{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c7fe399d-69d9-561b-aeb3-0769b208ff44",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/animations",
      "purl": "pkg:npm/%40angular/animations@16.2.11-tuxcare.6",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.6",
      "version": "16.2.11-tuxcare.6",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e88f2a75-6349-5674-9d2f-82a24846bc0d",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59052 affects version 16.2.11-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1588850f-2b60-5657-a44d-72a3e6d46f06",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 16.2.11-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:65142380-a0dc-551e-9eb6-3be171879007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 16.2.11-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:63bf0f5b-5fc6-5925-9cbf-e0de75ec7daf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-101895 is fixed in version 16.2.11-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ea8de47d-1fb6-51c1-8a7a-b473d98a5690",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 16.2.11-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:8133b0e2-d5d1-513d-9a73-97f267bed5ce",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 16.2.11-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:9c62cb3c-8e36-54cd-941f-923fb80b860a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 16.2.11-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1a3ecc29-d836-5559-a04b-bee0ef4abc63",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 16.2.11-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:11661119-f8ba-55b3-87b1-2b2d6ef8fd51",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 16.2.11-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:24196f8a-9fe5-5fad-b3d7-2ce823d4e6b7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 16.2.11-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d7ef7b63-ee6c-5e46-b811-6c2915effe39",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 16.2.11-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:df6bdf96-57ab-55e3-b753-a8b7903fba7b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 16.2.11-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e15e32b6-6841-52c0-a1ca-ebf89e483135",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 16.2.11-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c88d4ad5-ccce-574b-9774-d93d4bd4a5b5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 16.2.11-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:7caed110-9108-5b7b-9c72-f2f7d19e2d6f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 16.2.11-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:167db300-de8f-5bef-92e3-558e1b0aaf8c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 16.2.11-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:0c0326b1-feb9-565d-9f68-e67f14f3e155",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 16.2.11-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:0940bbe0-0699-5152-9829-f5966e6ea7c0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 16.2.11-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:8a919896-1064-56da-80f9-6a7e44526549",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 16.2.11-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:01f2ac16-54f4-55dc-ab3b-3317c71aca5e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 16.2.11-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:01ed58e6-e1dc-58a5-8171-5965ddd093bf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 16.2.11-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:acbd7d93-e9bf-5657-b638-2ea4f15bcd55",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 16.2.11-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:189b57cd-deb8-5357-baac-f7ddf8356e92",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 16.2.11-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:9fb5ecc4-3ac0-5ede-93fd-fbfb7495ed77",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 16.2.11-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:edb6e5d0-25ae-5709-b1bc-31a19b9d8764",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 16.2.11-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:0c1e4978-0504-54d1-b53a-059fe5241a5f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 16.2.11-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:8cedaeb6-1bee-5573-984e-2c739b2dfde0",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 16.2.11-tuxcare.6 of @angular/animations. not_affected \u2014 Angular 16.2.11-tuxcare.2 is NOT affected by CVE-2026-88056. The vulnerability requires WHATWG URL validation combined with String.prototype.trim() on URLs during SSR, creating a discrepancy that enables SSRF. While the target uses WHATWG URL parsing (backported in commit c03fbfd7cc for CVE-2026-50168), it does NOT call String.prototype.trim() on URLs. The attack chain is broken at the trim() s...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:944230d3-cee7-51dd-8d67-01ad8a6da918",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 16.2.11-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d7bb5092-e7b0-568b-9ed7-53389beb7b8a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 16.2.11-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:24b4f1e3-3ce8-5f30-b4a3-8045f4f1ab3a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 16.2.11-tuxcare.6 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:3e8a2bdb-1b3a-5603-aa61-f87a7b8565b7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 16.2.11-tuxcare.6 of @angular/animations."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/animations@16.2.11-tuxcare.6"
    }
  ]
}