{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3d761efd-9af6-5d2b-9941-36ab0845a110",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/common",
      "purl": "pkg:npm/%40angular/common@12.2.17-tuxcare.12",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/common@12.2.17-tuxcare.12",
      "version": "12.2.17-tuxcare.12",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:58aa45b4-c213-5796-9b31-3d03e9f9b58b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 12.2.17-tuxcare.12 of @angular/common."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:c9cc04c2-567a-5ee8-bceb-0431df0004b2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 12.2.17-tuxcare.12 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:7a0da2f7-e0f2-5ce4-a943-af7dd0d6ff5e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-101895 is fixed in version 12.2.17-tuxcare.12 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:23808db3-5826-55dc-855a-42d718e2ee2c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 12.2.17-tuxcare.12 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:6387144f-363c-5868-b122-4e8371277055",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 12.2.17-tuxcare.12 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:267492ad-00d3-5c25-97a5-bfd11e444d52",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 12.2.17-tuxcare.12 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:4f4f2a6c-3497-5ea4-ba8b-6db1e5cabad9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 12.2.17-tuxcare.12 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:a4f3e73f-6f26-5cab-94a6-58653181a10b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 12.2.17-tuxcare.12 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:a3039ba5-2d33-5b02-91fb-51ab51356609",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 12.2.17-tuxcare.12 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:a7e99976-1e55-5410-9e0a-1b22ab9120b2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 12.2.17-tuxcare.12 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:fe045ae5-4167-5381-81e1-2f62c0bb1b68",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 12.2.17-tuxcare.12 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:0c12397c-b316-5bb4-a702-ea30bc6c6c6e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 12.2.17-tuxcare.12 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:b31e5054-dbd4-5a6f-8cb8-71ec2c6d07b8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 12.2.17-tuxcare.12 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:bd4b4983-b760-51f9-b327-9e5edf3c51a9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 12.2.17-tuxcare.12 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:92341547-7339-5f4c-b748-2b3772fd2325",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 12.2.17-tuxcare.12 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:cb360056-2387-5beb-af88-3c1291e0418c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 12.2.17-tuxcare.12 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:28dbb8d1-b8a1-5ff7-b48e-523c0639fa6f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 12.2.17-tuxcare.12 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:0f4dc3c1-ce79-5636-93f7-01407f81ef63",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 12.2.17-tuxcare.12 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:195cc96b-d5f2-5c17-be07-5fcf223ba05a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 12.2.17-tuxcare.12 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:c661de3f-5af9-5f5d-bfab-3d7dc88481ba",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 12.2.17-tuxcare.12 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:981650a3-3dd6-5f12-8903-1cca6e816dc0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 12.2.17-tuxcare.12 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:8e9d588a-a2ac-553a-944b-70b3d1e41c1a",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 12.2.17-tuxcare.12 of @angular/common. not_affected \u2014 Angular 12.2.17 does not contain the HttpTransferCache feature affected by CVE-2026-68945. HttpTransferCache, which caches HTTP requests during Server-Side Rendering (SSR), was first introduced in Angular 16.0.0\u2014approximately 4 major versions after the target version. The vulnerability concerns cache-key collision when repeated HTTP parameters are serialized, but since the entire HttpTransferCa...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:c7e43959-248a-5aa4-ae3d-9671b927b245",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 12.2.17-tuxcare.12 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:17f89d66-2eac-5e88-8a47-4f8d46c1fe39",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 12.2.17-tuxcare.12 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:85b2af51-92fe-5fdb-89a0-69202a8a1157",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88056 is fixed in version 12.2.17-tuxcare.12 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:36fc38d5-5a6c-57a3-807d-027426cdda6d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 12.2.17-tuxcare.12 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:107ce503-7b11-53a2-b838-5f0762c9e467",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 12.2.17-tuxcare.12 of @angular/common."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:b12f4f69-4130-5df6-979a-674b6bb6b4d8",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 12.2.17-tuxcare.12 of @angular/common. not_affected \u2014 Angular 12.2.17-tuxcare.9 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, withRequestsMadeViaParent(), and provideClientHydration() features which were introduced in Angular 16.0.0. This version uses the older module-based HttpClientModule system and lacks the entire SSR hydration transfer-cache infrastructure. The vulnerable code pattern described in the CVE do...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/common@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:88b66203-6552-588b-848d-3d4907c627da",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 12.2.17-tuxcare.12 of @angular/common."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/common@12.2.17-tuxcare.12"
    }
  ]
}