{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:0aa139e3-99cd-5f31-b31a-8170aa13efe9",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/benchpress",
      "purl": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.18",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.18",
      "version": "17.3.12-tuxcare.18",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:f96c4733-34d9-5c44-8c62-670b1c692203",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.3.12-tuxcare.18 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:15b23ded-0ab6-5f08-a22d-71614192a02d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.3.12-tuxcare.18 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:ee24cb2f-13e9-5963-8d3f-7271eb62e2cf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.3.12-tuxcare.18 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:e93bcaae-4a37-5a58-a158-8bc2fa89171e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-101895 is fixed in version 17.3.12-tuxcare.18 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:01b2a221-c451-5a39-b91e-75bcaf53f682",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 17.3.12-tuxcare.18 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:52bb3cf7-b92a-553d-be94-658e0517452a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.3.12-tuxcare.18 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:a47dc5ab-ee9a-5c7b-aa61-0ba6055984c7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.3.12-tuxcare.18 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:e085ee65-8412-573b-b7a9-44a753d806d3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.3.12-tuxcare.18 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:3974c0a4-e192-59f3-9b67-9cb2f4b2a9ae",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 17.3.12-tuxcare.18 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:951766fb-646f-56fe-b0ea-59955dcff14e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 17.3.12-tuxcare.18 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:53b071f6-b2d7-5091-9cf0-6a4954b728d4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 17.3.12-tuxcare.18 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:d06245a2-0395-51be-bfcf-34e9ec4a069b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 17.3.12-tuxcare.18 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:03b849b2-9f0e-5e16-a3b9-7e1ecb115866",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 17.3.12-tuxcare.18 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:3ad9687a-7e6c-5320-a9e6-08909d01f40c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 17.3.12-tuxcare.18 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:49765bad-2627-56f4-bd42-9ca5998bfe38",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 17.3.12-tuxcare.18 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:b45fc10e-e796-5776-9422-a1e6245e1d80",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 17.3.12-tuxcare.18 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:a32dfcbc-1769-55bd-8330-60aa77fca0e0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 17.3.12-tuxcare.18 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:fa11a94e-52b7-542d-9865-70955aa8cb05",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 17.3.12-tuxcare.18 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:c9efa6fc-a0c0-5fb7-b470-4210803c3b65",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 17.3.12-tuxcare.18 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:f584cded-c97f-5573-add4-cb4358d3bb39",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 17.3.12-tuxcare.18 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:a3056229-96b8-5a41-9454-4032c8c441a9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 17.3.12-tuxcare.18 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:2084d821-17e6-5123-8092-805a3808e4f3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 17.3.12-tuxcare.18 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:58026845-f5f2-5f4c-9177-a135f93dea8f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 17.3.12-tuxcare.18 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:1d03db0b-9fd6-5563-84a7-83019d8fe5bc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 17.3.12-tuxcare.18 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:e1e90f94-2d20-585d-ac8e-e7da20f8eea3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 17.3.12-tuxcare.18 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:7847ec61-195c-5e52-9794-486a0d0b3aee",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 17.3.12-tuxcare.18 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:7a9f34e5-e9be-5a45-96eb-9d7c45fd6d76",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.3.12-tuxcare.18 of @angular/benchpress. not_affected \u2014 Version 17.3.12 is not affected by CVE-2026-88056. The vulnerability involves String.prototype.trim() being applied during URL resolution in Angular's platform-server, converting validated same-origin URLs with Unicode whitespace into cross-origin protocol-relative URLs, leading to SSRF. This vulnerable code pattern was introduced in newer Angular versions (v20+) and does not exist in version 1...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:6be9896c-2950-5882-8387-dc969b5cf1b7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 17.3.12-tuxcare.18 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:ef4b01ae-2079-5be8-8325-5da527f8c62a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 17.3.12-tuxcare.18 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:a0701a53-a87a-5758-bec2-f7d6e6c3dcef",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 17.3.12-tuxcare.18 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.18"
        }
      ],
      "bom-ref": "urn:uuid:7cd19f43-b594-510e-9ea1-8a71486a909d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 17.3.12-tuxcare.18 of @angular/benchpress."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/benchpress@17.3.12-tuxcare.18"
    }
  ]
}