{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:bcb36bbc-4277-587e-af69-e50b3c123427",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/core",
      "purl": "pkg:npm/%40angular/core@16.2.12-tuxcare.16",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.16",
      "version": "16.2.12-tuxcare.16",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:a33b5d76-fc15-5a1f-980d-584349d497c1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 16.2.12-tuxcare.16 of @angular/core."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:139f6cbf-58d6-5501-a131-33d0110c5d88",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 16.2.12-tuxcare.16 of @angular/core."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:a68df2d2-79c0-52c3-a86f-aa9bab9bb7c4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 16.2.12-tuxcare.16 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:d8c963b4-8b02-5869-b855-406dc5c1037c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-101895 is fixed in version 16.2.12-tuxcare.16 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:1b6a4f22-eb9f-5cad-b799-510a1447c988",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 16.2.12-tuxcare.16 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:b397854f-3a7e-5b98-9b7a-02b02fba61ae",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 16.2.12-tuxcare.16 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:b1d6b10f-880c-5b62-938a-a6879b77b6c6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 16.2.12-tuxcare.16 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:0ebf54a6-d105-574d-bfbd-a666304deb5c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 16.2.12-tuxcare.16 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:218a5fb4-5ffb-52a4-8b0b-e8a1ccd8e917",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 16.2.12-tuxcare.16 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:98aefc02-97d3-5ce5-92e4-1491d78a5647",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 16.2.12-tuxcare.16 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:cc60c393-917b-5440-9b7f-7fb46037290b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 16.2.12-tuxcare.16 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:b44d32e5-4119-55ba-aeba-341fa283d073",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 16.2.12-tuxcare.16 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:d22007e1-3e12-5280-a787-2d4fc6a0c10c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 16.2.12-tuxcare.16 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:c08e37e7-99fd-57a0-89c5-a6085331180a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 16.2.12-tuxcare.16 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:582c67ed-8b48-5962-b3e4-b1cf3b29d7e6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 16.2.12-tuxcare.16 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:490cff9c-8b74-5a01-90bb-9147d2d43628",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 16.2.12-tuxcare.16 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:49f89d8a-6131-56db-919a-1eb7fb94719e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 16.2.12-tuxcare.16 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:5f8f8dd5-7fe6-558a-b8e0-1578321a31ed",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 16.2.12-tuxcare.16 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:dccf1953-8c1b-553f-a0da-80f5a2c5a54e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 16.2.12-tuxcare.16 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:1801e0ef-31c0-5bf4-96b7-110d72bd437f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 16.2.12-tuxcare.16 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:303e0f80-1946-52fb-b015-f990c413997e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 16.2.12-tuxcare.16 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:6bc74c43-bec4-5053-9213-fed13aa3a6a5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 16.2.12-tuxcare.16 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:a5d5a5ae-a6e1-52af-9266-92bb96343898",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 16.2.12-tuxcare.16 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:32209527-1eae-5f64-9829-ff011683ca73",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 16.2.12-tuxcare.16 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:a08c9d09-c22b-5460-8329-678e13efb8d9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 16.2.12-tuxcare.16 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:0576d656-affd-565f-ba06-63a034145303",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 16.2.12-tuxcare.16 of @angular/core. not_affected \u2014 CVE-2026-88056 affects Angular versions 20.3.x, 21.2.x, and 22.x where a refactored URL parsing utility added String.prototype.trim() that strips Unicode whitespace, enabling SSRF bypasses. The target (Angular 16.2.12-tuxcare.12) is based on Angular 16.2.x architecture, which predates the vulnerable code pattern entirely. TuxCare created url.ts fresh on June 24, 2026 for CVE-2026-50168, modelin...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:239a3e24-87b1-50dc-8fee-acea91fc5be3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 16.2.12-tuxcare.16 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:f5be2873-140a-51cb-97d7-0ee1a4fab2a4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 16.2.12-tuxcare.16 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:60661720-958e-50ef-8942-ad99de1d0b75",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 16.2.12-tuxcare.16 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:ccc30923-a384-5830-92b4-6a83bb93d2bf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 16.2.12-tuxcare.16 of @angular/core."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/core@16.2.12-tuxcare.16"
    }
  ]
}