{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ea0c3fa6-3306-58fd-913f-fe227cd0a1e8",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/compiler-cli@18.2.12-tuxcare.4",
      "type": "library",
      "name": "@angular/compiler-cli",
      "version": "18.2.12-tuxcare.4",
      "purl": "pkg:npm/%40angular/compiler-cli@18.2.12-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:5dd66238-e71b-5ca1-ab85-471de9b51871",
      "id": "CVE-2025-59052",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 18.2.12-tuxcare.4 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7fc67804-8ae0-51bb-9769-b46c1cfc9607",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.2.12-tuxcare.4 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:170ba564-beff-5265-9411-e9777795e7b0",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 18.2.12-tuxcare.4 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9daf08ac-f429-50c6-a835-96895f45f6e6",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 18.2.12-tuxcare.4 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a16bfe11-5612-51d1-a5c3-9e97c4379dcf",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 18.2.12-tuxcare.4 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b2c2700-d975-5199-8faa-8b075518920d",
      "id": "CVE-2026-32635",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 18.2.12-tuxcare.4 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbf63894-e0dc-5204-b2bd-585e15c6b3e0",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 18.2.12-tuxcare.4 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1318c240-34bf-5fd3-b4f2-b787777804fb",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 18.2.12-tuxcare.4 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c71af52a-4173-59ff-9099-e3286dd4ab3f",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 18.2.12-tuxcare.4 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:771ddc7e-ad65-50d0-93d0-b829f7d429c3",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 18.2.12-tuxcare.4 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1fa4fe3-99d5-5093-b3f6-0433d5146623",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 18.2.12-tuxcare.4 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c45285f9-ed85-5127-8246-8b2dfa1508f7",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 18.2.12-tuxcare.4 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28d19326-db40-5ace-9974-75ec5053f2e2",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 18.2.12-tuxcare.4 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc3750cb-7aaa-5bb4-84ca-8c18479d8bc9",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50555 does not affect version 18.2.12-tuxcare.4 of @angular/compiler-cli. already_fixed \u2014 CVE-2026-50555 fix is already present in the target repository. The vulnerability concerns XSS in domino's noscript element serialization. The fix (escaping matching closing tags and adding NOSCRIPT to raw-text element handling) exists as a patch file that is automatically applied during yarn install via patch-package."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d4fa432-1e47-5110-9740-e55f69687e59",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50556 does not affect version 18.2.12-tuxcare.4 of @angular/compiler-cli. already_fixed \u2014 CVE-2026-50556 (XSS via <noscript> raw-text serialization in domino) has been fixed. The target repository contains a committed patch file (tools/esm-interop/patches/npm/domino+2.1.6.patch) that applies the complete fix to the domino dependency. The patch adds NOSCRIPT to the hasRawContent set and removes the conditional _scripting_enabled check, matching the upstream fix exactly. This patch is..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8172a54-7124-5607-9dde-4fc496e6aa33",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 18.2.12-tuxcare.4 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0de57fa0-6450-5dd3-be55-9b78060f62cd",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 18.2.12-tuxcare.4 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a74d7c33-824e-51aa-b4ef-86edd1c17346",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 18.2.12-tuxcare.4 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fc6bd91-8559-5e28-9f24-b25686d8abee",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 18.2.12-tuxcare.4 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4791794-e14e-551c-93e0-0c1990cbef16",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 18.2.12-tuxcare.4 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea0fdc43-b2c3-5560-b192-73687348d846",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 18.2.12-tuxcare.4 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01c1b133-9d6a-5896-9b8f-ae6dd698abc0",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 18.2.12-tuxcare.4 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6aa530e5-3d4f-5252-96ea-21869156d9c4",
      "id": "CVE-2026-68945",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 18.2.12-tuxcare.4 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d35983cc-bbdc-532a-89c8-583a3344340f",
      "id": "CVE-2026-69149",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 18.2.12-tuxcare.4 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20a09df2-714c-5729-81e3-32b8c8ca4cc4",
      "id": "CVE-2026-69151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 18.2.12-tuxcare.4 of @angular/compiler-cli."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler-cli@18.2.12-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/compiler-cli@18.2.12-tuxcare.4"
    }
  ]
}