{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ff69a288-1a6b-5903-9863-30f78db92d1d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:npm/%40angular/core@18.2.12-tuxcare.4",
      "type": "library",
      "name": "@angular/core",
      "version": "18.2.12-tuxcare.4",
      "purl": "pkg:npm/%40angular/core@18.2.12-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:31bb91c0-5278-59ea-91e5-766d3494cc69",
      "id": "CVE-2025-59052",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 18.2.12-tuxcare.4 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e27e9ed-c068-55b8-a098-fe470172ad91",
      "id": "CVE-2025-66035",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.2.12-tuxcare.4 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:baeea16b-64bc-5bb9-81fa-e4abe8daf76b",
      "id": "CVE-2025-66412",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 18.2.12-tuxcare.4 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36bccafb-abde-5a45-8484-f6f790bfcef5",
      "id": "CVE-2026-22610",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 18.2.12-tuxcare.4 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:192dfa2c-5f8e-5acf-9ec7-a72bdf7d3beb",
      "id": "CVE-2026-27970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 18.2.12-tuxcare.4 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75b6bfea-eb11-58b2-bf6f-f92e547e7955",
      "id": "CVE-2026-32635",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 18.2.12-tuxcare.4 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:548f986d-9ade-5510-b2c3-d40aefaba136",
      "id": "CVE-2026-41423",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 18.2.12-tuxcare.4 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19b2df01-0222-5a7c-8c38-01652b4f8072",
      "id": "CVE-2026-46417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 18.2.12-tuxcare.4 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00af4818-d807-5811-8d45-b5a136059c4f",
      "id": "CVE-2026-50168",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 18.2.12-tuxcare.4 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e06b530-57ff-5f34-ac54-0b8dab82ed5a",
      "id": "CVE-2026-50169",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 18.2.12-tuxcare.4 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbacf341-6f03-57c4-bae9-94fadc515037",
      "id": "CVE-2026-50170",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 18.2.12-tuxcare.4 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:401f463b-5d75-51ef-95fc-15b989124373",
      "id": "CVE-2026-50171",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 18.2.12-tuxcare.4 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12d8a7a0-22bb-57d8-8a2e-4aa1c5bb5e3a",
      "id": "CVE-2026-50184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 18.2.12-tuxcare.4 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4730fbd2-8013-5c38-aeab-bfe62cfd812d",
      "id": "CVE-2026-50555",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50555 does not affect version 18.2.12-tuxcare.4 of @angular/core. already_fixed \u2014 CVE-2026-50555 fix is already present in the target repository. The vulnerability concerns XSS in domino's noscript element serialization. The fix (escaping matching closing tags and adding NOSCRIPT to raw-text element handling) exists as a patch file that is automatically applied during yarn install via patch-package."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:beb98325-9690-5f2b-b7cc-ba38ab6f709d",
      "id": "CVE-2026-50556",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-50556 does not affect version 18.2.12-tuxcare.4 of @angular/core. already_fixed \u2014 CVE-2026-50556 (XSS via <noscript> raw-text serialization in domino) has been fixed. The target repository contains a committed patch file (tools/esm-interop/patches/npm/domino+2.1.6.patch) that applies the complete fix to the domino dependency. The patch adds NOSCRIPT to the hasRawContent set and removes the conditional _scripting_enabled check, matching the upstream fix exactly. This patch is..."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d8d50d3-1e6c-5f49-b8a9-2ca62580de30",
      "id": "CVE-2026-50557",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 18.2.12-tuxcare.4 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f49fdb4-120b-52ac-9095-301cc1611e29",
      "id": "CVE-2026-52725",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 18.2.12-tuxcare.4 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:607d972d-9aa7-57c0-9ab8-02b3e3599250",
      "id": "CVE-2026-54264",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 18.2.12-tuxcare.4 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8184e6af-0480-51a1-9f9b-2edc61a7eb33",
      "id": "CVE-2026-54265",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 18.2.12-tuxcare.4 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3505300-076f-596f-b05e-1450a452335f",
      "id": "CVE-2026-54266",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 18.2.12-tuxcare.4 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38fdf20f-723c-50ab-acbb-05efd550f90a",
      "id": "CVE-2026-54267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 18.2.12-tuxcare.4 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85581fb1-308c-56e3-8c75-c0907db82f1b",
      "id": "CVE-2026-54268",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 18.2.12-tuxcare.4 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86308c5c-f8fe-5873-b8c1-56b9e2e7a7fd",
      "id": "CVE-2026-68945",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 18.2.12-tuxcare.4 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d2689be-a306-5520-9cd4-68f2fcb90303",
      "id": "CVE-2026-69149",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 18.2.12-tuxcare.4 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.12-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6fcece4e-4284-526c-b0a3-c2dac60477ec",
      "id": "CVE-2026-69151",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 18.2.12-tuxcare.4 of @angular/core."
      },
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@18.2.12-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/core@18.2.12-tuxcare.4"
    }
  ]
}