{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:8d22ee3f-d16d-5243-9aa6-ac7b803281fd",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/benchpress",
      "purl": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.6",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.6",
      "version": "16.2.11-tuxcare.6",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:7df8afde-d53d-541f-88e9-ec192380f1ca",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59052 affects version 16.2.11-tuxcare.6 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4275b479-ab42-5d65-aa87-0bada792de60",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 16.2.11-tuxcare.6 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:56bc77f8-e62f-53d5-b26c-4f388924a7c2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 16.2.11-tuxcare.6 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a402eb8a-325c-59d1-8449-2c1676f9ea19",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-101895 is fixed in version 16.2.11-tuxcare.6 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:94e0ded4-ae56-5153-86f7-32f84d10b4c7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 16.2.11-tuxcare.6 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:59e05f4e-fed8-52f2-a464-32eb571d64dc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 16.2.11-tuxcare.6 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:8ecf429d-1566-5525-a952-96d8a6654a62",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 16.2.11-tuxcare.6 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1e1d6be3-470e-5eab-8a8c-b8e6e53d18b6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 16.2.11-tuxcare.6 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ba0a3841-bf99-58ee-8508-1fa75586d31e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 16.2.11-tuxcare.6 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:028ef4f0-89e7-5e28-82c4-9db637f740cc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 16.2.11-tuxcare.6 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:df88d471-8de2-536f-b5a3-95d2901c3b3d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 16.2.11-tuxcare.6 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:5b5ef1f7-a0d0-545f-989d-5fe2a40a3a6b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 16.2.11-tuxcare.6 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:64364da4-05bf-5321-a6e5-72bd89a747e5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 16.2.11-tuxcare.6 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:69d44815-a35d-519c-824a-f6fd0fe9c844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 16.2.11-tuxcare.6 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:94e36efa-14fb-5c97-8a81-48eccf916b17",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 16.2.11-tuxcare.6 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a2108631-33c4-5dec-8129-c2d4e0ed77ad",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 16.2.11-tuxcare.6 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d942c056-ef95-55a6-bbef-e2b4508f3a8b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 16.2.11-tuxcare.6 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:742bf931-cd44-5f80-bf89-6b19ed99e517",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 16.2.11-tuxcare.6 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:417c6895-af78-5d56-8aaf-4af731ce9fb5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 16.2.11-tuxcare.6 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ffd6a5df-9b4c-540a-acec-55f445c0ffec",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 16.2.11-tuxcare.6 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4f8766e0-c65b-57df-a5bd-3e8d8d79fbaf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 16.2.11-tuxcare.6 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a723272b-64a7-52c4-9808-d89e5a8cfb8b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 16.2.11-tuxcare.6 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:371988c4-91dd-5b06-a804-4f5012e5cc5b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 16.2.11-tuxcare.6 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:9ee269d9-3342-5f53-920e-cdf1a6b599c6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 16.2.11-tuxcare.6 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:79764019-db9c-5600-8fa3-9745c95dfa6d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 16.2.11-tuxcare.6 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c58b8277-745d-5a9d-94e8-43672507a0ef",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 16.2.11-tuxcare.6 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4d671bd5-78d8-51a5-8525-bb50f7b47135",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 16.2.11-tuxcare.6 of @angular/benchpress. not_affected \u2014 Angular 16.2.11-tuxcare.2 is NOT affected by CVE-2026-88056. The vulnerability requires WHATWG URL validation combined with String.prototype.trim() on URLs during SSR, creating a discrepancy that enables SSRF. While the target uses WHATWG URL parsing (backported in commit c03fbfd7cc for CVE-2026-50168), it does NOT call String.prototype.trim() on URLs. The attack chain is broken at the trim() s...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:3ee4e09d-2b8f-5b29-844e-e2a48565a465",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 16.2.11-tuxcare.6 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:07492814-e2bf-5cbe-bd6f-7328255d12d5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 16.2.11-tuxcare.6 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4f52fb4a-f963-5e68-acc9-c82ec5c1e15d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 16.2.11-tuxcare.6 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:0a611e7f-0c3e-5d06-b37d-bccb961f4a52",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 16.2.11-tuxcare.6 of @angular/benchpress."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/benchpress@16.2.11-tuxcare.6"
    }
  ]
}