{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:41dc8df3-abbf-53b2-aa16-2609e5140683",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/elements",
      "purl": "pkg:npm/%40angular/elements@8.2.14-tuxcare.14",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/elements@8.2.14-tuxcare.14",
      "version": "8.2.14-tuxcare.14",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2021-4231",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:a6d107ed-9514-5ac8-975c-6e0b8362d404",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-4231 is fixed in version 8.2.14-tuxcare.14 of @angular/elements."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:803b5a73-3b22-5342-b883-b113a024cabd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 8.2.14-tuxcare.14 of @angular/elements."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:639b78b6-1c7d-5f07-b305-54f35686e8b2",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 8.2.14-tuxcare.14 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:761e5607-aa6e-5a35-8183-966ed7bef75f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-101895 is fixed in version 8.2.14-tuxcare.14 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:2995564a-6e8e-5734-a230-021bf4cbf9e7",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 8.2.14-tuxcare.14 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:5a24d7e6-3e78-56c6-ae6a-25e5869a2eb5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 8.2.14-tuxcare.14 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:5f9f835f-79f1-524a-9d97-893c5d057046",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 8.2.14-tuxcare.14 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:2293379a-e944-51ba-8239-9bd5f5ad402d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 8.2.14-tuxcare.14 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:5e240707-4733-5379-8107-5580da1e042b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 8.2.14-tuxcare.14 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:ed6638a9-943b-5df0-911b-54308265d644",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 8.2.14-tuxcare.14 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:f556ac0a-b2e2-57d5-aa63-f49894d44060",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 8.2.14-tuxcare.14 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:9f58c2a2-2296-56ea-a169-5c04f0270907",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 8.2.14-tuxcare.14 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:97b792d6-3dc9-5682-8521-5cca68905769",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 8.2.14-tuxcare.14 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:f84b44b1-9ef6-5902-a8ea-0988f81bb422",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 8.2.14-tuxcare.14 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:5181fb15-eca7-568c-a556-0d4ff796ad76",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 8.2.14-tuxcare.14 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:77694220-7607-5664-b0ac-656042276b29",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 8.2.14-tuxcare.14 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:ed02c8ba-a176-5674-81ee-95361952738b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 8.2.14-tuxcare.14 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:a0706485-5160-52a7-b48b-64221a7b9e8d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 8.2.14-tuxcare.14 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:6f7b6bda-b2f4-5569-8c83-83aad93bf92d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 8.2.14-tuxcare.14 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:7de37f97-dd6f-5a90-8936-8897193d17f8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 8.2.14-tuxcare.14 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:72967121-6aad-5e4f-b0ac-ccf77268556d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 8.2.14-tuxcare.14 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:a15da1e0-3693-53cd-9b5d-7e167f774847",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 8.2.14-tuxcare.14 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:b240d72b-524f-5870-8474-68983768a16a",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-68945 does not affect version 8.2.14-tuxcare.14 of @angular/elements. not_affected \u2014 Angular 8.2.14 is NOT affected by CVE-2026-68945. The vulnerability exists in HttpTransferCache, a feature that automatically caches HTTP requests during SSR for client hydration. HttpTransferCache was introduced in Angular v16+ and does not exist in version 8.2.14. This version has only a manual TransferState key-value store with no automatic HttpClient integration, and no HTTP caching mechani...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:55b03453-e98d-5bb2-9511-3bbfa97ae0ff",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 8.2.14-tuxcare.14 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:7935a769-b683-5725-876a-e7af5ab6033b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 8.2.14-tuxcare.14 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:a6bc82d5-864c-5193-be65-0f9fe8c04573",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 8.2.14-tuxcare.14 of @angular/elements. not_affected \u2014 Angular 8.2.14 is NOT AFFECTED by CVE-2026-88056. The vulnerability requires a sophisticated URL resolution utility (`parseUrl` in `packages/platform-server/src/url.ts`) that calls `String.prototype.trim()` to strip Unicode whitespace, creating a discrepancy with WHATWG URL validation. This architecture was introduced in Angular v12+ (circa 2026 as TuxCare backports). Angular 8.2.14 (released N...",
        "justification": "code_not_reachable"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:28d5126f-6786-5969-b055-56fe78440d3b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 8.2.14-tuxcare.14 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:a52d79fd-c632-513a-abbf-64b3434e6d45",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 8.2.14-tuxcare.14 of @angular/elements."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:cebd28f2-1683-5839-a174-c6e17bf18734",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88059 does not affect version 8.2.14-tuxcare.14 of @angular/elements. not_affected \u2014 Angular v8.2.14 is not affected by CVE-2026-88059. The vulnerability requires HttpTransferCache, provideClientHydration(), and withRequestsMadeViaParent() \u2014 all features that do not exist in this version. These features were introduced in Angular v16 (per patches/CVE-2026-50170.patch and patches/CVE-2026-54266.patch). The target uses the legacy NgModule-based HttpClientModule without automatic ...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/elements@8.2.14-tuxcare.14"
        }
      ],
      "bom-ref": "urn:uuid:28ee0476-4c38-5955-a5f3-9a16b56ec359",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 8.2.14-tuxcare.14 of @angular/elements."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/elements@8.2.14-tuxcare.14"
    }
  ]
}