{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d9af69be-e0eb-59be-8405-d27a834cccf9",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/animations",
      "purl": "pkg:npm/%40angular/animations@12.2.17-tuxcare.12",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/animations@12.2.17-tuxcare.12",
      "version": "12.2.17-tuxcare.12",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:cacd70fa-d169-57c7-aab4-24809785ec39",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 12.2.17-tuxcare.12 of @angular/animations."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:9b7c3bf7-69fb-5e1d-a52d-3bd114c45986",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 12.2.17-tuxcare.12 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:b48a27f8-6c42-5a53-bdbd-bd7e9c378834",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-101895 is fixed in version 12.2.17-tuxcare.12 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:e3e99a73-7e57-5f6f-8866-1b831d1f404a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 12.2.17-tuxcare.12 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:12c1cbb2-d6c7-5dd9-b2c6-cc59c133194e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 12.2.17-tuxcare.12 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:447a60f0-f403-5d60-891f-c26503610cf3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 12.2.17-tuxcare.12 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:4494e3de-1f71-5756-8c3f-9c6639794de7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 12.2.17-tuxcare.12 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:41c9e01a-6db0-5496-b6c1-9e2bc08ad40a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 12.2.17-tuxcare.12 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:496bc7ad-7d52-5823-b4b8-9a826d4be5bd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 12.2.17-tuxcare.12 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:1036391a-8509-5952-89ba-bb24fdc39090",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 12.2.17-tuxcare.12 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:154ba3b1-0069-5c4a-9370-b3d0a76f47f9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 12.2.17-tuxcare.12 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:3b6dfbde-a161-5264-9ecd-b8310e4d5016",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 12.2.17-tuxcare.12 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:c3437a8a-98c5-5814-b98c-e5cad85e7ef5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 12.2.17-tuxcare.12 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:fde4cc75-c7ad-59be-8075-6880f8c4fd93",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 12.2.17-tuxcare.12 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:fa2b85a9-760b-5d8f-a870-028022f13c82",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 12.2.17-tuxcare.12 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:832f42e6-2909-5288-993c-6d9aa4c034fc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 12.2.17-tuxcare.12 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:445d5335-26c2-5145-b220-f4e8a605e2b4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 12.2.17-tuxcare.12 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:36e293cd-0ba1-5fc6-8133-59ded4749f14",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 12.2.17-tuxcare.12 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:96e7c3d6-b773-56e3-ac5b-6c693dcb9a8c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 12.2.17-tuxcare.12 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:dccd3aa4-9dde-5e56-bc44-f51c5db8a9ed",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 12.2.17-tuxcare.12 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:314d5344-3c29-565d-8662-ce38bb6744bc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 12.2.17-tuxcare.12 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:d8b2b417-7599-5d68-936d-61cc0427a11e",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 12.2.17-tuxcare.12 of @angular/animations. not_affected \u2014 Angular 12.2.17 does not contain the HttpTransferCache feature affected by CVE-2026-68945. HttpTransferCache, which caches HTTP requests during Server-Side Rendering (SSR), was first introduced in Angular 16.0.0\u2014approximately 4 major versions after the target version. The vulnerability concerns cache-key collision when repeated HTTP parameters are serialized, but since the entire HttpTransferCa...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:322c1a21-a882-5ed0-9e00-b5c1f10c08a0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 12.2.17-tuxcare.12 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:7a7600f6-b1e1-5d89-b1a3-c3250c12f0c7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 12.2.17-tuxcare.12 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:0208959d-3e84-5dd8-b789-ab43ed239414",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88056 is fixed in version 12.2.17-tuxcare.12 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:c886e7ff-5d9e-5799-b8f2-7ada5040f146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 12.2.17-tuxcare.12 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:702df7c3-3381-5b90-bda8-0880c8e066b1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 12.2.17-tuxcare.12 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:cf426c1b-a4d9-5010-8301-6b3f0ab520ac",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 12.2.17-tuxcare.12 of @angular/animations. not_affected \u2014 Angular 12.2.17-tuxcare.9 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, withRequestsMadeViaParent(), and provideClientHydration() features which were introduced in Angular 16.0.0. This version uses the older module-based HttpClientModule system and lacks the entire SSR hydration transfer-cache infrastructure. The vulnerable code pattern described in the CVE do...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:5fcd31d2-9936-5eb8-bff3-98516c814c01",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 12.2.17-tuxcare.12 of @angular/animations."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/animations@12.2.17-tuxcare.12"
    }
  ]
}