcare.12) is based on Angular 16.2.x architecture, which predates the vulnerable code pattern entirely. TuxCare created url.ts fresh on June 24, 2026 for CVE-2026-50168, modelin...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@16.2.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0f9e4b06-2516-5cd1-bd13-22395ca17467",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 16.2.12-tuxcare.1 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@16.2.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e5f7b6af-4093-5d33-9aa7-cc97cf91f377",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 16.2.12-tuxcare.1 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@16.2.12-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:62c83dad-7aef-504e-acee-a657c6a6c982",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 16.2.12-tuxcare.1 of @angular/upgrade."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/upgrade@16.2.12-tuxcare.1"
    }
  ]
}