{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:29190c03-6e94-5ea0-a833-b835455a514b",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/benchpress",
      "purl": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.17",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.17",
      "version": "17.3.12-tuxcare.17",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:91492e14-5817-589a-a982-fd1238edb9d4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.3.12-tuxcare.17 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:ef5ce912-0445-5d42-8b12-adf1f45bd25a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.3.12-tuxcare.17 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:2c8d34df-6f7f-5d8b-8fb3-5865cbf7ac9d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.3.12-tuxcare.17 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:4bb16995-58de-59f5-b792-982b4349a306",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101895 affects version 17.3.12-tuxcare.17 of @angular/benchpress, and is fixed in 17.3.12-tuxcare.18."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:d8600816-de79-5fc1-b105-27f176f47e99",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 17.3.12-tuxcare.17 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:b45a18f2-aa0c-5875-81a2-9f05be3aafc6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.3.12-tuxcare.17 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:c440684e-643d-5102-9312-c4ca5bc055ca",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.3.12-tuxcare.17 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:f1451e44-49bc-5181-abf1-1fd8f7c05bac",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.3.12-tuxcare.17 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:f1e9a411-69c9-5534-8a34-ebb3a33bef17",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 17.3.12-tuxcare.17 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:6497c29f-05ed-534a-b9a7-18f49a2523c9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 17.3.12-tuxcare.17 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:7605305b-1409-5e93-a213-9f9bdffa0aad",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 17.3.12-tuxcare.17 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:0af4c30e-43e2-5154-b0dd-1723b233c1fc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 17.3.12-tuxcare.17 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:f9144df4-4442-5f3c-8dfe-61493310707b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 17.3.12-tuxcare.17 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:c5a49bf4-3b0e-5bc9-93ae-56a795745f41",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 17.3.12-tuxcare.17 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:faeb0707-b25e-5343-a69e-c638bc0e4a08",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 17.3.12-tuxcare.17 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:75f2829e-9087-55b6-9570-de11e374cb36",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 17.3.12-tuxcare.17 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:a89425d2-41c2-50fd-93f0-e990f9a36f39",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 17.3.12-tuxcare.17 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:210e4478-8235-56a6-9c40-8250f7142a7d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 17.3.12-tuxcare.17 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:0fb3eca1-c633-5905-bc66-b6c79c8cc297",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 17.3.12-tuxcare.17 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:cd11083d-85a2-52f4-aa9d-5a9622b306d8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 17.3.12-tuxcare.17 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:f7e636e2-5b65-522a-98d6-eee11bec5365",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 17.3.12-tuxcare.17 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:63078c59-1649-51fa-9169-fd70e25bf896",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 17.3.12-tuxcare.17 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:9f7d3ab0-4ec4-5c01-bee9-0f4668152d6e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 17.3.12-tuxcare.17 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:7bcc72fb-f354-51b6-b60f-2b2af150570e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 17.3.12-tuxcare.17 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:ae6f39a1-f0ea-503c-8c3c-46befc239e1a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 17.3.12-tuxcare.17 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:237f98d9-568a-5745-832b-72bc3926523f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 17.3.12-tuxcare.17 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:9660db03-c1af-5173-b3ce-ed1429f36935",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.3.12-tuxcare.17 of @angular/benchpress. not_affected \u2014 Version 17.3.12 is not affected by CVE-2026-88056. The vulnerability involves String.prototype.trim() being applied during URL resolution in Angular's platform-server, converting validated same-origin URLs with Unicode whitespace into cross-origin protocol-relative URLs, leading to SSRF. This vulnerable code pattern was introduced in newer Angular versions (v20+) and does not exist in version 1...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:5f57c116-210b-5880-a235-f6eef712a961",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 17.3.12-tuxcare.17 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:596c9ace-ac73-5a2f-814b-75837aa66f91",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 17.3.12-tuxcare.17 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:85e1a791-aa57-5260-a5b3-47c3d2f15ba3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 17.3.12-tuxcare.17 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.17"
        }
      ],
      "bom-ref": "urn:uuid:b2545a30-2356-56be-a2a5-66b753289de4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 17.3.12-tuxcare.17 of @angular/benchpress."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.17"
    }
  ]
}