{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:8eb047d4-7ddb-5c1c-9516-1242136bf50c",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/core",
      "purl": "pkg:npm/%40angular/core@16.2.11-tuxcare.5",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.5",
      "version": "16.2.11-tuxcare.5",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2d859b4e-13ea-5083-8ec1-b4e65c34b970",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59052 affects version 16.2.11-tuxcare.5 of @angular/core."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:97e3f3cf-58e9-5c79-944e-99688a896ae0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 16.2.11-tuxcare.5 of @angular/core."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:1c610d49-7de5-5f49-997e-502527fc5feb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 16.2.11-tuxcare.5 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:63a09d87-bafd-5703-9dce-419c6642fd89",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101895 affects version 16.2.11-tuxcare.5 of @angular/core, and is fixed in 16.2.11-tuxcare.6."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b0e22d9c-75d9-5abf-b764-aef9cac91753",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 16.2.11-tuxcare.5 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2b9369c6-324e-552d-87a2-f0f3080f6b7f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 16.2.11-tuxcare.5 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:c4b9c3db-3c6e-5c21-a52e-88ad70b8621a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 16.2.11-tuxcare.5 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2f36d79b-222c-56eb-b3cc-71311d6002b0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 16.2.11-tuxcare.5 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:557bf3ea-4ce7-51c4-90e6-a1cf76c407a3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 16.2.11-tuxcare.5 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:de7e3bf1-5166-56dd-9847-672e98b9855d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 16.2.11-tuxcare.5 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b787f741-ad76-57b0-8d06-80a783cfd7b7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 16.2.11-tuxcare.5 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:29a80a49-f43c-53e1-85a1-269d732585fd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 16.2.11-tuxcare.5 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:f670087b-aa3c-5306-b86d-a739348570d3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 16.2.11-tuxcare.5 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:d95bf617-16eb-5bce-be08-0a31988604f4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 16.2.11-tuxcare.5 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:93c68b45-b6a1-51c0-9d8c-a6576276749a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 16.2.11-tuxcare.5 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:23fb9185-5a79-5422-bbb9-b39968800317",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 16.2.11-tuxcare.5 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:6d395f26-32cd-5fdd-811c-040310b3a03f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 16.2.11-tuxcare.5 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0dc24ad7-7d6c-59e8-aa9c-6d6de3c9f69f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 16.2.11-tuxcare.5 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b762f5ed-d446-5a4d-8fa4-18a657ade752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 16.2.11-tuxcare.5 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:2d3e344d-03af-51c6-b590-3edc9dfdfe38",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 16.2.11-tuxcare.5 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:b222a01b-63e8-59bf-b5a5-41c9bac20e88",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 16.2.11-tuxcare.5 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:aec06318-28ab-5020-a597-b478cb5decd3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 16.2.11-tuxcare.5 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:ab720b03-4bd8-5adb-9059-58d09cacbcb1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 16.2.11-tuxcare.5 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0b532c2d-9641-511c-9304-875175f23949",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 16.2.11-tuxcare.5 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:e0f83ad0-d8ec-5807-9469-c256ee325760",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 16.2.11-tuxcare.5 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:a923626e-b99f-5bad-8f69-a81b7bd05966",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 16.2.11-tuxcare.5 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:08989bbd-d11b-5576-a4d8-0a28e8b31428",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 16.2.11-tuxcare.5 of @angular/core. not_affected \u2014 Angular 16.2.11-tuxcare.2 is NOT affected by CVE-2026-88056. The vulnerability requires WHATWG URL validation combined with String.prototype.trim() on URLs during SSR, creating a discrepancy that enables SSRF. While the target uses WHATWG URL parsing (backported in commit c03fbfd7cc for CVE-2026-50168), it does NOT call String.prototype.trim() on URLs. The attack chain is broken at the trim() s...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:dedd9d4c-5d07-5365-a60c-1ad53cfb07c5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 16.2.11-tuxcare.5 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:330d26b1-7a71-5eff-a2db-dcc01d73390c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 16.2.11-tuxcare.5 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:0bec92bf-7416-57d2-8dc5-99e92d893dc4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 16.2.11-tuxcare.5 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.5"
        }
      ],
      "bom-ref": "urn:uuid:9d586fd1-ad30-5827-93c9-df3d42fac051",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 16.2.11-tuxcare.5 of @angular/core."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.5"
    }
  ]
}