{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:9e670b0a-45a8-55a1-9de2-c089a4fc4ac0",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/compiler",
      "purl": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.6",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.6",
      "version": "16.2.11-tuxcare.6",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:105000c3-0eff-5010-8891-b51e78d22430",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59052 affects version 16.2.11-tuxcare.6 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:5b6d6e22-eddb-558a-b152-bb9f8dbc7221",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 16.2.11-tuxcare.6 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:5bdb68a1-4894-5932-b6be-dd22da1f0c9f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 16.2.11-tuxcare.6 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:5bf4b595-2d3e-571c-a671-c5a1b86f41dc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-101895 is fixed in version 16.2.11-tuxcare.6 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2a9789d1-1d7c-599a-b29f-2291fca3c011",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 16.2.11-tuxcare.6 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:1bdd3464-97f6-5e24-8616-883b4c981923",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 16.2.11-tuxcare.6 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c57e695a-345b-50ad-93bb-ce58e4d86202",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 16.2.11-tuxcare.6 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:321e13be-3b2a-58be-8329-1a7c9a598e23",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 16.2.11-tuxcare.6 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:97ee3c2d-4d89-5554-91ab-d4dca24ca111",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 16.2.11-tuxcare.6 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:16825dfc-5dc4-5670-af28-14ca86b14404",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 16.2.11-tuxcare.6 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:938f5167-db30-58bf-91d5-5bff092f5a68",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 16.2.11-tuxcare.6 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:b46d91fd-33aa-5724-90a9-52eeb026f399",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 16.2.11-tuxcare.6 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:ac99b8c7-02de-5d30-91e3-8e81b7b324b6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 16.2.11-tuxcare.6 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:0135d2bd-8a34-5677-8246-6e095d3206b7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 16.2.11-tuxcare.6 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6e82ceb7-29cf-5e9a-bb8d-650d8893886f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 16.2.11-tuxcare.6 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6ca0a6a0-698a-5caf-8b72-a39842ffefb5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 16.2.11-tuxcare.6 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:8ace9221-3318-5aa6-ac12-43c5edc81225",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 16.2.11-tuxcare.6 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d00175e0-66ec-567e-a939-aedf4c365ad0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 16.2.11-tuxcare.6 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4dd1fdc1-9f90-50d6-a781-430883c9eee4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 16.2.11-tuxcare.6 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:4c4ea670-405b-5061-949a-53b268753b6a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 16.2.11-tuxcare.6 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:5c09f2c4-9eb0-565c-b4ef-8f21bf9d8387",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 16.2.11-tuxcare.6 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:bebf9d60-157c-5a63-9a8e-6d9ed83a7947",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 16.2.11-tuxcare.6 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:3ed50b6d-dbdf-5a37-9e03-c7f8b3efa6b5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 16.2.11-tuxcare.6 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:8c65c5bf-88b0-5579-ab6e-97009fff2271",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 16.2.11-tuxcare.6 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:bb627cc2-36dd-52ba-997c-b6c272ffd62c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 16.2.11-tuxcare.6 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:a91e2969-4bc6-55da-8b0b-250da5d32176",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 16.2.11-tuxcare.6 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2819dc8e-1ad1-5e4a-8d26-7b0abcf68b8c",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 16.2.11-tuxcare.6 of @angular/compiler. not_affected \u2014 Angular 16.2.11-tuxcare.2 is NOT affected by CVE-2026-88056. The vulnerability requires WHATWG URL validation combined with String.prototype.trim() on URLs during SSR, creating a discrepancy that enables SSRF. While the target uses WHATWG URL parsing (backported in commit c03fbfd7cc for CVE-2026-50168), it does NOT call String.prototype.trim() on URLs. The attack chain is broken at the trim() s...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:45b2e37a-f66d-5bee-8202-3df0452df6ae",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 16.2.11-tuxcare.6 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:e2cef776-f4de-5cc4-87ba-c4e0b5eff071",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 16.2.11-tuxcare.6 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:988690af-8c36-5476-910e-50c1b4c52923",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 16.2.11-tuxcare.6 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:186239f5-563a-53d8-a84a-b5da10af46e3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 16.2.11-tuxcare.6 of @angular/compiler."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/compiler@16.2.11-tuxcare.6"
    }
  ]
}