{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e91e23cd-81dd-5cd0-b6a8-b4bcff638f85",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/compiler",
      "purl": "pkg:npm/%40angular/compiler@18.2.14-tuxcare.16",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/compiler@18.2.14-tuxcare.16",
      "version": "18.2.14-tuxcare.16",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:5f2e25d0-9018-53d1-a54b-86291b000ddd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.2.14-tuxcare.16 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:9288759b-bb96-520e-93d6-2db28580354e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 18.2.14-tuxcare.16 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:f7f86050-dbcd-51ed-930b-d57b65edf9b4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101895 affects version 18.2.14-tuxcare.16 of @angular/compiler, and is fixed in 18.2.14-tuxcare.17."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:0036b778-cd88-5ee3-ad5d-6d75f15ae49b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 18.2.14-tuxcare.16 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:4efef499-e229-5ec8-a340-dc6917fe8a2f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 18.2.14-tuxcare.16 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:4cfac1da-bf74-56a4-9806-6d14b0acba6e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 18.2.14-tuxcare.16 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:b6fb64fa-e217-507a-a56c-dca9312c116c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 18.2.14-tuxcare.16 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:03c9b67c-b060-5127-b885-56a13bf992e0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 18.2.14-tuxcare.16 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:d7684847-a2c0-5928-b621-aeca71ac5626",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 18.2.14-tuxcare.16 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:bb4e8bc9-b4e9-533c-add7-0afa8f8246f3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 18.2.14-tuxcare.16 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:d27a0949-3db8-55f4-a664-e6298f17cdda",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 18.2.14-tuxcare.16 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:46e56994-fff3-5283-ac4d-d45cb963ab6e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 18.2.14-tuxcare.16 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:1237d263-f08a-52ce-a9be-4cc3b6e481c9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 18.2.14-tuxcare.16 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:7346ba25-8f25-5cda-afab-f4171c33e074",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 18.2.14-tuxcare.16 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:69bb23ea-1045-55f8-9974-4aa322a73422",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 18.2.14-tuxcare.16 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:d281f3fd-9e78-5b54-859d-753ab5e41963",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 18.2.14-tuxcare.16 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:01a0226a-0f54-5685-b674-e099490f6e8c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 18.2.14-tuxcare.16 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:b9349b11-bc2b-5d1c-a5d3-5eb80f93e7d4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 18.2.14-tuxcare.16 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:c2a4e894-4152-51c1-b9e6-166da1abec4e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 18.2.14-tuxcare.16 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:6d08167b-4c59-5c1c-b305-e5e468f964b8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 18.2.14-tuxcare.16 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:4b55aba0-ce37-5470-bb50-81ad598477dc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 18.2.14-tuxcare.16 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:5b36ecb4-2d39-57a5-8d1d-fb968814171a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 18.2.14-tuxcare.16 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:38b3568e-2f0c-53f9-8965-a597b83d065e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 18.2.14-tuxcare.16 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:355497f2-ed28-5f56-8c8c-683b57f99440",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 18.2.14-tuxcare.16 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:82eff96f-2ffe-5a02-83f1-f6acee82651b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 18.2.14-tuxcare.16 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:236b91c3-ae0b-581f-9966-d1f87b0120de",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 18.2.14-tuxcare.16 of @angular/compiler. not_affected \u2014 The target version 18.2.14-tuxcare.13 is NOT affected by CVE-2026-88056. The vulnerable code pattern (calling String.prototype.trim() on URL strings before resolution) was never present in this version. The target uses a refactored parseUrl() implementation introduced via commit 49a60f6045 (May 2026) that correctly handles Unicode whitespace by percent-encoding it rather than stripping it, main...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:48d9082f-a818-5bba-a211-7d83ad4c6d59",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 18.2.14-tuxcare.16 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:c2e5281b-eff5-58ad-b4f7-f8bbb40e5677",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 18.2.14-tuxcare.16 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:c253eeb9-4cab-5db8-80fe-92b5802bb6ed",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 18.2.14-tuxcare.16 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:0e5391be-c1b7-5f98-864f-23346a64bd54",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 18.2.14-tuxcare.16 of @angular/compiler."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/compiler@18.2.14-tuxcare.16"
    }
  ]
}