{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:76c87400-59af-5393-923c-5ff17fa0d1b7",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/elements",
      "purl": "pkg:npm/%40angular/elements@17.1.0-tuxcare.7",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/elements@17.1.0-tuxcare.7",
      "version": "17.1.0-tuxcare.7",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:7334dc34-6f4f-577e-a217-1629134df117",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.1.0-tuxcare.7 of @angular/elements."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:0656e18e-3be3-58c7-9261-c305edd6bc8b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.1.0-tuxcare.7 of @angular/elements."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:c30653c4-34cb-58f9-b08c-ce601299a50f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.1.0-tuxcare.7 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:2dac5344-0ac5-5076-8170-3c6cdba41920",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101895 affects version 17.1.0-tuxcare.7 of @angular/elements, and is fixed in 17.1.0-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:53468fab-7f31-5201-b1f5-660f574479a4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 17.1.0-tuxcare.7 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:1cfeb12d-913b-5b2c-94ba-ebae56dc2b25",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.1.0-tuxcare.7 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:a3e95936-49db-5e32-95d5-5a865d288a5f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.1.0-tuxcare.7 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:80830eb9-4c77-5bf3-b653-b486222ea2b7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.1.0-tuxcare.7 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:0c97894d-3878-5506-acd4-04d0b4658e5f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 17.1.0-tuxcare.7 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:8a5ff8d2-0041-5d4a-8a45-954818e5edc1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 17.1.0-tuxcare.7 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:2be5084d-be94-5746-97b2-62cfc4caaafd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 17.1.0-tuxcare.7 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:d5604ee1-cbda-5f78-b6b4-b7482ab3de07",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 17.1.0-tuxcare.7 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:719de536-0d87-572e-8daa-7ecc16e02587",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 17.1.0-tuxcare.7 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:7e62005e-1998-5bba-a3ee-8c9074877a65",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 17.1.0-tuxcare.7 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:690bbf9a-15bf-55e6-b818-6ba775f48183",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 17.1.0-tuxcare.7 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:dea55190-e5f6-54e1-9ee9-cb9a7aa1c681",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 17.1.0-tuxcare.7 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:4f6980c1-5f2d-5a95-b8c5-02c1fa65c84f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 17.1.0-tuxcare.7 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:9592a40d-57f1-5d8e-b344-ed70c48f3afb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 17.1.0-tuxcare.7 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:0f0923ad-6b71-539e-b047-0e9ab60e6383",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 17.1.0-tuxcare.7 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:a40e019a-b82b-5c2f-b10c-68aea403ef21",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 17.1.0-tuxcare.7 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:823ea32c-e18b-56c5-80ca-d7e88edc6ba6",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 17.1.0-tuxcare.7 of @angular/elements. not_affected \u2014 Angular v17.1.0 does not have the TwoWayProperty IR operation that is the subject of CVE-2026-54265. Two-way bindings are desugared into separate property and event bindings before template pipeline processing, with the property half using the same parsePropertyBinding() code path as one-way property bindings, which are properly sanitized.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:96b50ed1-a34a-5493-80b8-8b24e3cc75c1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 17.1.0-tuxcare.7 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:d20195ee-7b03-5392-8aba-b103bae8b917",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 17.1.0-tuxcare.7 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:afaeab8a-523b-5f4c-80ee-d1abf0d0427f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 17.1.0-tuxcare.7 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:18aac1a5-c727-550b-820c-b8129f12920a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 17.1.0-tuxcare.7 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:059e61c6-0d3e-51f4-a238-1b41cec3b819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 17.1.0-tuxcare.7 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:77943c7a-764b-57d9-930b-989f45ea3477",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 17.1.0-tuxcare.7 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:7ba2ff8e-15c7-5a76-a9a6-ced904c628c9",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.1.0-tuxcare.7 of @angular/elements. not_affected \u2014 Angular 17.1.0 was never vulnerable to CVE-2026-88056. The vulnerability exists only in newer Angular versions (v18+, v19+, v20+ before fixes) where a url.ts file with a parseUrl function that uses String.prototype.trim() was introduced. Angular 17.1.0 does not have this file in the upstream release. TuxCare created url.ts for their 17.1.0 fork (commit e06d36f339 by ejarocki@cloudlinux.com) but...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:ea500b34-de46-51fe-89b9-c94331f2f739",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 17.1.0-tuxcare.7 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:b00b1558-52b5-5a20-8820-b78b19670203",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88058 does not affect version 17.1.0-tuxcare.7 of @angular/elements. not_affected \u2014 The Angular repository (version 17.1.0-tuxcare.5 at SHA 1b802ce320) is not affected by CVE-2026-88058 because it does not contain the vulnerable source code. The vulnerability exists in the domino library's HTML serialization code (lib/NodeUtils.js), which Angular references as a dependency in package.json but does not vendor. The upstream patch (89b20568dfaee1ec8e0b3bcf1872acdddd2f4fef) is a D...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:e849fc4a-8650-523d-a020-86381f93e209",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 17.1.0-tuxcare.7 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:0bd46053-5995-5b23-8998-75e752845414",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 17.1.0-tuxcare.7 of @angular/elements."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/elements@17.1.0-tuxcare.7"
    }
  ]
}