{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:95798198-ecc6-5f51-80c6-4f5f9c67cf92",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/compiler-cli",
      "purl": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.7",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.7",
      "version": "17.1.0-tuxcare.7",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:5805fba4-9330-5cee-8cfa-c2aba8665579",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.1.0-tuxcare.7 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:c55af3a2-a138-5dda-955f-95e251004a83",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.1.0-tuxcare.7 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:0e83eb39-8a19-5785-9ab2-5718362fac0e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.1.0-tuxcare.7 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:2eb7a235-2f82-5496-ba85-bc31fc46fd36",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101895 affects version 17.1.0-tuxcare.7 of @angular/compiler-cli, and is fixed in 17.1.0-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:9b5fe6df-f533-5654-95d9-570340977330",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 17.1.0-tuxcare.7 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:9ef46b68-31b6-51fb-829d-ac7468468eb5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.1.0-tuxcare.7 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:bf44adc9-c821-5b0d-81a1-24cdd6ba68c1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.1.0-tuxcare.7 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:7ab3b44b-eac3-51b3-9cd9-5d0599e8bbdd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.1.0-tuxcare.7 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:e71a5e04-eb66-56c6-b4ba-198e99bdec8e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 17.1.0-tuxcare.7 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:7ae18bc4-5a00-5ea5-a19f-4fcba07e4c49",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 17.1.0-tuxcare.7 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:865d912f-206c-544b-b0dc-7f8f5d0fd56c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 17.1.0-tuxcare.7 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:64330728-50c6-5a34-a43c-a3159ea1762d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 17.1.0-tuxcare.7 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:d4e1c176-f90a-541d-801f-84536fb87325",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 17.1.0-tuxcare.7 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:0e4a12c6-f944-521a-8fca-76e807e31f84",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 17.1.0-tuxcare.7 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:da629b89-44d5-5501-92bd-c01504df65b2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 17.1.0-tuxcare.7 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:f6fc1fa6-582b-5e16-b31a-72d7a0d93b16",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 17.1.0-tuxcare.7 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:e216f5f5-9f66-51c1-ac03-384163e5efc5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 17.1.0-tuxcare.7 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:9b7916ca-13c3-5a04-bb43-2ce59fd707a2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 17.1.0-tuxcare.7 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:ac93ecff-ca2e-56c2-83e3-3330c0ca8207",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 17.1.0-tuxcare.7 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:038db0b2-a529-5be5-870f-a72fafedde3d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 17.1.0-tuxcare.7 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:13c4a277-166c-5384-a916-50d61f590078",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 17.1.0-tuxcare.7 of @angular/compiler-cli. not_affected \u2014 Angular v17.1.0 does not have the TwoWayProperty IR operation that is the subject of CVE-2026-54265. Two-way bindings are desugared into separate property and event bindings before template pipeline processing, with the property half using the same parsePropertyBinding() code path as one-way property bindings, which are properly sanitized.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:551c1ec6-26cf-5367-a8fa-bfd757094386",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 17.1.0-tuxcare.7 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:6d117b4b-3f7a-53d2-8a42-48ef75e61602",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 17.1.0-tuxcare.7 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:09bcfc70-b861-567a-8f2a-3b224b9f87c2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 17.1.0-tuxcare.7 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:673b8352-1da3-5921-923e-1dd7e67382b8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 17.1.0-tuxcare.7 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:53ce51e7-f5cf-5614-b1c8-b10f48631c83",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 17.1.0-tuxcare.7 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:3c596acf-b3d7-5129-ab26-922e10e51959",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 17.1.0-tuxcare.7 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:c7099b19-feeb-56de-8fbd-65404e360975",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.1.0-tuxcare.7 of @angular/compiler-cli. not_affected \u2014 Angular 17.1.0 was never vulnerable to CVE-2026-88056. The vulnerability exists only in newer Angular versions (v18+, v19+, v20+ before fixes) where a url.ts file with a parseUrl function that uses String.prototype.trim() was introduced. Angular 17.1.0 does not have this file in the upstream release. TuxCare created url.ts for their 17.1.0 fork (commit e06d36f339 by ejarocki@cloudlinux.com) but...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:92925935-42bd-5792-9508-0f9a44ab0157",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 17.1.0-tuxcare.7 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:5e6ac65f-34b9-5ff3-ad25-01dc94921373",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88058 does not affect version 17.1.0-tuxcare.7 of @angular/compiler-cli. not_affected \u2014 The Angular repository (version 17.1.0-tuxcare.5 at SHA 1b802ce320) is not affected by CVE-2026-88058 because it does not contain the vulnerable source code. The vulnerability exists in the domino library's HTML serialization code (lib/NodeUtils.js), which Angular references as a dependency in package.json but does not vendor. The upstream patch (89b20568dfaee1ec8e0b3bcf1872acdddd2f4fef) is a D...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:921243fa-25e1-5719-a4a3-fc2d4997429c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 17.1.0-tuxcare.7 of @angular/compiler-cli."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:395dbf29-12c4-5bbd-83fc-fa3e7ea058bf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 17.1.0-tuxcare.7 of @angular/compiler-cli."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/compiler-cli@17.1.0-tuxcare.7"
    }
  ]
}