{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:0bfbb3c9-a333-51fa-9704-0ceb1cb453a9",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/animations",
      "purl": "pkg:npm/%40angular/animations@17.1.0-tuxcare.7",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.7",
      "version": "17.1.0-tuxcare.7",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:f324b6f7-6a95-5c16-99c1-195bbe9357ac",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.1.0-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:ef79d7a4-a082-5757-8a0a-79ef361542f4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.1.0-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:f76f8b4e-8aff-51c6-891c-40a621ddbfc9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.1.0-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:40fda50d-fa47-50f0-ae21-5921b0b28b63",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101895 affects version 17.1.0-tuxcare.7 of @angular/animations, and is fixed in 17.1.0-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:d0217db4-c8bf-5e21-9731-bae2da789650",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 17.1.0-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:af48a3ac-c09e-5769-848a-18ef5f0775c2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.1.0-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:8a9fe39f-46ee-54db-b3a4-ef71d1b5cfad",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.1.0-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:58619890-3c0a-562c-b832-62e8e5c4ca50",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.1.0-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:0a423e5c-8635-52b0-9927-c89949938143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 17.1.0-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:9d308d35-5992-5f7a-a38d-8eb6b274b134",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 17.1.0-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:a221869f-af56-56dd-a0bf-3368d580b9cf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 17.1.0-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:b60a2944-a0ec-50d8-96e3-6160a10c79ef",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 17.1.0-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:cc801a47-fb3d-53d6-bf46-45858246d3fd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 17.1.0-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:d050a0f0-1c7e-5c43-a20e-62b8a7c2b471",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 17.1.0-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:997e5ac6-d382-5663-96d4-6654a9f28a65",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 17.1.0-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:feb85d22-3439-5d8a-93e7-7a599b19ac62",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 17.1.0-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:83483ed7-494f-5d92-b3cf-4971ba4475ae",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 17.1.0-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:18b55813-ecd8-578c-bce9-7d6b3b6f9ccb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 17.1.0-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:cba9a175-b1e3-5b80-a6f7-56c1210a37b8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 17.1.0-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:13c986ae-6ff9-54eb-ad6e-ffd74d7ecfe9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 17.1.0-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:7f03a84e-e0cc-51ae-8013-f7eff454c92a",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 17.1.0-tuxcare.7 of @angular/animations. not_affected \u2014 Angular v17.1.0 does not have the TwoWayProperty IR operation that is the subject of CVE-2026-54265. Two-way bindings are desugared into separate property and event bindings before template pipeline processing, with the property half using the same parsePropertyBinding() code path as one-way property bindings, which are properly sanitized.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:1f2b793c-762a-574d-9c4e-4cf50d052224",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 17.1.0-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:f91062e1-9d56-515c-9816-1a7adfa28864",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 17.1.0-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:d3ac67bb-f2e5-51f1-8d32-0d363b576c4f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 17.1.0-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:56b5fd5a-7a0a-5a5b-aa79-1918b8d6726b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 17.1.0-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:38d14239-81f5-5231-b23f-7286bb6fee7c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 17.1.0-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:4a71ffa2-d9d3-5b61-9d3b-81b0f207bed8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 17.1.0-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:70286031-f1f3-5d62-8457-62089809f0c4",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.1.0-tuxcare.7 of @angular/animations. not_affected \u2014 Angular 17.1.0 was never vulnerable to CVE-2026-88056. The vulnerability exists only in newer Angular versions (v18+, v19+, v20+ before fixes) where a url.ts file with a parseUrl function that uses String.prototype.trim() was introduced. Angular 17.1.0 does not have this file in the upstream release. TuxCare created url.ts for their 17.1.0 fork (commit e06d36f339 by ejarocki@cloudlinux.com) but...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:f20c845e-c3c7-5b7c-a277-d3290ba7cf49",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 17.1.0-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:3ca47804-f049-57ab-b0ac-f50b9c20d18d",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88058 does not affect version 17.1.0-tuxcare.7 of @angular/animations. not_affected \u2014 The Angular repository (version 17.1.0-tuxcare.5 at SHA 1b802ce320) is not affected by CVE-2026-88058 because it does not contain the vulnerable source code. The vulnerability exists in the domino library's HTML serialization code (lib/NodeUtils.js), which Angular references as a dependency in package.json but does not vendor. The upstream patch (89b20568dfaee1ec8e0b3bcf1872acdddd2f4fef) is a D...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:cc2906cb-8489-576e-a17f-c0664205dd4a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 17.1.0-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:7b5e960c-e14a-5b5f-8bf4-2227538f74f7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 17.1.0-tuxcare.7 of @angular/animations."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/animations@17.1.0-tuxcare.7"
    }
  ]
}