{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b83ea874-efb9-5d68-9af5-2c40f27c99d3",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/forms",
      "purl": "pkg:npm/%40angular/forms@19.2.25-tuxcare.4",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/forms@19.2.25-tuxcare.4",
      "version": "19.2.25-tuxcare.4",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@19.2.25-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:ff51b6ae-c0bf-539b-a4f8-c4b49191edc9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 19.2.25-tuxcare.4 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@19.2.25-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:a16edcaf-47d7-5165-960b-ad3b9093dc71",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101895 affects version 19.2.25-tuxcare.4 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@19.2.25-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:55331f28-1d8f-5f3c-8836-d2e156113208",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 19.2.25-tuxcare.4 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@19.2.25-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:1b311fb8-c468-5ede-b36f-7d2f5adec919",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-27970 does not affect version 19.2.25-tuxcare.4 of @angular/forms. Angular 19.2.25 is NOT affected by CVE-2026-27970. The vulnerability (XSS via unsanitized attributes in ICU message translations) was fixed in upstream Angular v19.2.19 by commit 747548721d authored by Doug Parker (Angular team). The target version 19.2.25 is 6 patch releases after the fix. The defense code is present at packages/core/src/render3/i18n/i18n_parse.ts:843-867, implementing allowlist validation, URI attribute blocking, and unknown attribute dropping. This is an upstream vendor fix, not a TuxCare backport.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@19.2.25-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e5db0f85-374e-5696-b843-32147a99a37c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54264 affects version 19.2.25-tuxcare.4 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@19.2.25-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:1da3ec2c-b3cb-5fb9-8729-93554d2065cf",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54265 affects version 19.2.25-tuxcare.4 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@19.2.25-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:cae14374-1301-5362-83ef-0367d4612a73",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54266 affects version 19.2.25-tuxcare.4 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@19.2.25-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:146ce72d-a44c-5d01-aff6-5a8d1398fdc3",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54267 affects version 19.2.25-tuxcare.4 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@19.2.25-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:47ac945e-6dfc-5403-8ba2-65424924ce44",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-54268 affects version 19.2.25-tuxcare.4 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@19.2.25-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:2b44722b-324c-54ab-aed1-c3cea491f00f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-68945 affects version 19.2.25-tuxcare.4 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@19.2.25-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:34325564-9609-5492-a473-9cafa35f4d9b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 19.2.25-tuxcare.4 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@19.2.25-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:e194c300-5453-545c-b4f7-89f572732783",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-69151 affects version 19.2.25-tuxcare.4 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@19.2.25-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:f0a7e3b5-a5b2-5ea2-abb7-3216a3f41f28",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88056 is fixed in version 19.2.25-tuxcare.4 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@19.2.25-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:c605b618-e7b8-583e-b65a-9f5e2eabc5e5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 19.2.25-tuxcare.4 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@19.2.25-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:ae36244d-e18d-5bee-b0f2-c926be040d7f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88058 affects version 19.2.25-tuxcare.4 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@19.2.25-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:c9f2e086-b01a-520e-bc73-8decaa9f03bb",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-88059 affects version 19.2.25-tuxcare.4 of @angular/forms."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/forms@19.2.25-tuxcare.4"
        }
      ],
      "bom-ref": "urn:uuid:08673512-c093-5988-89a5-bc3cba48d669",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 19.2.25-tuxcare.4 of @angular/forms."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/forms@19.2.25-tuxcare.4"
    }
  ]
}