{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a9f8199a-6ec7-5730-8bbf-d538a272d53a",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/upgrade",
      "purl": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.10",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.10",
      "version": "18.2.14-tuxcare.10",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:a9d32724-4c87-5247-a733-852c2d2be2b9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.2.14-tuxcare.10 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:01d690bd-953a-5ad0-8c0a-1c14c938885d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 18.2.14-tuxcare.10 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:6332a110-cfdd-5d28-8e25-35c518df1743",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 18.2.14-tuxcare.10 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:88df38fc-324d-5399-8ce7-babc5fafacbb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 18.2.14-tuxcare.10 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:eca98b56-6cfc-5fd7-8617-b17130241be1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 18.2.14-tuxcare.10 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:33983cd9-a374-52b9-972f-f397b51f22c2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 18.2.14-tuxcare.10 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:2d562269-9d5a-5b79-b4ee-1acd481940ca",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 18.2.14-tuxcare.10 of @angular/upgrade, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:59339052-d203-5cd7-b2d4-e4864f8bf32e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 18.2.14-tuxcare.10 of @angular/upgrade, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:5919fe8e-01e2-57b2-99b6-3e011b4492f7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 18.2.14-tuxcare.10 of @angular/upgrade, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:a369d58e-fa4a-5a53-bb5a-5d6cc02b524a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 18.2.14-tuxcare.10 of @angular/upgrade, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:4b2c9d3e-32e1-5db6-bab4-2624932d8d23",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 18.2.14-tuxcare.10 of @angular/upgrade, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:6b5c274c-6329-533a-8660-da1d535efc9f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 18.2.14-tuxcare.10 of @angular/upgrade, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:0f0903bd-2d66-55bb-9860-898f86e92418",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 18.2.14-tuxcare.10 of @angular/upgrade, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:27b4afcd-19b4-5590-95eb-c86cfdcdf795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 18.2.14-tuxcare.10 of @angular/upgrade, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:d8cb5d1a-2f81-51da-a20c-83a6f11f1d66",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 18.2.14-tuxcare.10 of @angular/upgrade, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:de896308-251f-5fe6-9a1d-fc8115d41cac",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 18.2.14-tuxcare.10 of @angular/upgrade, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:c53be2a4-594d-5140-b0d9-3bb5d92da4d7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 18.2.14-tuxcare.10 of @angular/upgrade, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:e586a3b5-0ed6-578d-9a05-d09c59ecc9c5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 18.2.14-tuxcare.10 of @angular/upgrade, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:8614b0dd-c3b2-5676-9a33-e7e77a732a6d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 18.2.14-tuxcare.10 of @angular/upgrade, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:8090768f-a806-5316-b72a-3eb9f4c4b7c4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 18.2.14-tuxcare.10 of @angular/upgrade, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:339fb623-94d2-53ef-a9f9-84abfd14107d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 18.2.14-tuxcare.10 of @angular/upgrade, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:08f26517-bc52-59a3-bc71-96d057c9e217",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 18.2.14-tuxcare.10 of @angular/upgrade, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:b5d066ab-fc60-5388-b08e-b48d932d6efd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 18.2.14-tuxcare.10 of @angular/upgrade, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:d452d4cf-fef0-5d16-b681-85551ce16805",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 18.2.14-tuxcare.10 of @angular/upgrade. not_affected \u2014 The target version 18.2.14-tuxcare.13 is NOT affected by CVE-2026-88056. The vulnerable code pattern (calling String.prototype.trim() on URL strings before resolution) was never present in this version. The target uses a refactored parseUrl() implementation introduced via commit 49a60f6045 (May 2026) that correctly handles Unicode whitespace by percent-encoding it rather than stripping it, main...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:080e5c77-1dbb-52e6-ba06-89b55ad0d8c9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 18.2.14-tuxcare.10 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:7e2d367b-f548-56ff-8984-a579b0cf8022",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 18.2.14-tuxcare.10 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.10"
        }
      ],
      "bom-ref": "urn:uuid:9fe04773-dd60-5903-b8b0-8ab81f0957d9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 18.2.14-tuxcare.10 of @angular/upgrade."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.10"
    }
  ]
}