{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:727bffbd-9d75-5f98-b773-ab4e7f8e99f1",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/compiler",
      "purl": "pkg:npm/%40angular/compiler@6.1.10-tuxcare.15",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/compiler@6.1.10-tuxcare.15",
      "version": "6.1.10-tuxcare.15",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@6.1.10-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:4c0738ee-0094-54cd-ae2f-9261e9eb907c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 6.1.10-tuxcare.15 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@6.1.10-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:f3cca756-b798-592f-a815-d589d3a87618",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 6.1.10-tuxcare.15 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@6.1.10-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:b9f29cf2-9c95-57d3-89a4-eeb3bd80e844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 6.1.10-tuxcare.15 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@6.1.10-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:5f8ff6dc-e821-5d95-9cb4-dfba2441ae36",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-101895 is fixed in version 6.1.10-tuxcare.15 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@6.1.10-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:8dd2ddb2-f92a-5d15-9a84-6733052a0c74",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 6.1.10-tuxcare.15 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@6.1.10-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:b0f46d71-c119-5085-8e29-0414e96b2113",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 6.1.10-tuxcare.15 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@6.1.10-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:ea3aaea2-c38f-5e70-aae7-3efb6ff7b52e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 6.1.10-tuxcare.15 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@6.1.10-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:29e68ddd-f758-59ae-9aa1-458b20e20467",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 6.1.10-tuxcare.15 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@6.1.10-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:7c761916-e7c5-5d1f-af3d-3d978a65d159",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 6.1.10-tuxcare.15 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@6.1.10-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:e9b82009-2075-5343-9b2d-a8a8e1199b0c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 6.1.10-tuxcare.15 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@6.1.10-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:c3ea05dc-3333-5f1f-858a-f72f7f932cc1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 6.1.10-tuxcare.15 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@6.1.10-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:862b19df-26ae-5999-894a-710f70579c84",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 6.1.10-tuxcare.15 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@6.1.10-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:d5db3293-df9c-56dc-aa46-f9d71a8f4df3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 6.1.10-tuxcare.15 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@6.1.10-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:746b706d-50da-5c0a-a54d-549bba3a162f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 6.1.10-tuxcare.15 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@6.1.10-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:838ccdb0-1199-5cbf-8925-f98921c267b6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 6.1.10-tuxcare.15 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@6.1.10-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:d37ca489-e9cf-5a55-a808-7debd6d9ae62",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 6.1.10-tuxcare.15 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@6.1.10-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:ddf08942-820d-5289-8e3c-05c149d636cf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 6.1.10-tuxcare.15 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@6.1.10-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:861eed6d-56ce-50ac-a46c-1d1e6077e767",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 6.1.10-tuxcare.15 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@6.1.10-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:a94d905a-7356-5333-92d3-17816d71a71e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 6.1.10-tuxcare.15 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@6.1.10-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:d6621cee-9148-54dd-823d-26d825b75372",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 6.1.10-tuxcare.15 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@6.1.10-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:f9d0ed46-72c4-5ade-a968-46c95e20e642",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 6.1.10-tuxcare.15 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@6.1.10-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:82fbed6b-33cf-5f5f-bd8c-be40b7256cd9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 6.1.10-tuxcare.15 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@6.1.10-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:e56c8772-9118-5fae-9a2f-cb3706b13c70",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 6.1.10-tuxcare.15 of @angular/compiler. not_affected \u2014 Angular 6.1.10 is NOT AFFECTED by CVE-2026-68945. The vulnerable HttpTransferCache feature does not exist in this version \u2014 it was introduced in Angular 16.0.0 (April 2023), more than 5 years after Angular 6.1.10 (2018). The vulnerable file `packages/common/http/src/transfer_cache.ts` and all related APIs (`provideClientHydration`, `withNoHttpTransferCache`, `sortAndConcatParams`) are completel...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@6.1.10-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:7ecec2a4-f176-562a-8165-b92dcb463831",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 6.1.10-tuxcare.15 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@6.1.10-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:ab94a1a8-e819-58c4-a727-933e966739f1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 6.1.10-tuxcare.15 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@6.1.10-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:511535e9-795e-5721-86a9-a86bc7e28502",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 6.1.10-tuxcare.15 of @angular/compiler. not_affected \u2014 Angular version 6.1.10 is not affected by CVE-2026-88056. The vulnerable code pattern (url.ts with parseUrl using String.prototype.trim() and relativeUrlsTransformerInterceptorFn interceptor) does not exist in this version. These components were introduced in later Angular versions (post-6.1.10) and subsequently fixed in August 2026. Version 6.1.10 predates the vulnerable SSR URL resolution arc...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@6.1.10-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:bacd7dd5-b7c2-5282-a3fc-c9e6bcf49092",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 6.1.10-tuxcare.15 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@6.1.10-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:fc6d6dc2-278f-5673-b79a-ca95e6571595",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 6.1.10-tuxcare.15 of @angular/compiler."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@6.1.10-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:87c64667-fda2-58e8-9973-206cf2a6e018",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 6.1.10-tuxcare.15 of @angular/compiler. not_affected \u2014 Angular 6.1.10 is not affected by CVE-2026-88059. The vulnerable HttpTransferCache feature, withRequestsMadeViaParent() delegation API, and modern hydration system (provideClientHydration()) do not exist in this version. These components were introduced in Angular 16+ (circa 2023), while the target version is from Angular 6 (2018). The vulnerability requires automatic HTTP response caching duri...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/compiler@6.1.10-tuxcare.15"
        }
      ],
      "bom-ref": "urn:uuid:45dd6fbf-ceaf-5852-90bf-5c163a4e9a42",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 6.1.10-tuxcare.15 of @angular/compiler."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/compiler@6.1.10-tuxcare.15"
    }
  ]
}