{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f25fbd08-6878-5a62-aa1c-624a5eb66468",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/benchpress",
      "purl": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.16",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.16",
      "version": "16.2.12-tuxcare.16",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:6d4d600a-da53-5e86-b4ce-6ff63d1d5fa1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 16.2.12-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:aff2fbd3-99b7-5840-a68f-f55852107a0e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 16.2.12-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:4ef88c20-96f3-5c35-825e-8247faa85c4a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 16.2.12-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:d9e2b858-fd40-5bd3-8bab-c25796360d69",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-101895 is fixed in version 16.2.12-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:0d2cce61-7fbd-5c27-8538-8637a0a92fc4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 16.2.12-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:59c5f739-ddbb-596e-bc4f-4084e3b8613f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 16.2.12-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:ed698d56-9339-5b17-8323-f78f9cba480e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 16.2.12-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:a8859311-058f-59c7-b823-d6462ea98690",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 16.2.12-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:9fd9a4ae-177f-5a1c-8416-6e9b78856e7b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 16.2.12-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:8e301a86-c4d0-55fb-814d-3f4b8927139f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 16.2.12-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:73d5e894-8690-5e77-b637-1b90348d2a62",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 16.2.12-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:4c186e73-9aad-5f94-a4fd-bb6c29535be9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 16.2.12-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:4f0e6931-ee4b-5660-9b74-57d1a60b538b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 16.2.12-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:20d53f84-5f7b-5395-9f0e-3fea835865cb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 16.2.12-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:f61e86c6-ac18-51fe-878e-952ee7eb23ef",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 16.2.12-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:a20172b8-6da4-5e61-9d8e-1491e4fac9d2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 16.2.12-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:df8cc43a-8977-59cb-8b17-0b7d0c7de246",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 16.2.12-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:1101dc1c-93ac-54ae-89e5-0c4307839dd4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 16.2.12-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:f5479174-f15f-5670-bda7-646241376416",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 16.2.12-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:406eddad-d0ba-502d-8b1e-2ba400d83c59",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 16.2.12-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:4f4ea12e-3270-5eed-9662-176682a70758",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 16.2.12-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:593c5d88-c2a4-570e-ab18-944680b1e43c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 16.2.12-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:2a1de904-92bd-5dc0-b77a-3eda128c1967",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 16.2.12-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:3d4bc465-3ccb-5372-8263-86e166ee9dab",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 16.2.12-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:7d645519-d5a7-525e-b212-bdbd89a25b3e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 16.2.12-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:1f663c7a-7237-5a02-b302-f68541c55aa5",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 16.2.12-tuxcare.16 of @angular/benchpress. not_affected \u2014 CVE-2026-88056 affects Angular versions 20.3.x, 21.2.x, and 22.x where a refactored URL parsing utility added String.prototype.trim() that strips Unicode whitespace, enabling SSRF bypasses. The target (Angular 16.2.12-tuxcare.12) is based on Angular 16.2.x architecture, which predates the vulnerable code pattern entirely. TuxCare created url.ts fresh on June 24, 2026 for CVE-2026-50168, modelin...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:8ea649ff-728b-5a41-b5bd-8417a95d91f3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 16.2.12-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:c42a694a-3dfb-554a-bf9a-fe3d76fb2763",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 16.2.12-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:356f25a0-5722-5e4a-87e4-ed14227399ae",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 16.2.12-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:2063f7d8-0cd1-5963-b823-4d39be4d8dc3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 16.2.12-tuxcare.16 of @angular/benchpress."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/benchpress@16.2.12-tuxcare.16"
    }
  ]
}