{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:84329d55-5736-5d7f-8b4d-9d602ceb8051",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/upgrade",
      "purl": "pkg:npm/%40angular/upgrade@17.3.12-tuxcare.4",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/upgrade@17.3.12-tuxcare.4",
      "version": "17.3.12-tuxcare.4",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:dc97ea61-7774-5bad-afb6-9f720a37c50f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.3.12-tuxcare.4 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:f676e539-210c-5a27-806b-c9a6bd5c4a2e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.3.12-tuxcare.4 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:0a13e26c-0223-5a98-a206-7aa48caac4a5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66412 affects version 17.3.12-tuxcare.4 of @angular/upgrade, and is fixed in 17.3.12-tuxcare.5."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:3026e09c-9139-532c-b6da-f6ab07f2a7f8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22610 affects version 17.3.12-tuxcare.4 of @angular/upgrade, and is fixed in 17.3.12-tuxcare.5."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:5da2d078-124c-5651-a02a-4c9e04786990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 17.3.12-tuxcare.4 of @angular/upgrade, and is fixed in 17.3.12-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:25c58f93-a926-511e-9b1c-d5fb2eda78de",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32635 affects version 17.3.12-tuxcare.4 of @angular/upgrade, and is fixed in 17.3.12-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:71ced514-d96c-5d46-beed-029098d5467c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 17.3.12-tuxcare.4 of @angular/upgrade, and is fixed in 17.3.12-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:d0ab21ff-14d4-5fcd-ba4c-86b8e78e2c4e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 17.3.12-tuxcare.4 of @angular/upgrade, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:c36d155b-06a1-53c2-89d0-d46f2b5d4a33",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 17.3.12-tuxcare.4 of @angular/upgrade, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:0762bd32-535e-5b20-b13f-fcd6900e9f71",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 17.3.12-tuxcare.4 of @angular/upgrade, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:b3c760de-4bfc-5cd5-b960-030661ee6774",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 17.3.12-tuxcare.4 of @angular/upgrade, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:6945ff12-7486-5692-b2c9-c4468766e79b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 17.3.12-tuxcare.4 of @angular/upgrade, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:fca69faf-d08d-5a55-89a9-ff390ff1b5e5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 17.3.12-tuxcare.4 of @angular/upgrade, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:7a279391-cb29-52a2-9240-abd344fb8f24",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 17.3.12-tuxcare.4 of @angular/upgrade, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:6d62de10-d1f7-5f0a-9c64-f02cf76158a2",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 17.3.12-tuxcare.4 of @angular/upgrade, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:3bb9ff5e-73ec-5ca5-b487-4acdf4a0167b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 17.3.12-tuxcare.4 of @angular/upgrade, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:7839b9a4-32bc-5f75-8664-6815beec1e10",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 17.3.12-tuxcare.4 of @angular/upgrade, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:3414692d-9ad8-585a-98ac-961cf6f0d261",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 17.3.12-tuxcare.4 of @angular/upgrade, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:dbe0ed55-54c3-559a-8a7a-aef3ad465985",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 17.3.12-tuxcare.4 of @angular/upgrade, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:ef2b7c08-7e1c-538a-85b4-607363c6294d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 17.3.12-tuxcare.4 of @angular/upgrade, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:496c7c1e-47d2-5091-b9aa-53027bca3ef1",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 17.3.12-tuxcare.4 of @angular/upgrade, and is fixed in 17.3.12-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:f1523333-f1b2-578d-86d8-48abe2d6aa7a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 17.3.12-tuxcare.4 of @angular/upgrade, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:cedd5fdb-c655-5d3b-b4d0-416b10ffd168",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 17.3.12-tuxcare.4 of @angular/upgrade, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:8f0a01b2-49eb-5b3c-aa32-aecd809cf98a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 17.3.12-tuxcare.4 of @angular/upgrade, and is fixed in 17.3.12-tuxcare.14."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:35b70c91-92f7-5ef2-945a-a8687cffef24",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.3.12-tuxcare.4 of @angular/upgrade. not_affected \u2014 Version 17.3.12 is not affected by CVE-2026-88056. The vulnerability involves String.prototype.trim() being applied during URL resolution in Angular's platform-server, converting validated same-origin URLs with Unicode whitespace into cross-origin protocol-relative URLs, leading to SSRF. This vulnerable code pattern was introduced in newer Angular versions (v20+) and does not exist in version 1...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:14e95e15-331a-56da-902f-e8b27f691c84",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 17.3.12-tuxcare.4 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:853e9a81-2537-51a1-9379-4830fb9c1e0b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 17.3.12-tuxcare.4 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@17.3.12-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:cd958b1c-162d-5c3a-945a-6dd06c4288d5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 17.3.12-tuxcare.4 of @angular/upgrade."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/upgrade@17.3.12-tuxcare.4"
    }
  ]
}