{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:7265d7f7-5a14-57fc-84a5-2671a792eb38",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/compiler",
      "purl": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.5",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.5",
      "version": "16.2.11-tuxcare.5",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8eb4c0af-4e88-58f9-a79d-6554e7aa5bc8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59052 affects version 16.2.11-tuxcare.5 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0f132d90-4efc-5430-a3c7-4b5b8d168185",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 16.2.11-tuxcare.5 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:22f81cea-9e22-5723-9c8c-bfa644c6ba54",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 16.2.11-tuxcare.5 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:33b8dfff-2b98-5b21-9a20-0e3816b50ad5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101895 affects version 16.2.11-tuxcare.5 of @angular/compiler, and is fixed in 16.2.11-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:32e449eb-aad4-5a66-81a0-c0ebda9ff355",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 16.2.11-tuxcare.5 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4e0d3152-37b6-5984-b682-484e91eee932",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 16.2.11-tuxcare.5 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:cf68ab82-c0fd-5ca1-81b7-79754500d3d1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 16.2.11-tuxcare.5 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:bba82209-20e3-5be5-8846-65d299f968b5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 16.2.11-tuxcare.5 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:22b5bae4-9f84-54ce-b3ae-2fa02612f84f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 16.2.11-tuxcare.5 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:8cc286b4-5091-5886-9b86-56edeef3c6ce",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 16.2.11-tuxcare.5 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:305122b7-004f-5633-aa11-eca67a0f55ec",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 16.2.11-tuxcare.5 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a28d90b9-703e-5187-9543-0bd455feb482",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 16.2.11-tuxcare.5 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:eda10d3e-0ee1-569f-b41f-53dbcd94f8b0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 16.2.11-tuxcare.5 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:3a071cb3-8de9-5ba8-8c22-ee9eed3abc1f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 16.2.11-tuxcare.5 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:6e545a2e-9c64-5e72-8862-17f4bf027596",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 16.2.11-tuxcare.5 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4976a8cd-b1be-50ce-9f60-cdf235db1f48",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 16.2.11-tuxcare.5 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e088e374-de45-521d-8d38-633151010cd5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 16.2.11-tuxcare.5 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:89a8fba4-5a15-57ae-acb3-19b6384af071",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 16.2.11-tuxcare.5 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:6e225d21-405d-5226-97e1-ecc927e9537d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 16.2.11-tuxcare.5 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d18af1ba-21b1-55f2-9bf1-31f341f5198f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 16.2.11-tuxcare.5 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c4e98e09-fc9d-5359-a791-f58e85edab50",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 16.2.11-tuxcare.5 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:5bf4d1a7-e3b7-5c5c-9c8c-b5151cdb8704",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 16.2.11-tuxcare.5 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c8183f9b-3911-5fac-84a5-a292265b0fdf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 16.2.11-tuxcare.5 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1e8d1593-20b4-5b4d-a8fa-689f13ca126a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 16.2.11-tuxcare.5 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e8ef1bbe-f61e-50a8-8321-b755029b2ff8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 16.2.11-tuxcare.5 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:fff6c18b-6783-5d76-9657-6c7fe84a846d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 16.2.11-tuxcare.5 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:4eb47e5f-240d-554a-9484-2319fa0f404c",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 16.2.11-tuxcare.5 of @angular/compiler. not_affected \u2014 Angular 16.2.11-tuxcare.2 is NOT affected by CVE-2026-88056. The vulnerability requires WHATWG URL validation combined with String.prototype.trim() on URLs during SSR, creating a discrepancy that enables SSRF. While the target uses WHATWG URL parsing (backported in commit c03fbfd7cc for CVE-2026-50168), it does NOT call String.prototype.trim() on URLs. The attack chain is broken at the trim() s...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:7daa3c83-ba12-5d11-991f-01c5148548f6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 16.2.11-tuxcare.5 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2742e2c8-2374-583e-acca-7c71aa27768d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 16.2.11-tuxcare.5 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0bb92fde-d192-57a4-9f99-fd879583fdd0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 16.2.11-tuxcare.5 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:df1aff2f-f287-5291-adfe-7ec73b6909d6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 16.2.11-tuxcare.5 of @angular/compiler."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.5"
    }
  ]
}