{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3d9a2e8f-ac20-586c-9189-40cbdf94e720",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/benchpress",
      "purl": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.16",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.16",
      "version": "18.2.14-tuxcare.16",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:7dcbcefd-ef12-5da4-be01-3cc72fc1cbce",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.2.14-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:1a4ece56-d825-5d9e-9363-c53c823e1313",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 18.2.14-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:8af796cc-f270-5bb8-bf16-af51de7d17b8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101895 affects version 18.2.14-tuxcare.16 of @angular/benchpress, and is fixed in 18.2.14-tuxcare.17."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:31fb8d9d-8bca-59fb-9936-e7e697a73cff",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 18.2.14-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:d526ef92-8ad2-5807-a5d0-6dceac51d50c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 18.2.14-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:afe21b15-2cd2-51da-91d1-2fb16454e644",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 18.2.14-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:f3780e1d-f35c-541f-85d1-860f2ce8ecbb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 18.2.14-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:0345af6a-43e4-5edf-bbdb-bfcd4351b3e8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 18.2.14-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:2a70388b-ec6b-5ba7-8485-805e8c31c552",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 18.2.14-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:fd69103c-f2d6-52c1-901b-58a722ddb3dc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 18.2.14-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:2707a987-52d7-5c68-8bf8-67f12e28f6a6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 18.2.14-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:c01eef70-9fe1-5704-b1d1-8a26f1f16c47",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 18.2.14-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:de49cbb6-ff05-5f44-82ae-e14cccc43a93",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 18.2.14-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:fde2c20f-40a4-51d7-a63a-fd29db58c03f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 18.2.14-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:6c31a528-55df-5f3a-85c0-3ac5498135af",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 18.2.14-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:6a2588e8-6327-55b9-86da-e63441f6b578",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 18.2.14-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:80c15b29-c6fc-595f-ab27-abe62f40a2b2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 18.2.14-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:1782a822-ece3-5e4c-b743-2b8465bfa520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 18.2.14-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:5e4217b6-cd62-51f4-9b3e-c3413ae38df7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 18.2.14-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:7af7d7a0-ad97-53b0-923c-e4ec85696f8e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 18.2.14-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:6dea626e-fc0a-53f0-825d-12fc7068f6b4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 18.2.14-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:b8da35d0-7c35-5b34-9b60-87291db8faa9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 18.2.14-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:602b0559-d029-5ce5-a299-97b578fc1c93",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 18.2.14-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:b5ab53ca-2476-545b-ac35-29b893eab194",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 18.2.14-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:8b0b0fb3-22d2-586e-abcf-e0850a5e141f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 18.2.14-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:7c3eb084-5ff7-5fc8-a353-85917b9ced01",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 18.2.14-tuxcare.16 of @angular/benchpress. not_affected \u2014 The target version 18.2.14-tuxcare.13 is NOT affected by CVE-2026-88056. The vulnerable code pattern (calling String.prototype.trim() on URL strings before resolution) was never present in this version. The target uses a refactored parseUrl() implementation introduced via commit 49a60f6045 (May 2026) that correctly handles Unicode whitespace by percent-encoding it rather than stripping it, main...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:e9b2451e-7446-5b8b-b104-264273468e99",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 18.2.14-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:183684e6-b428-5a22-bab8-4c65260cb742",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 18.2.14-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:e1f8cd7e-93fb-5f30-b350-6e4697e10762",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 18.2.14-tuxcare.16 of @angular/benchpress."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:8a97547e-ba14-549f-b7c1-bd9239f341f2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 18.2.14-tuxcare.16 of @angular/benchpress."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/benchpress@18.2.14-tuxcare.16"
    }
  ]
}