{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:97cc9a84-8caf-5c49-8b07-00f1c188f7cf",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/animations",
      "purl": "pkg:npm/%40angular/animations@8.2.14-tuxcare.14",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.14",
      "version": "8.2.14-tuxcare.14",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:170179bd-8092-5e80-8df7-59450cf80781",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 8.2.14-tuxcare.14 of @angular/animations."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:c674f977-f49f-50e4-afcb-8598af83c1ea",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 8.2.14-tuxcare.14 of @angular/animations."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:e0131b5a-a1ce-526d-84a1-c67bd8ec945d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 8.2.14-tuxcare.14 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:1b630609-c899-542c-b4fb-daa07cb22733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-101895 is fixed in version 8.2.14-tuxcare.14 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:1a540ac8-50ee-552c-b19f-355984e30039",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 8.2.14-tuxcare.14 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:f15502a5-b571-5a7f-8770-4a5df56560e8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 8.2.14-tuxcare.14 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:e2739a76-440f-568b-8b93-234e27689458",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 8.2.14-tuxcare.14 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:9530398b-7e02-5e13-8b11-06c43c3a3bb9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 8.2.14-tuxcare.14 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:106e2148-7ad5-5ca0-b89b-3beff351799d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 8.2.14-tuxcare.14 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:8baf1be9-4dc4-5de3-a8b8-5a1865d3a620",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 8.2.14-tuxcare.14 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:cc4d6463-6b95-5bb9-a087-d3e2c7fda74d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 8.2.14-tuxcare.14 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:3101c5e4-9c1f-50fe-836d-1a4a7726bf21",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 8.2.14-tuxcare.14 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:fee60cf7-c590-526b-bb24-263becfaa47e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 8.2.14-tuxcare.14 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:164b2bad-c8af-57e5-8b56-91ca128438e8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 8.2.14-tuxcare.14 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:434dc39c-fbf4-5c02-a28c-20193c2f77c4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 8.2.14-tuxcare.14 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:f22a03e4-28d4-59e2-8be0-d5d610267b3e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 8.2.14-tuxcare.14 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:439081d7-e1dd-5cec-864b-232d84650f54",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 8.2.14-tuxcare.14 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:0074e2fc-be18-5c1a-9ba5-31efdf535791",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 8.2.14-tuxcare.14 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:ce6bbdb4-8223-56d3-b741-e5d8a3e67f21",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 8.2.14-tuxcare.14 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:6fec75c4-0560-5691-96ee-fe114149bbb4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 8.2.14-tuxcare.14 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:d55fcb8b-daff-559f-8fcf-b1a03b21881f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 8.2.14-tuxcare.14 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:17eebab7-c65e-5b4e-ac88-f31a66c7352e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 8.2.14-tuxcare.14 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:5c333812-0aab-5746-a758-91e23d821104",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 8.2.14-tuxcare.14 of @angular/animations. not_affected \u2014 Angular 8.2.14 is NOT affected by CVE-2026-68945. The vulnerability exists in HttpTransferCache, a feature that automatically caches HTTP requests during SSR for client hydration. HttpTransferCache was introduced in Angular v16+ and does not exist in version 8.2.14. This version has only a manual TransferState key-value store with no automatic HttpClient integration, and no HTTP caching mechani...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:b3f7e6ca-f21d-5975-aac6-306b2b921090",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 8.2.14-tuxcare.14 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:f7f6b427-20a7-5d4c-9960-aaad0f0b4d27",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 8.2.14-tuxcare.14 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:0f630968-7dd6-5bd8-8cf3-b2b57c07be03",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 8.2.14-tuxcare.14 of @angular/animations. not_affected \u2014 Angular 8.2.14 is NOT AFFECTED by CVE-2026-88056. The vulnerability requires a sophisticated URL resolution utility (`parseUrl` in `packages/platform-server/src/url.ts`) that calls `String.prototype.trim()` to strip Unicode whitespace, creating a discrepancy with WHATWG URL validation. This architecture was introduced in Angular v12+ (circa 2026 as TuxCare backports). Angular 8.2.14 (released N...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:6ad8db1b-138c-527e-80a1-7c03883c27c4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 8.2.14-tuxcare.14 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:1694f8dd-7b93-5f99-b92c-6f73b0d499bb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 8.2.14-tuxcare.14 of @angular/animations."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:62022f45-c3b5-5443-8906-2739bdbfd7d9",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 8.2.14-tuxcare.14 of @angular/animations. not_affected \u2014 Angular v8.2.14 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, provideClientHydration(), and withRequestsMadeViaParent() \u2014 all features that do not exist in this version. These features were introduced in Angular v16 (per patches/CVE-2026-50170.patch and patches/CVE-2026-54266.patch). The target uses the legacy NgModule-based HttpClientModule without automatic ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:aae9b481-7011-53d6-82af-f6250574afde",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 8.2.14-tuxcare.14 of @angular/animations."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/animations@8.2.14-tuxcare.14"
    }
  ]
}