{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:7b356105-18d6-58d2-9e4b-c80922dc7166",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/core",
      "purl": "pkg:npm/%40angular/core@16.2.11-tuxcare.6",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.6",
      "version": "16.2.11-tuxcare.6",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c804b4d1-e70c-57a0-bcf0-0e47c4d96a02",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-59052 affects version 16.2.11-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:d28a2619-9890-5548-a898-e25c65fe6f38",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 16.2.11-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:67c75b7f-7a56-5929-b655-4c6db80bdd37",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 16.2.11-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:17444d79-4780-5d13-9b80-a2704329f724",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-101895 is fixed in version 16.2.11-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:57d1acc4-b785-5cc5-aef2-c8e607f37cc7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 16.2.11-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:3ee6483f-0f32-5793-af3e-862838f2d40e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 16.2.11-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:acdfb4ba-db3a-53b4-a49c-3c016e19b534",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 16.2.11-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:fe781d2e-7c37-5d17-a3ab-15491bebd036",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 16.2.11-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:71a9fca3-ef63-5df1-a5a3-188aead63e8e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 16.2.11-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:de5d75ad-b85f-5147-8cdb-6b38789d8bc2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 16.2.11-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:bf3c84e9-8a08-577f-95e4-902ccab3fa03",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 16.2.11-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:f01921f1-35c3-51a1-8624-761a98cb7fc4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 16.2.11-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2ab6c8d9-ba60-5eaa-b748-82d52a5963c4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 16.2.11-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:0f0c218a-440e-5775-9925-49335189632b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 16.2.11-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:576d2cca-a110-58f3-93c4-c911e62bb046",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 16.2.11-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:aa5f72df-2450-5427-bda2-22e143938f6f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 16.2.11-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:11c7646c-6d8c-5867-8fee-50d712b057d6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 16.2.11-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:c82af03e-f7b5-51b1-ab00-ee3be80e8615",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 16.2.11-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:7e20cb52-f7a6-57d5-8a75-907872846ab1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 16.2.11-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:86c5e535-f4f7-542f-a865-fd42a8ae5860",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 16.2.11-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:6df03279-2f52-5159-a106-92f6f874664c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 16.2.11-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:8e17dadc-f0dd-5800-b285-e38839e8876a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 16.2.11-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:27b7cf90-9c1c-54c7-8358-1c2d772e0268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 16.2.11-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:18230c98-bdc1-57c9-a391-2ba06d462bc1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 16.2.11-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:099ce653-7385-5326-9da3-ec79090a65bd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 16.2.11-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:51dd381d-f418-5e2c-8234-b2bbff620ff7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 16.2.11-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2ef01825-7573-5746-9da4-c06f2794b488",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 16.2.11-tuxcare.6 of @angular/core. not_affected \u2014 Angular 16.2.11-tuxcare.2 is NOT affected by CVE-2026-88056. The vulnerability requires WHATWG URL validation combined with String.prototype.trim() on URLs during SSR, creating a discrepancy that enables SSRF. While the target uses WHATWG URL parsing (backported in commit c03fbfd7cc for CVE-2026-50168), it does NOT call String.prototype.trim() on URLs. The attack chain is broken at the trim() s...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:19edecc8-2e43-54fa-91c2-7b19c1ad23e5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 16.2.11-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2649e60b-486e-56c6-8ae9-6a08b12adc63",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 16.2.11-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:9492b719-a2a7-5f35-ac0b-0987eb5ea1af",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 16.2.11-tuxcare.6 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.6"
        }
      ],
      "bom-ref": "urn:uuid:2a973339-ddbd-52a8-9c28-2bedecd12ab9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 16.2.11-tuxcare.6 of @angular/core."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/core@16.2.11-tuxcare.6"
    }
  ]
}