{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:fd4deb0b-29bb-5de4-a475-678d7312ddd4",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/bazel",
      "purl": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.16",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.16",
      "version": "18.2.14-tuxcare.16",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:7590a90e-2fe7-52b3-aacd-887b39eac224",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.2.14-tuxcare.16 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:2ff4b905-94e0-5764-8e5d-fe01069f3a34",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 18.2.14-tuxcare.16 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:6faadd49-06d8-5da4-8ec6-70744cbe1215",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101895 affects version 18.2.14-tuxcare.16 of @angular/bazel, and is fixed in 18.2.14-tuxcare.17."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:b5f26d28-1e65-546f-a766-4311aa3f3bef",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 18.2.14-tuxcare.16 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:607625d8-e8b1-5daa-82f5-6e6628f70fff",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 18.2.14-tuxcare.16 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:40a66eed-0894-534b-8116-5dd969031bd0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 18.2.14-tuxcare.16 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:af20a454-12cb-50b9-a34e-592a32f5f4ab",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 18.2.14-tuxcare.16 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:8a70f9be-3c78-5271-8b03-c3c8d3d65422",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 18.2.14-tuxcare.16 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:5f537f55-a3d4-5027-8ea5-e612f8f3bd29",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 18.2.14-tuxcare.16 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:06981fd9-3ba3-5967-aaaa-2350ce6313cf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 18.2.14-tuxcare.16 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:32e99492-eba0-55a8-9426-f413b577ed4e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 18.2.14-tuxcare.16 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:6f7d0811-b36b-5924-b3ae-c725684547c8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 18.2.14-tuxcare.16 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:54549142-0ecc-5b93-b34f-e1c0aebcf465",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 18.2.14-tuxcare.16 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:43ca6ce4-d14d-56f5-a90d-0977e03e3257",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 18.2.14-tuxcare.16 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:94167c80-6395-57cf-9267-263adfaf568e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 18.2.14-tuxcare.16 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:0d14eb13-ab05-529a-9580-c4d55520ae8c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 18.2.14-tuxcare.16 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:31aa39a2-76b5-5c7c-8e6b-b7442facf0d9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 18.2.14-tuxcare.16 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:58bf833a-a905-5c09-b538-6a37b794041b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 18.2.14-tuxcare.16 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:68e6aaa2-0bb4-520c-8801-112b8a868a9e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 18.2.14-tuxcare.16 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:bf5b7770-67f7-5787-ae5a-a460efb4de9e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 18.2.14-tuxcare.16 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:ffd5c9dd-e9a8-55ce-9b27-6a167698e859",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 18.2.14-tuxcare.16 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:747a4e0a-1010-5b9c-9452-f76cec7a2b26",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 18.2.14-tuxcare.16 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:cffe2a04-1f0f-59c6-96f3-65113d834b3b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 18.2.14-tuxcare.16 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:3a9fae7c-8a5e-50f9-be7a-a58d135c04d1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 18.2.14-tuxcare.16 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:fc44a030-dce6-57ca-9579-4de437a270bf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 18.2.14-tuxcare.16 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:b20f9734-d23d-5461-9754-aa1dda11134e",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 18.2.14-tuxcare.16 of @angular/bazel. not_affected \u2014 The target version 18.2.14-tuxcare.13 is NOT affected by CVE-2026-88056. The vulnerable code pattern (calling String.prototype.trim() on URL strings before resolution) was never present in this version. The target uses a refactored parseUrl() implementation introduced via commit 49a60f6045 (May 2026) that correctly handles Unicode whitespace by percent-encoding it rather than stripping it, main...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:279963bb-a915-52f9-91f0-5f870774a2b9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 18.2.14-tuxcare.16 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:5621fcf3-ebc6-5782-a1e4-9f1b9034ca36",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 18.2.14-tuxcare.16 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:a4e9f5e0-1930-511e-b9b7-f4768f83c097",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 18.2.14-tuxcare.16 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:32c8347a-e3e6-5b34-b4e0-908bd34b7594",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 18.2.14-tuxcare.16 of @angular/bazel."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/bazel@18.2.14-tuxcare.16"
    }
  ]
}