{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f5686390-2463-5f6a-be03-606c5562f7c5",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/animations",
      "purl": "pkg:npm/%40angular/animations@18.1.2-tuxcare.7",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/animations@18.1.2-tuxcare.7",
      "version": "18.1.2-tuxcare.7",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:5951c5b2-d1fc-5a0e-93ac-5b060b4cb205",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59052 affects version 18.1.2-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:d2164bbb-5b84-5d0f-a1ba-95eddd68b280",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.1.2-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:1968b858-a792-5101-8d14-51cf4bb1e15a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 18.1.2-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:d517004b-bf9f-5c83-9a3c-6bb18095144f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101895 affects version 18.1.2-tuxcare.7 of @angular/animations, and is fixed in 18.1.2-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:48a77db3-c591-5529-8dc0-f3c6df67b088",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 18.1.2-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:da0ddcee-6a1d-5909-bce4-70d5622cabc3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 18.1.2-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:90d4805e-aef3-5443-bb9f-edbd639d6fe4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 18.1.2-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:9422539f-9e03-5d7c-94c9-0912325a983e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 18.1.2-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:0ea66604-e4ac-5252-be2e-e4d032546348",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 18.1.2-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:204bc84a-b3ec-5305-8e0d-edf0b3fdc156",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 18.1.2-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:d87d6fc4-90bf-5754-9786-bd05fb1b7ac2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 18.1.2-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:606b37be-345d-530b-94e9-cddf47a6d04c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 18.1.2-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:d77c1f09-d6af-54cc-a3c4-1357b9caceee",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 18.1.2-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:42c7c29c-fbe4-5e59-b7c7-0fce63f0afb1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 18.1.2-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:b98f56fe-4ed2-5cfd-812a-07aeb73fff69",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 18.1.2-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:8f6c8d12-0015-5596-8c69-1b974387f174",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50555 does not affect version 18.1.2-tuxcare.7 of @angular/animations. already_fixed \u2014 The target Angular 18.1.2 repository has already been patched for this vulnerability. TuxCare commit 32991dd728 'fix all CVEs' added a cumulative domino patch that fixes both the NOSCRIPT XSS vulnerability (CVE-2026-50556, corresponding to the provided patch f74cccd) and the astral Unicode index bug (CVE-2026-50555). The patch is applied automatically to the domino dependency via patch-package ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:07e8ea9b-ed91-5d6e-9de4-680579402995",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50556 does not affect version 18.1.2-tuxcare.7 of @angular/animations. already_fixed \u2014 CVE-2026-50556 (XSS via noscript raw-text serialization in domino) has been fixed in this Angular repository. The fix is present in tools/esm-interop/patches/npm/domino+2.1.6.patch and is automatically applied to the domino dependency during installation via the postinstall script. The patch was added by TuxCare in commit 32991dd728 on 2026-07-01.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:6dfcb02d-8b17-5c28-9e62-8b95bc005032",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 18.1.2-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:7886f014-1e88-57fd-9686-ed87e6174857",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 18.1.2-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:cc35689b-5d4b-5ab4-8395-7ade4f31b30e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 18.1.2-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:9d368862-c6f0-5ea8-ba0a-34e0fc24f48d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 18.1.2-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:e0d2d4a8-6439-5332-8ed2-984e94be4785",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 18.1.2-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:0ce4ff41-7d25-593c-a8b2-d34f6da7302e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 18.1.2-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:abfb7291-ca5a-5672-bf33-de26ea3b112d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 18.1.2-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:5187450a-22dc-5223-8f69-bfb655459476",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 18.1.2-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:15cc9bb5-962e-5552-a424-bb0767eb890b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 18.1.2-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:4064d163-ae4e-59d4-9ca1-8e539f8881c1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 18.1.2-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:f65173b3-d6c3-5189-950f-11970cf427d5",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 18.1.2-tuxcare.7 of @angular/animations. not_affected \u2014 The target version (Angular 18.1.2) does NOT contain the vulnerable code pattern. CVE-2026-88056 describes a Unicode whitespace trimming vulnerability in Angular SSR's URL resolution, where `String.prototype.trim()` strips characters like U+00A0, converting same-origin paths into protocol-relative cross-origin URLs. The vulnerability was introduced in Angular v20.x during a refactoring (commit ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:b842c639-106d-5136-bae9-70179e8ac7ea",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 18.1.2-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:233143ce-e746-546c-93f7-1de7a804db76",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 18.1.2-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:ae87035e-870b-50ce-b6c8-eb030384fba2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 18.1.2-tuxcare.7 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@18.1.2-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:51502850-c392-58be-8b19-7c791977252d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 18.1.2-tuxcare.7 of @angular/animations."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/animations@18.1.2-tuxcare.7"
    }
  ]
}