{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:921bc74d-4121-5092-a1c0-8346b8651b12",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/bazel",
      "purl": "pkg:npm/%40angular/bazel@18.1.2-tuxcare.8",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/bazel@18.1.2-tuxcare.8",
      "version": "18.1.2-tuxcare.8",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:77f53dc1-82ab-544d-a18d-bfff6c2f135e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59052 affects version 18.1.2-tuxcare.8 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:01a9ee6e-d77e-5503-87e1-06694a3126cf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.1.2-tuxcare.8 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:1ae273fc-3d91-5522-aaaf-d6e7532bff2c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 18.1.2-tuxcare.8 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:52f5804d-fa86-531c-b5c1-fe7599b70335",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-101895 is fixed in version 18.1.2-tuxcare.8 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:309bf633-cb3f-585a-babc-c4d7d331aaa0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 18.1.2-tuxcare.8 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:ab370b93-8687-598e-aa42-14737f47cb48",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 18.1.2-tuxcare.8 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:8cd4b50e-db6c-51dc-8ba1-39373c84e433",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 18.1.2-tuxcare.8 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:8a1e6136-50b9-5f69-bb39-aec04f9cce93",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 18.1.2-tuxcare.8 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:684dff72-7f00-5500-863b-63ec8223e85e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 18.1.2-tuxcare.8 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:8c9b5429-0ce1-59c9-a75a-be8fde1e2649",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 18.1.2-tuxcare.8 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:6682402d-a463-567b-b6b9-1bd0dd132efd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 18.1.2-tuxcare.8 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:f8556eed-1748-5475-828c-b82cf6490f7e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 18.1.2-tuxcare.8 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:2324260c-8b63-5ee0-91f2-a224e5033cd9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 18.1.2-tuxcare.8 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:a3fe0602-f30c-588b-b37b-5ca01b850b9b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 18.1.2-tuxcare.8 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:768d4afa-84d5-5861-a433-62c2c34c4f51",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 18.1.2-tuxcare.8 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:22f40b78-4a00-56ef-b711-3ca69d2ae1ef",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50555 does not affect version 18.1.2-tuxcare.8 of @angular/bazel. already_fixed \u2014 The target Angular 18.1.2 repository has already been patched for this vulnerability. TuxCare commit 32991dd728 'fix all CVEs' added a cumulative domino patch that fixes both the NOSCRIPT XSS vulnerability (CVE-2026-50556, corresponding to the provided patch f74cccd) and the astral Unicode index bug (CVE-2026-50555). The patch is applied automatically to the domino dependency via patch-package ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:1dc26053-842f-51ab-8760-1f9585e2f732",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50556 does not affect version 18.1.2-tuxcare.8 of @angular/bazel. already_fixed \u2014 CVE-2026-50556 (XSS via noscript raw-text serialization in domino) has been fixed in this Angular repository. The fix is present in tools/esm-interop/patches/npm/domino+2.1.6.patch and is automatically applied to the domino dependency during installation via the postinstall script. The patch was added by TuxCare in commit 32991dd728 on 2026-07-01.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:0cb7d326-8fd1-54e0-baef-d53f35e4e0ed",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 18.1.2-tuxcare.8 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:e78cae11-e36f-58c7-8756-889dc2a37426",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 18.1.2-tuxcare.8 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:08279fdc-44bd-5ba9-9e35-b70bafb2effb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 18.1.2-tuxcare.8 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:b8bd732c-acc3-5d46-bca9-6359a83463be",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 18.1.2-tuxcare.8 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:aed5a8d8-363a-5a70-aaca-bff51a681c11",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 18.1.2-tuxcare.8 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:e09fc073-50d4-5faf-a316-76b37e34376a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 18.1.2-tuxcare.8 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:eb84996d-f148-5973-a51e-999247bb7eff",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 18.1.2-tuxcare.8 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:2c10d0e2-0668-5641-9219-fbf3c6b79c5b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 18.1.2-tuxcare.8 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:44b1006b-e7f0-57f3-9d1a-f6242e389f96",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 18.1.2-tuxcare.8 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:de7673b4-7111-5d31-9286-14ca9e4e04b5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 18.1.2-tuxcare.8 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:b7b9e217-c943-5c8d-b8ef-a5e1204b714c",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 18.1.2-tuxcare.8 of @angular/bazel. not_affected \u2014 The target version (Angular 18.1.2) does NOT contain the vulnerable code pattern. CVE-2026-88056 describes a Unicode whitespace trimming vulnerability in Angular SSR's URL resolution, where `String.prototype.trim()` strips characters like U+00A0, converting same-origin paths into protocol-relative cross-origin URLs. The vulnerability was introduced in Angular v20.x during a refactoring (commit ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:cf93a46c-3248-5d3d-846e-97f2839f4f5d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 18.1.2-tuxcare.8 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:554ff267-e1e5-5976-a11c-00f0f5a0b0d6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 18.1.2-tuxcare.8 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:fc99001c-a249-5d59-92e3-146c254a83c4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 18.1.2-tuxcare.8 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.1.2-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:b3478c1f-498a-52ff-88f2-5786a3d75b61",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 18.1.2-tuxcare.8 of @angular/bazel."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/bazel@18.1.2-tuxcare.8"
    }
  ]
}