{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:398a58d4-d1f2-5d94-89a9-45763d529238",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/core",
      "purl": "pkg:npm/%40angular/core@8.2.14-tuxcare.14",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/core@8.2.14-tuxcare.14",
      "version": "8.2.14-tuxcare.14",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:71556c97-0922-5e17-83db-56cc501411e5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 8.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:0a583bd8-bc6d-57bd-92e0-e99539a9b1f6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 8.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:62e7249d-6039-5a88-86f5-31bc1385040d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 8.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:045ebb94-15b5-5bdb-a64c-20c54381dd14",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-101895 is fixed in version 8.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:abc5ef1f-6444-5da2-9f68-5e01264c7d36",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 8.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:b418f823-3282-5917-b074-756b5e13f751",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 8.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:d37db4f9-97d9-514c-9f32-94c8247a5340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 8.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:bdf54b0d-d947-5ba0-b57b-9b7758baf345",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 8.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:8cb557d2-591b-5bdb-bc0f-d7d34a0923a6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 8.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:67d42624-c045-5d50-87c2-5e39293cf2d7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 8.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:bb942049-28ff-543c-be02-bb0d34c7553a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 8.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:013b4fd7-3b17-5c56-8bbd-aadce204746b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 8.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:565da22c-2562-53a0-b60f-d9ac31ce5ffe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 8.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:32e81c83-52c1-58cf-a60a-3c002c08cfab",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 8.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:aaa0e2b1-0691-5d4b-8116-03d87f23209a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 8.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:91a68792-dd6a-5c08-81e4-5f99a9c1f48d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 8.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:9c12f8a7-e32b-5bd0-a011-83aff99a89e4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 8.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:7fb01015-112f-514e-88b8-5aa3e9211009",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 8.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:e79ca040-838b-5054-8579-b7e330e8f8fc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 8.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:bb5643ef-b131-5421-b3cb-362e73b6d76a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 8.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:3f37a95d-ea36-5dc9-8707-584a2a02e54b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 8.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:2e849bee-b2ae-52b0-ba2e-547f8bf36ce2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 8.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:b3213d5f-a17a-55c3-8d09-07fc119c616f",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 8.2.14-tuxcare.14 of @angular/core. not_affected \u2014 Angular 8.2.14 is NOT affected by CVE-2026-68945. The vulnerability exists in HttpTransferCache, a feature that automatically caches HTTP requests during SSR for client hydration. HttpTransferCache was introduced in Angular v16+ and does not exist in version 8.2.14. This version has only a manual TransferState key-value store with no automatic HttpClient integration, and no HTTP caching mechani...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:c4ce0d86-df7c-5b43-a0bb-58b0b5aa1de1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 8.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:6c941a63-6c03-54df-bf7a-b7f5012c5db0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 8.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:bcadc02a-252a-5fef-8d9f-74dd676ff4e9",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 8.2.14-tuxcare.14 of @angular/core. not_affected \u2014 Angular 8.2.14 is NOT AFFECTED by CVE-2026-88056. The vulnerability requires a sophisticated URL resolution utility (`parseUrl` in `packages/platform-server/src/url.ts`) that calls `String.prototype.trim()` to strip Unicode whitespace, creating a discrepancy with WHATWG URL validation. This architecture was introduced in Angular v12+ (circa 2026 as TuxCare backports). Angular 8.2.14 (released N...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:90ffc16f-2c39-5751-b851-2a10523d6a21",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 8.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:55aef83e-c36a-5272-acd1-db32a59ad357",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 8.2.14-tuxcare.14 of @angular/core."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:e63b288f-0cfa-5a30-84d2-18abbf3a46cb",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 8.2.14-tuxcare.14 of @angular/core. not_affected \u2014 Angular v8.2.14 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, provideClientHydration(), and withRequestsMadeViaParent() \u2014 all features that do not exist in this version. These features were introduced in Angular v16 (per patches/CVE-2026-50170.patch and patches/CVE-2026-54266.patch). The target uses the legacy NgModule-based HttpClientModule without automatic ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/core@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:fe41b353-8fa1-5edf-abf4-fb16479d6d43",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 8.2.14-tuxcare.14 of @angular/core."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/core@8.2.14-tuxcare.14"
    }
  ]
}