{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d68c4850-0cc8-5603-af34-353acbd83d84",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/forms",
      "purl": "pkg:npm/%40angular/forms@17.1.0-tuxcare.8",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.8",
      "version": "17.1.0-tuxcare.8",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:700a7239-0a11-5b38-b98e-ec4c32b1c76b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.1.0-tuxcare.8 of @angular/forms."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:7a5b6b64-1b4f-5757-9679-4977f1256489",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.1.0-tuxcare.8 of @angular/forms."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:d75909dd-7c31-5db0-99df-17f95033f160",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.1.0-tuxcare.8 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:61f5716c-9f74-5990-9d7e-6b25b9575ebb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-101895 is fixed in version 17.1.0-tuxcare.8 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:9c533c84-58e6-525d-8e3e-6268450633ac",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 17.1.0-tuxcare.8 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:f238ae10-a131-53ec-bc4f-3d20fb4d6f6d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.1.0-tuxcare.8 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:98107557-9e2e-5c5e-be97-0753fd42906e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.1.0-tuxcare.8 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:c4eafd9b-dbd0-5e27-b43e-6928f2a33b09",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.1.0-tuxcare.8 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:d439d6c9-94ce-573b-9af9-8153a7c7e6a6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 17.1.0-tuxcare.8 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:418d0a55-d085-56e1-ae9a-6fe411edea0f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 17.1.0-tuxcare.8 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:27dd8c9f-7d4c-50ef-b239-a115cc879f70",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 17.1.0-tuxcare.8 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:81c2321f-4e55-582c-a49b-cffe28d14f9f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 17.1.0-tuxcare.8 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:1001509d-0476-5c40-90fd-92dcf627fe13",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 17.1.0-tuxcare.8 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:6e273a4a-9a71-59d2-ba87-af4eba54c2f7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 17.1.0-tuxcare.8 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:35a8483c-a8b8-5e44-93ff-05e173da9dfc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 17.1.0-tuxcare.8 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:3732fbd9-7f81-52fd-86a6-a603484cf4d0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 17.1.0-tuxcare.8 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:78e82108-776d-532f-bafb-d572028692b3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 17.1.0-tuxcare.8 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:b62a9d08-57d9-5e0c-b5d0-06ae4e02988b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 17.1.0-tuxcare.8 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:8361b1a6-a0aa-53a9-90c2-e3df31023c21",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 17.1.0-tuxcare.8 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:715f5cc0-7815-51da-a0d7-52b53284664e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 17.1.0-tuxcare.8 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:bc85a1fe-bda2-52ea-94fd-515f7243dad8",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 17.1.0-tuxcare.8 of @angular/forms. not_affected \u2014 Angular v17.1.0 does not have the TwoWayProperty IR operation that is the subject of CVE-2026-54265. Two-way bindings are desugared into separate property and event bindings before template pipeline processing, with the property half using the same parsePropertyBinding() code path as one-way property bindings, which are properly sanitized.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:a0fc3539-8e16-5b2e-8699-267bc8e1b434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 17.1.0-tuxcare.8 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:a5ed937d-a722-5253-9194-ee08ee68d04f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 17.1.0-tuxcare.8 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:f9972f01-0694-50d2-8818-7466d8c4a590",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 17.1.0-tuxcare.8 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:64389624-809b-50da-a2e0-6a1060e6c781",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 17.1.0-tuxcare.8 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:b953686a-b221-557a-96b7-b536d30f5c62",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 17.1.0-tuxcare.8 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:cf7a707b-02d7-5d2c-84d3-35aaf4dbae4d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 17.1.0-tuxcare.8 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:47a37007-bf71-5f78-b9f3-0210095d26ea",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.1.0-tuxcare.8 of @angular/forms. not_affected \u2014 Angular 17.1.0 was never vulnerable to CVE-2026-88056. The vulnerability exists only in newer Angular versions (v18+, v19+, v20+ before fixes) where a url.ts file with a parseUrl function that uses String.prototype.trim() was introduced. Angular 17.1.0 does not have this file in the upstream release. TuxCare created url.ts for their 17.1.0 fork (commit e06d36f339 by ejarocki@cloudlinux.com) but...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:2cc715a0-da5c-5712-b87e-f00fc7aff062",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 17.1.0-tuxcare.8 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:8f9fc1ed-7d51-564b-a991-7a8c585393ef",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88058 does not affect version 17.1.0-tuxcare.8 of @angular/forms. not_affected \u2014 The Angular repository (version 17.1.0-tuxcare.5 at SHA 1b802ce320) is not affected by CVE-2026-88058 because it does not contain the vulnerable source code. The vulnerability exists in the domino library's HTML serialization code (lib/NodeUtils.js), which Angular references as a dependency in package.json but does not vendor. The upstream patch (89b20568dfaee1ec8e0b3bcf1872acdddd2f4fef) is a D...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:a011f9a0-6bf8-5eb1-9691-08c54048158f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 17.1.0-tuxcare.8 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.8"
        }
      ],
      "bom-ref": "urn:uuid:d8e27269-92de-57a9-8b63-f3153be4148d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 17.1.0-tuxcare.8 of @angular/forms."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/forms@17.1.0-tuxcare.8"
    }
  ]
}