{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:efdec15f-b951-552e-812c-513ad29c252e",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/upgrade",
      "purl": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.3",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.3",
      "version": "18.2.14-tuxcare.3",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:8925ba45-cee3-504f-ad8e-0a1518090d6a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.2.14-tuxcare.3 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:f9307dc6-e630-5627-83e3-539a52dc7e4e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 18.2.14-tuxcare.3 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:ffcde086-a125-57b2-8a52-9238bea89c87",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22610 affects version 18.2.14-tuxcare.3 of @angular/upgrade, and is fixed in 18.2.14-tuxcare.4."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:08a5f23a-e0df-59df-9f42-d240fd912b6b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27970 affects version 18.2.14-tuxcare.3 of @angular/upgrade, and is fixed in 18.2.14-tuxcare.7."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:fef55db7-fc7b-574a-b530-15e4c29aaac5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32635 affects version 18.2.14-tuxcare.3 of @angular/upgrade, and is fixed in 18.2.14-tuxcare.5."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:847f61ad-87fa-5639-ba0e-11a3eb827151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-46417 affects version 18.2.14-tuxcare.3 of @angular/upgrade, and is fixed in 18.2.14-tuxcare.10."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:5e49c7e7-f411-5156-bfea-527ec138a483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50168 affects version 18.2.14-tuxcare.3 of @angular/upgrade, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:31752054-a1cf-5bdb-8bd5-b6e2b608a1f0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50169 affects version 18.2.14-tuxcare.3 of @angular/upgrade, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:71ac8d95-cfc7-55ed-ad5d-e517ed5b1ae9",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50170 affects version 18.2.14-tuxcare.3 of @angular/upgrade, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:878497a2-2dee-5c2d-a5bd-3681b6858128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50171 affects version 18.2.14-tuxcare.3 of @angular/upgrade, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:30d334ab-5f63-5dab-9015-07de9630af10",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50184 affects version 18.2.14-tuxcare.3 of @angular/upgrade, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:b52e5111-a181-5929-907a-59a717ec7f43",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50555 affects version 18.2.14-tuxcare.3 of @angular/upgrade, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:971b3939-49d0-529d-a11a-4cc318e2838e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50556 affects version 18.2.14-tuxcare.3 of @angular/upgrade, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:0d8c3adf-8a6e-5f85-9fa5-2720593c1a43",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-50557 affects version 18.2.14-tuxcare.3 of @angular/upgrade, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:89846b9d-0d9a-5f14-add3-9543bbb211aa",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-52725 affects version 18.2.14-tuxcare.3 of @angular/upgrade, and is fixed in 18.2.14-tuxcare.11."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:4891945c-45f1-519c-945e-b095a8ace3ba",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 18.2.14-tuxcare.3 of @angular/upgrade, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:fcd21fe4-77ff-520d-9421-16ca62cad57b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 18.2.14-tuxcare.3 of @angular/upgrade, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:6c3eb947-9da9-5f5e-ad8f-11a774c65d9d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 18.2.14-tuxcare.3 of @angular/upgrade, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:e491d1aa-a8a4-550c-95e0-7545f986ed6d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 18.2.14-tuxcare.3 of @angular/upgrade, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:2856fe83-9cd4-53ea-8525-ffa59529253e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 18.2.14-tuxcare.3 of @angular/upgrade, and is fixed in 18.2.14-tuxcare.12."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:43e1ab6c-52da-574a-96f4-2476497d22ee",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 18.2.14-tuxcare.3 of @angular/upgrade, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:230d26e2-9393-5dcf-95d8-f8e09092a19e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69149 affects version 18.2.14-tuxcare.3 of @angular/upgrade, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:1bccbd59-2cf2-597d-a779-e76255aae5ea",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 18.2.14-tuxcare.3 of @angular/upgrade, and is fixed in 18.2.14-tuxcare.13."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:0947de2a-4c2b-5a0f-b196-c1ab4d6daebd",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 18.2.14-tuxcare.3 of @angular/upgrade. not_affected \u2014 The target version 18.2.14-tuxcare.13 is NOT affected by CVE-2026-88056. The vulnerable code pattern (calling String.prototype.trim() on URL strings before resolution) was never present in this version. The target uses a refactored parseUrl() implementation introduced via commit 49a60f6045 (May 2026) that correctly handles Unicode whitespace by percent-encoding it rather than stripping it, main...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:31ef03e5-c5ec-5c21-a7ee-c8ed2e74a39f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88057 affects version 18.2.14-tuxcare.3 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:b0836123-40c1-5dbf-9421-41580f931552",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 18.2.14-tuxcare.3 of @angular/upgrade."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.3"
        }
      ],
      "bom-ref": "urn:uuid:5c4e5239-e144-5654-b07e-15a5d5a7004c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88060 affects version 18.2.14-tuxcare.3 of @angular/upgrade."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/upgrade@18.2.14-tuxcare.3"
    }
  ]
}