{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e3682846-38f9-5f0c-9e1d-52ec396ac81c",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/animations",
      "purl": "pkg:npm/%40angular/animations@16.2.11-tuxcare.5",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.5",
      "version": "16.2.11-tuxcare.5",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:cf0ac6cb-8b9c-5eff-bff6-fdc69ed1f11c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59052 affects version 16.2.11-tuxcare.5 of @angular/animations."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:77f0e55d-6adf-59c0-9374-7fad4ae9e2e9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 16.2.11-tuxcare.5 of @angular/animations."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f125c8e5-0241-59b4-bff8-13eb218870b8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 16.2.11-tuxcare.5 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f7b111c9-d418-5d2c-bd42-9d78e29997ad",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101895 affects version 16.2.11-tuxcare.5 of @angular/animations, and is fixed in 16.2.11-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:16576b34-d0aa-5c25-b46b-644f6a1fd265",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 16.2.11-tuxcare.5 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:633e4983-50f7-5a46-b2c3-5e901e8bca67",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 16.2.11-tuxcare.5 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:db34dcf2-14b9-5e30-9592-68c0444c5c40",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 16.2.11-tuxcare.5 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:af7d9537-8ed3-54ca-a4a8-ca49626a3ae1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 16.2.11-tuxcare.5 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b9745d23-6163-5729-9783-ed23bde642e9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 16.2.11-tuxcare.5 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:101d6328-90ae-5edd-bd3f-5a799e8db467",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 16.2.11-tuxcare.5 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d7b227a0-b25b-5d71-94e5-73aa8ddaa892",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 16.2.11-tuxcare.5 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0ec9bb7d-e144-5f64-9bba-b0524212c386",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 16.2.11-tuxcare.5 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:bbbc9fd0-fa0b-5106-bb63-6db735cf87f4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 16.2.11-tuxcare.5 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:782f2772-67bf-5541-adb9-34cc2d737cb5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 16.2.11-tuxcare.5 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:217d7213-6875-5f62-b5b4-427e6a56bc26",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 16.2.11-tuxcare.5 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e96459ce-fe0b-5130-9ce2-1a85cc7d6bda",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 16.2.11-tuxcare.5 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9ea004e4-28fe-5ed7-8d28-56b85ee93dae",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 16.2.11-tuxcare.5 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:97405878-70db-5690-acc4-7c8fb0158419",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 16.2.11-tuxcare.5 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:78933d30-0cd4-5b47-8e1c-4845abdbad48",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 16.2.11-tuxcare.5 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:02692735-4d44-5e6d-955c-97c4dcf7ca1f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 16.2.11-tuxcare.5 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f7106fa3-5be6-5c1e-af07-7173e4087b05",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 16.2.11-tuxcare.5 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d5096239-3e1a-5415-9b00-e74460da0b89",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 16.2.11-tuxcare.5 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b60c16b5-4951-5062-93ef-4054c816b5be",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 16.2.11-tuxcare.5 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7672075f-7e79-55c0-8069-2e3222d2643a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 16.2.11-tuxcare.5 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f0af6089-2bc1-5b95-ac90-a58e9e306c82",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 16.2.11-tuxcare.5 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3332ed5b-68e0-5ed7-9a52-8b71ee43b1d6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 16.2.11-tuxcare.5 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:897d4581-eb08-52fc-a27d-d316a23f2234",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 16.2.11-tuxcare.5 of @angular/animations. not_affected \u2014 Angular 16.2.11-tuxcare.2 is NOT affected by CVE-2026-88056. The vulnerability requires WHATWG URL validation combined with String.prototype.trim() on URLs during SSR, creating a discrepancy that enables SSRF. While the target uses WHATWG URL parsing (backported in commit c03fbfd7cc for CVE-2026-50168), it does NOT call String.prototype.trim() on URLs. The attack chain is broken at the trim() s...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:10bfbaf1-fba4-567b-a526-2375cd2ed535",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 16.2.11-tuxcare.5 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c4485c3d-165a-575c-a4d7-87d0776b6571",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 16.2.11-tuxcare.5 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:06dc38e0-9a41-589c-b4a5-8ae2ae651d76",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 16.2.11-tuxcare.5 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:6a85fcce-a116-5c4b-bf93-f0615d699df9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 16.2.11-tuxcare.5 of @angular/animations."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.5"
    }
  ]
}