{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:794966ad-6d7e-541b-8ad5-50bfeaf822c5",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/bazel",
      "purl": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.17",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.17",
      "version": "17.3.12-tuxcare.17",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:7dd5880e-ba94-5e1f-96a9-499aedc01f73",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.3.12-tuxcare.17 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:ba530ecc-ef47-59c2-8add-06703d1925d5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.3.12-tuxcare.17 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:801cffb3-5ea7-521c-a33e-5eb458622993",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.3.12-tuxcare.17 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:37a4f60a-20b3-5c62-a038-775fb908ff34",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101895 affects version 17.3.12-tuxcare.17 of @angular/bazel, and is fixed in 17.3.12-tuxcare.18."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:ce36ffbe-e547-5e86-923a-d1263c76aa09",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 17.3.12-tuxcare.17 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:a4d1aa06-d296-5c9c-b859-adcfdabc2f28",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.3.12-tuxcare.17 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:da917e6a-bdc2-5e6f-8b4a-fcf502445d5d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.3.12-tuxcare.17 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:e7a16ac7-c527-5a95-8adc-b2a526c2aa48",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.3.12-tuxcare.17 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:2a1a46c6-9d49-5431-93db-f70b42123046",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 17.3.12-tuxcare.17 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:91404878-fef8-598a-8bd9-7363e498a1ba",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 17.3.12-tuxcare.17 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:e023af37-4428-5e2e-ae78-598d1b392ddf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 17.3.12-tuxcare.17 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:6e8cb23c-e483-53db-9852-e96eec536a5f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 17.3.12-tuxcare.17 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:5177246f-e615-585c-9a18-4c1818732e28",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 17.3.12-tuxcare.17 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:118014a8-3694-50f6-9d09-b84d9715348c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 17.3.12-tuxcare.17 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:a429916d-2acb-5b87-a306-2c7293911ddf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 17.3.12-tuxcare.17 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:b6689171-18a2-50b3-8cae-c340ed3e661c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 17.3.12-tuxcare.17 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:fd9307b3-e7da-5c89-bcae-9dce9bd06713",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 17.3.12-tuxcare.17 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:68f7fbf9-d50d-5613-9006-b2218f9f1e60",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 17.3.12-tuxcare.17 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:033b0910-79ab-5150-ac3a-d59a028c8587",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 17.3.12-tuxcare.17 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:7f94ec52-dfa2-5fa8-acb6-9af9c37d6f9f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 17.3.12-tuxcare.17 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:30057cc7-02c6-58b6-95eb-4c644e298cd2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 17.3.12-tuxcare.17 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:0ce0ed26-b029-5111-adaa-969f9a48ac34",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 17.3.12-tuxcare.17 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:ca7bac2b-5b93-528f-bfab-7a362b117848",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 17.3.12-tuxcare.17 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:13319171-ae2b-5bf7-ae57-d748ab67685c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 17.3.12-tuxcare.17 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:bc92c44c-c513-5061-96d8-6619c6e61b34",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 17.3.12-tuxcare.17 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:469442a8-452b-58a9-886b-d5fe0276366c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 17.3.12-tuxcare.17 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:bbb5160f-fb71-5845-919a-e35fde0ec9f7",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.3.12-tuxcare.17 of @angular/bazel. not_affected \u2014 Version 17.3.12 is not affected by CVE-2026-88056. The vulnerability involves String.prototype.trim() being applied during URL resolution in Angular's platform-server, converting validated same-origin URLs with Unicode whitespace into cross-origin protocol-relative URLs, leading to SSRF. This vulnerable code pattern was introduced in newer Angular versions (v20+) and does not exist in version 1...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:c2f373c4-3f81-5bac-a45a-d5651190d67f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 17.3.12-tuxcare.17 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:e4f57606-5b0d-5273-81e7-feb525552a83",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 17.3.12-tuxcare.17 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:cc30ccf8-62b7-5b9d-840f-2a0b5063b538",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 17.3.12-tuxcare.17 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:c58fd088-e81b-5f22-8847-0c1b247edfc5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 17.3.12-tuxcare.17 of @angular/bazel."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/bazel@17.3.12-tuxcare.17"
    }
  ]
}