{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:6ebf1dcb-41da-5bf4-ad0f-dbc6a84e6e8d",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/benchpress",
      "purl": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.7",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.7",
      "version": "17.1.0-tuxcare.7",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:0a6f2773-c558-5a83-b5f1-f54f558fce7e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.1.0-tuxcare.7 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:202e03ce-aacd-551c-af37-14edfc68bbb1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.1.0-tuxcare.7 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:1876d950-9eb0-5c93-b314-19adbfabba4f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.1.0-tuxcare.7 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:dd2a15fc-278b-5720-b6ba-146c53c0bd02",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101895 affects version 17.1.0-tuxcare.7 of @angular/benchpress, and is fixed in 17.1.0-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:8f1b8ac5-4cc6-5768-9c4f-c7778bd8ff3e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 17.1.0-tuxcare.7 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:fb907191-089f-5615-886e-8b7f914d1906",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.1.0-tuxcare.7 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:0077af1e-61d9-5584-be5a-68478077ba60",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.1.0-tuxcare.7 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:ad23f9da-eae9-5933-b286-760e2222d425",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.1.0-tuxcare.7 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:32ac548b-3a61-5b61-9a5c-6f54570278d1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 17.1.0-tuxcare.7 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:2f247dc3-11ba-5c95-809b-3f3b6d3cd046",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 17.1.0-tuxcare.7 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:4394827d-fb67-515d-9a67-9af84d4a526b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 17.1.0-tuxcare.7 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:0b071611-b568-5fd7-9854-eb31530d4033",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 17.1.0-tuxcare.7 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:940625c3-45a6-5952-9379-7e51b8b77a54",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 17.1.0-tuxcare.7 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:67871f2e-f56d-5514-8475-41da96a656a3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 17.1.0-tuxcare.7 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:0646269f-3b25-5eeb-9e3b-93787a691b0b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 17.1.0-tuxcare.7 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:3c73c75d-df88-5418-b816-db80c9b10000",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 17.1.0-tuxcare.7 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:d2f8d0cd-a9d1-5ee0-8cf4-bc46de923943",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 17.1.0-tuxcare.7 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:ea72fef7-b674-55e0-8569-bed550ebac56",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 17.1.0-tuxcare.7 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:2ecfa6cc-e1ae-5225-82fa-5ed0bc4bd15d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 17.1.0-tuxcare.7 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:a4beecd9-ffbe-5bdc-97d1-20688fb5d980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 17.1.0-tuxcare.7 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:1a5a6a18-6b9b-541a-b762-4de2d6c03a8d",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 17.1.0-tuxcare.7 of @angular/benchpress. not_affected \u2014 Angular v17.1.0 does not have the TwoWayProperty IR operation that is the subject of CVE-2026-54265. Two-way bindings are desugared into separate property and event bindings before template pipeline processing, with the property half using the same parsePropertyBinding() code path as one-way property bindings, which are properly sanitized.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:a8aaa3cd-0e4c-5750-980e-57cd4c8ef65a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 17.1.0-tuxcare.7 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:e529188a-edad-5a99-b07b-63bbdb89964f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 17.1.0-tuxcare.7 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:3c31aabb-f473-5550-b8f1-4fec4181fe13",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 17.1.0-tuxcare.7 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:566c5e31-5c7b-5536-a711-372ce57828e2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 17.1.0-tuxcare.7 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:0bc38195-3835-553f-b154-5ecbdffde471",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 17.1.0-tuxcare.7 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:73b5a107-e55d-5674-851e-7cbbedd0757b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 17.1.0-tuxcare.7 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:6c39f652-b217-5f19-b72b-fba669c15ee5",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.1.0-tuxcare.7 of @angular/benchpress. not_affected \u2014 Angular 17.1.0 was never vulnerable to CVE-2026-88056. The vulnerability exists only in newer Angular versions (v18+, v19+, v20+ before fixes) where a url.ts file with a parseUrl function that uses String.prototype.trim() was introduced. Angular 17.1.0 does not have this file in the upstream release. TuxCare created url.ts for their 17.1.0 fork (commit e06d36f339 by ejarocki@cloudlinux.com) but...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:22e085bc-a685-5981-82f5-f958626dd736",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 17.1.0-tuxcare.7 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:6507cc32-785c-5d73-94af-3e7b23a5d034",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88058 does not affect version 17.1.0-tuxcare.7 of @angular/benchpress. not_affected \u2014 The Angular repository (version 17.1.0-tuxcare.5 at SHA 1b802ce320) is not affected by CVE-2026-88058 because it does not contain the vulnerable source code. The vulnerability exists in the domino library's HTML serialization code (lib/NodeUtils.js), which Angular references as a dependency in package.json but does not vendor. The upstream patch (89b20568dfaee1ec8e0b3bcf1872acdddd2f4fef) is a D...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:d604ec84-ae61-5960-928b-dd1c11221afe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 17.1.0-tuxcare.7 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:50826345-e51c-5a02-84cf-b8a258e423c1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 17.1.0-tuxcare.7 of @angular/benchpress."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/benchpress@17.1.0-tuxcare.7"
    }
  ]
}