{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:edc9a776-f87e-5db2-a27c-ac89f30953c1",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/compiler",
      "purl": "pkg:npm/%40angular/compiler@19.2.21-tuxcare.8",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/compiler@19.2.21-tuxcare.8",
      "version": "19.2.21-tuxcare.8",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:b98c071a-08ff-539b-89da-0e568d406b64",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101895 affects version 19.2.21-tuxcare.8 of @angular/compiler, and is fixed in 19.2.21-tuxcare.9."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:ffc9ed09-dfbd-518a-a576-72f65dc7e44f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 19.2.21-tuxcare.8 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:ef59169c-729a-543c-929b-09e53e36074b",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-27970 does not affect version 19.2.21-tuxcare.8 of @angular/compiler. already_fixed \u2014 The target repository (Angular 19.2.21-tuxcare.4) already contains the fix for CVE-2026-27970. The vulnerability (XSS via unsanitized HTML attributes in ICU message translations) has been addressed by TuxCare in prior backports. The defense mechanism in packages/core/src/render3/i18n/i18n_parse.ts lines 829-843 implements the same attribute allowlist validation as the vendor patch, blocking URI...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:39caacf2-f455-5c88-9c9e-e3942b58899b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 19.2.21-tuxcare.8 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:389b0c76-1ff6-5099-a4c0-4abb87e62b03",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 19.2.21-tuxcare.8 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:6c6c2a8a-e4ca-57de-a847-a178049ef97e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 19.2.21-tuxcare.8 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:96f10b27-6e50-51cd-bcc4-837899ba2171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 19.2.21-tuxcare.8 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:4adb6bd1-0b7c-5d0e-a806-18dd4fcf0fc4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 19.2.21-tuxcare.8 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:a0482850-c990-55db-9b67-5be2e9a9c3ce",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 19.2.21-tuxcare.8 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:88836c39-465b-5bc3-a62a-8754525ff215",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 19.2.21-tuxcare.8 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:ec0f05a3-dce2-5a53-9202-5aca6ee04c4f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 19.2.21-tuxcare.8 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:34679118-7aba-5fe0-89bd-20b5a15dc81f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 19.2.21-tuxcare.8 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:342c9c97-78ea-580f-9064-1ca33c72c92a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 19.2.21-tuxcare.8 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:87830af1-9820-528e-8907-c54463e0de6a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 19.2.21-tuxcare.8 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:edf3df80-16b4-5892-a206-0fedf8ddb9b4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 19.2.21-tuxcare.8 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:bc5fd83b-7546-5a48-9787-02fa71f655bc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 19.2.21-tuxcare.8 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:557f83ba-ccf5-5b8b-bcb6-56ca665b1f84",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 19.2.21-tuxcare.8 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:009b9886-4f1d-5a65-ad48-d5dab72fa091",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 19.2.21-tuxcare.8 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:92a21483-adbe-5ad1-90cf-ce878ac8c3af",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 19.2.21-tuxcare.8 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:cb403304-fefb-50a2-a477-3a70cfbb07f0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 19.2.21-tuxcare.8 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:aa82d3bd-95d3-513f-acb7-6d5c79c4aae4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 19.2.21-tuxcare.8 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:3e40a0d8-7238-5d4a-b1bf-7bd5825e02e6",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 19.2.21-tuxcare.8 of @angular/compiler. not_affected \u2014 CVE-2026-88056 does not affect this Angular v19.2.21-tuxcare.5 target. The CVE describes a vulnerability where `String.prototype.trim()` strips Unicode whitespace (U+00A0, U+FEFF) from URLs during SSR, converting same-origin relative paths into cross-origin protocol-relative URLs that leak credentials. The v19.2.x branch uses a simpler URL resolution implementation created by TuxCare (commit 81...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:062f0b60-5b84-5a63-8838-b3d0ad5b1103",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 19.2.21-tuxcare.8 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:91049ed1-934a-5275-8886-794e2ba532b4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 19.2.21-tuxcare.8 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:a353c43e-2cb1-5188-b586-29020e8e2ffd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 19.2.21-tuxcare.8 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@19.2.21-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:8f47315f-79ae-5641-bde6-0495ed7c7084",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 19.2.21-tuxcare.8 of @angular/compiler."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/compiler@19.2.21-tuxcare.8"
    }
  ]
}