{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c639d1ce-3512-5789-bc0f-15403584f388",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/compiler",
      "purl": "pkg:npm/%40angular/compiler@12.2.17-tuxcare.12",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/compiler@12.2.17-tuxcare.12",
      "version": "12.2.17-tuxcare.12",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:6ca7f23f-9bcc-5b34-be49-e23dd6219cb4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 12.2.17-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:cc7fe862-9885-59a1-acf4-77beb287f73f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 12.2.17-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:545f5019-6b3d-5a40-b854-f00794509582",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-101895 is fixed in version 12.2.17-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:ac77638c-083f-5881-a9d4-bcf707d14aeb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 12.2.17-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:2d9fd098-19c8-5545-a7d8-fe78db6cd636",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 12.2.17-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:4f50c45a-856c-5a6a-9bd0-7c2acef1d866",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 12.2.17-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:973cd34a-e6a7-595f-84d7-7e5a12687465",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 12.2.17-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:8c975b60-2bb4-5c07-b483-818b738da23a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 12.2.17-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:3b93addd-3434-50e1-9274-c60be7d0cccb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 12.2.17-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:b35f828f-b35d-5fd2-93fa-f8601d3e1662",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 12.2.17-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:ce258f69-d4b3-54a0-8f63-92b00f7a0417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 12.2.17-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:db985225-7d69-5a23-8504-8de4207e56f9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 12.2.17-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:50565234-2a67-5543-bcef-035ffce562af",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 12.2.17-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:1f3c2196-c5b9-5c7a-9771-b188d8d5d404",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 12.2.17-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:3e3eab3d-3882-52ec-8d92-4852d3e80c1e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 12.2.17-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:7ba43c24-bb03-5de5-8046-fe42ec8e19d3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 12.2.17-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:fa4fef87-60fa-58d7-b23e-e4bff7581da3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 12.2.17-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:1be29f07-2653-5565-bf13-31eb91f84cd6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 12.2.17-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:b008dda8-ea8e-5835-ace1-bfe8f436f350",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 12.2.17-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:c2df46a3-85a8-512f-8c8d-b2b9b778e3b6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 12.2.17-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:9652c754-e83d-5f4e-a469-6f8e87172e4f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 12.2.17-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:fe40598b-91bb-5ea0-8028-3f42d423fa27",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 12.2.17-tuxcare.12 of @angular/compiler. not_affected \u2014 Angular 12.2.17 does not contain the HttpTransferCache feature affected by CVE-2026-68945. HttpTransferCache, which caches HTTP requests during Server-Side Rendering (SSR), was first introduced in Angular 16.0.0\u2014approximately 4 major versions after the target version. The vulnerability concerns cache-key collision when repeated HTTP parameters are serialized, but since the entire HttpTransferCa...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:97e82d06-6681-556f-b254-c63a35b96ab7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 12.2.17-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:feee84b6-d7ad-53e5-8e0d-c7a9aecc060d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 12.2.17-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:2fb5660c-b8c4-5468-9d06-459e402a04fd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88056 is fixed in version 12.2.17-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:937acc6e-e9ef-5c77-a062-e3a557fae778",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 12.2.17-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:68ca2f49-79d6-5f84-8b11-55c99b7f7d60",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 12.2.17-tuxcare.12 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:c887ad9e-4786-5be7-bccb-7d3b77723520",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 12.2.17-tuxcare.12 of @angular/compiler. not_affected \u2014 Angular 12.2.17-tuxcare.9 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, withRequestsMadeViaParent(), and provideClientHydration() features which were introduced in Angular 16.0.0. This version uses the older module-based HttpClientModule system and lacks the entire SSR hydration transfer-cache infrastructure. The vulnerable code pattern described in the CVE do...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@12.2.17-tuxcare.12"
        }
      ],
      "bom-ref": "urn:uuid:48457c16-1a5a-5529-b5f7-d12b6ff283fd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 12.2.17-tuxcare.12 of @angular/compiler."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/compiler@12.2.17-tuxcare.12"
    }
  ]
}