{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:44cec03f-2ca0-5d7c-b7ba-42d9052940d4",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/animations",
      "purl": "pkg:npm/%40angular/animations@19.2.21-tuxcare.8",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.8",
      "version": "19.2.21-tuxcare.8",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:c382476f-c5e6-57a3-a979-f71346942e13",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101895 affects version 19.2.21-tuxcare.8 of @angular/animations, and is fixed in 19.2.21-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:51dadd75-fd5f-54ef-bf42-0c5750c92a7f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 19.2.21-tuxcare.8 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:66e5f1c0-7963-58a5-8335-abd22bf07039",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-27970 does not affect version 19.2.21-tuxcare.8 of @angular/animations. already_fixed \u2014 The target repository (Angular 19.2.21-tuxcare.4) already contains the fix for CVE-2026-27970. The vulnerability (XSS via unsanitized HTML attributes in ICU message translations) has been addressed by TuxCare in prior backports. The defense mechanism in packages/core/src/render3/i18n/i18n_parse.ts lines 829-843 implements the same attribute allowlist validation as the vendor patch, blocking URI...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:d91bb8ec-e15a-56b4-9096-6f0e2cd1ef6b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 19.2.21-tuxcare.8 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:46cfcd57-0595-5a3d-8c5a-4719b633e07f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 19.2.21-tuxcare.8 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:50967e83-5596-5a7b-8427-a97220861599",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 19.2.21-tuxcare.8 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:31e906b1-5ca1-5d6c-bb47-5db6ea00d9c0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 19.2.21-tuxcare.8 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:44f1a113-66db-50d8-9c43-ade56a3d1605",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 19.2.21-tuxcare.8 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:18705864-229e-52ad-b370-ef1ea9b4de7f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 19.2.21-tuxcare.8 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:87ff2e95-793e-5068-ae2e-99a4f0f7a28d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 19.2.21-tuxcare.8 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:f886d9d7-241f-5b81-afcb-31ec2c7d67c6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 19.2.21-tuxcare.8 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:ea354592-f5ed-5cd3-8262-b24504708e5e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 19.2.21-tuxcare.8 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:484130f3-a407-5e2a-97c5-79a00b46a328",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 19.2.21-tuxcare.8 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:9bbe1824-67c6-53af-9a78-2b4b2e3fb056",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 19.2.21-tuxcare.8 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:41b87c15-4179-517c-8c70-f4b5b5444e27",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 19.2.21-tuxcare.8 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:007ccd7a-e73e-505b-8fa8-ca8fabbc52c6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 19.2.21-tuxcare.8 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:df14f882-ee4a-5087-accf-a560a40f4bb2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 19.2.21-tuxcare.8 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:08ae5259-f872-54fd-9494-76f6fdc1bf55",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 19.2.21-tuxcare.8 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:518951f9-25c0-50b9-bc1e-9092efc9e0c1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 19.2.21-tuxcare.8 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:f1e5701c-cce4-50b5-b460-e46d3914be4b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 19.2.21-tuxcare.8 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:0b9eac4b-25b6-5dea-bd7c-f73f763dabad",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 19.2.21-tuxcare.8 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:d457dcd7-6c7f-5210-a503-b044c7d414bf",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 19.2.21-tuxcare.8 of @angular/animations. not_affected \u2014 CVE-2026-88056 does not affect this Angular v19.2.21-tuxcare.5 target. The CVE describes a vulnerability where `String.prototype.trim()` strips Unicode whitespace (U+00A0, U+FEFF) from URLs during SSR, converting same-origin relative paths into cross-origin protocol-relative URLs that leak credentials. The v19.2.x branch uses a simpler URL resolution implementation created by TuxCare (commit 81...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:5211b7d7-c371-55fa-818a-344d9d96167f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 19.2.21-tuxcare.8 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:6a6394f1-09ad-50e8-a701-35bc05b436c0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 19.2.21-tuxcare.8 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:37d057de-fc9a-584d-b0b6-89a520a1bb25",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 19.2.21-tuxcare.8 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:d7f61dd0-3263-5072-b024-7d0fc74b24db",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 19.2.21-tuxcare.8 of @angular/animations."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/animations@19.2.21-tuxcare.8"
    }
  ]
}