{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:fe4ededf-9590-5bab-8c34-b9778623cc31",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/core",
      "purl": "pkg:npm/%40angular/core@17.1.0-tuxcare.8",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.8",
      "version": "17.1.0-tuxcare.8",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:3ca4b162-7c01-5f93-b139-3106ec2c9a88",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.1.0-tuxcare.8 of @angular/core."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:8e46de17-721b-5375-9857-e9d62808c872",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.1.0-tuxcare.8 of @angular/core."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:f4c0fa69-7d48-5246-9fb5-a119046ad515",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.1.0-tuxcare.8 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:e301a68c-8ec0-5553-a386-7ec3d593aecc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-101895 is fixed in version 17.1.0-tuxcare.8 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:7448aa6f-fb42-5eca-94a9-e7b6fa268a48",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 17.1.0-tuxcare.8 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:acba66de-5106-5231-ad15-815b07ca66ce",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.1.0-tuxcare.8 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:bf412f98-161a-57e4-a21b-40faadd94ac7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.1.0-tuxcare.8 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:0cd0c297-108b-52dc-8c02-28ecdf8849b1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.1.0-tuxcare.8 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:78ffe857-166b-5491-b2a4-9563738c7db5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 17.1.0-tuxcare.8 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:2030bc70-339e-5c13-8acc-00263ffae086",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 17.1.0-tuxcare.8 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:ace3b5d0-bdab-59d3-812a-db83d2e2995f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 17.1.0-tuxcare.8 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:0003c153-09cb-5bb0-a65c-cd6eed673e35",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 17.1.0-tuxcare.8 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:fd290a81-4bde-5717-aeb7-639227e7f1b6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 17.1.0-tuxcare.8 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:83d61f7c-5e48-5ab0-a717-c0e0a56559e9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 17.1.0-tuxcare.8 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:b1a67014-93ef-56ba-9129-5ec1b7364d06",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 17.1.0-tuxcare.8 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:bd3e13f1-edef-5d01-a0fd-41f93e17581d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 17.1.0-tuxcare.8 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:40afea04-107f-53d5-976b-33da40591c63",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 17.1.0-tuxcare.8 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:6bc61140-c02b-5f3d-867e-4a732f355e31",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 17.1.0-tuxcare.8 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:eb967f60-d8a9-5945-8780-739fe2c1ecc7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 17.1.0-tuxcare.8 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:2abf86fb-43c5-5e71-a096-f17426dc7c83",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 17.1.0-tuxcare.8 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:caddef00-f279-5b93-a060-0dcafe8ac43b",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 17.1.0-tuxcare.8 of @angular/core. not_affected \u2014 Angular v17.1.0 does not have the TwoWayProperty IR operation that is the subject of CVE-2026-54265. Two-way bindings are desugared into separate property and event bindings before template pipeline processing, with the property half using the same parsePropertyBinding() code path as one-way property bindings, which are properly sanitized.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:824ca9c8-023f-5308-8f3b-ee25f833f9e1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 17.1.0-tuxcare.8 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:90dfa195-3ba6-5fc7-aa67-f2d9e6bdd29f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 17.1.0-tuxcare.8 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:29afa3bc-8223-5ae1-ac19-5ac7a0c3d657",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 17.1.0-tuxcare.8 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:c5386864-8a94-5ce5-b3ae-bf3e01e4fb25",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 17.1.0-tuxcare.8 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:9609b285-c0f9-5914-b2d9-d3fbe1bcfc7b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 17.1.0-tuxcare.8 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:9fe98f06-f957-5084-969d-715353223b9b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 17.1.0-tuxcare.8 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:ab1f1be1-792a-5457-9443-06dd088b406e",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.1.0-tuxcare.8 of @angular/core. not_affected \u2014 Angular 17.1.0 was never vulnerable to CVE-2026-88056. The vulnerability exists only in newer Angular versions (v18+, v19+, v20+ before fixes) where a url.ts file with a parseUrl function that uses String.prototype.trim() was introduced. Angular 17.1.0 does not have this file in the upstream release. TuxCare created url.ts for their 17.1.0 fork (commit e06d36f339 by ejarocki@cloudlinux.com) but...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:6cd406d5-056f-5403-b806-01a2740bd57d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 17.1.0-tuxcare.8 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:4c6223c9-7d76-5236-95c9-bee938b46428",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88058 does not affect version 17.1.0-tuxcare.8 of @angular/core. not_affected \u2014 The Angular repository (version 17.1.0-tuxcare.5 at SHA 1b802ce320) is not affected by CVE-2026-88058 because it does not contain the vulnerable source code. The vulnerability exists in the domino library's HTML serialization code (lib/NodeUtils.js), which Angular references as a dependency in package.json but does not vendor. The upstream patch (89b20568dfaee1ec8e0b3bcf1872acdddd2f4fef) is a D...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:b473cef8-1400-5d82-b2bc-d0991919ec6d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 17.1.0-tuxcare.8 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:36273ea3-12ac-5c45-bde7-bdda2f73171c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 17.1.0-tuxcare.8 of @angular/core."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/core@17.1.0-tuxcare.8"
    }
  ]
}