{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ea28b71c-5d07-54aa-9d85-2b10b588ce46",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/bazel",
      "purl": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.14",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.14",
      "version": "8.2.14-tuxcare.14",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:b345a41b-3d76-5ddf-833f-965068c40ec4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 8.2.14-tuxcare.14 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:0f5f9aee-daf0-5a84-b794-3a934b76005a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 8.2.14-tuxcare.14 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:1f1928d5-1d5d-5fee-bf27-c4cf51fe3e83",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 8.2.14-tuxcare.14 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:b3b0e771-ed8b-53ad-8ded-8d28b1f3234a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-101895 is fixed in version 8.2.14-tuxcare.14 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:d93939ba-ee88-5c9b-b612-85799080363a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 8.2.14-tuxcare.14 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:623a6f34-e515-55ca-8a32-ff7df4db361a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 8.2.14-tuxcare.14 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:d0a879a0-ef13-5a60-a136-394181495b05",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 8.2.14-tuxcare.14 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:1bc0921b-53ea-5e24-8f61-d31737371f74",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 8.2.14-tuxcare.14 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:6e7ab458-c012-52de-89ba-37f5d9fe8326",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 8.2.14-tuxcare.14 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:cfaaa5f9-1e72-5af0-80d1-451509634aaf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 8.2.14-tuxcare.14 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:dfc9088a-fe74-5be0-a346-9c6cde055033",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 8.2.14-tuxcare.14 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:0ce30a01-f720-56ac-a2cc-3b1d0f2ccab6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 8.2.14-tuxcare.14 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:3c5dced1-0f3b-584b-969e-2357d357c119",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 8.2.14-tuxcare.14 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:3911c116-68ac-51cc-9492-fcebfc3f9839",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 8.2.14-tuxcare.14 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:d8a045cc-39b9-5c3a-8929-f320125382b4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 8.2.14-tuxcare.14 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:c40ab1fc-bf27-50fd-82f1-b24676cc3ec7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 8.2.14-tuxcare.14 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:723bfefd-748a-5aa8-b30f-c855450d5db4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 8.2.14-tuxcare.14 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:07f1a587-d214-55ae-8368-2e13981d33c6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 8.2.14-tuxcare.14 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:40992da3-af87-53a5-8a38-8bfefd223a93",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 8.2.14-tuxcare.14 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:3107889b-131c-513f-9ec8-4672bb371472",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 8.2.14-tuxcare.14 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:ff285840-517a-5ea6-9e9c-11dc5bd2bf1d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 8.2.14-tuxcare.14 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:8f734cd5-1b3b-56e0-a2ac-99c832d76b70",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 8.2.14-tuxcare.14 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:aece9807-c148-51f7-9b34-031cfff3c8bd",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 8.2.14-tuxcare.14 of @angular/bazel. not_affected \u2014 Angular 8.2.14 is NOT affected by CVE-2026-68945. The vulnerability exists in HttpTransferCache, a feature that automatically caches HTTP requests during SSR for client hydration. HttpTransferCache was introduced in Angular v16+ and does not exist in version 8.2.14. This version has only a manual TransferState key-value store with no automatic HttpClient integration, and no HTTP caching mechani...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:32ddf66d-3563-5ebb-be1a-5f5cac8fa43e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 8.2.14-tuxcare.14 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:bbf1735b-acce-53a1-9e9d-0cdb3fa64207",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 8.2.14-tuxcare.14 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:8747ee5d-9d71-5713-8901-9ae2cb6310e5",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 8.2.14-tuxcare.14 of @angular/bazel. not_affected \u2014 Angular 8.2.14 is NOT AFFECTED by CVE-2026-88056. The vulnerability requires a sophisticated URL resolution utility (`parseUrl` in `packages/platform-server/src/url.ts`) that calls `String.prototype.trim()` to strip Unicode whitespace, creating a discrepancy with WHATWG URL validation. This architecture was introduced in Angular v12+ (circa 2026 as TuxCare backports). Angular 8.2.14 (released N...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:40b5d4cd-ad6c-55d6-87fc-23ed6dfdd75f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 8.2.14-tuxcare.14 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:ba28bf72-eb5c-5b77-8ce7-fe7703390cfe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 8.2.14-tuxcare.14 of @angular/bazel."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:ba986ac7-5d9f-5411-9d6f-324474ac37ae",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 8.2.14-tuxcare.14 of @angular/bazel. not_affected \u2014 Angular v8.2.14 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, provideClientHydration(), and withRequestsMadeViaParent() \u2014 all features that do not exist in this version. These features were introduced in Angular v16 (per patches/CVE-2026-50170.patch and patches/CVE-2026-54266.patch). The target uses the legacy NgModule-based HttpClientModule without automatic ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:25722a61-fccc-516e-8308-8a8a90ff0d52",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 8.2.14-tuxcare.14 of @angular/bazel."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/bazel@8.2.14-tuxcare.14"
    }
  ]
}