{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:9d277233-9681-596c-a951-f6eed4669a76",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/language-service",
      "purl": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.7",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.7",
      "version": "17.1.0-tuxcare.7",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-59052",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:84d15b88-b122-5695-8dc7-62b45d052898",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-59052 is fixed in version 17.1.0-tuxcare.7 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:e0bd8cb1-23c9-558a-988e-087e0244f0c9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 17.1.0-tuxcare.7 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:54218ddb-894f-57d8-b883-c3347764e26c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 17.1.0-tuxcare.7 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:5988376e-1aa1-5fb6-ba00-fcf9b0c33a1f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101895 affects version 17.1.0-tuxcare.7 of @angular/language-service, and is fixed in 17.1.0-tuxcare.8."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:daaae1fb-263e-5d2f-a9ac-377e567048a0",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 17.1.0-tuxcare.7 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:0a07115c-f289-53cd-af43-9c928d786d91",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 17.1.0-tuxcare.7 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:93b496b7-2794-582f-8fa9-936b882902be",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 17.1.0-tuxcare.7 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:d63ad8b1-8db7-51ee-9194-420d2c276c52",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 17.1.0-tuxcare.7 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-41423",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:785a4cca-efba-57b2-b722-6c098369d9e7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41423 is fixed in version 17.1.0-tuxcare.7 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:7251935c-6876-54e6-8ff9-9aa63f34795e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 17.1.0-tuxcare.7 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:5474ed6f-07c2-5c3d-9ebe-dd243255a397",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 17.1.0-tuxcare.7 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:4ff4f76b-3d39-5401-b91c-7cf7e1282e98",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 17.1.0-tuxcare.7 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:f7edd83a-04e5-5847-a432-bb0fe9f184a3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 17.1.0-tuxcare.7 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:1674ba08-d469-582b-adf5-cc747ce88abf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 17.1.0-tuxcare.7 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:02855b8c-1b3c-5082-8924-06b6891bb9e7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 17.1.0-tuxcare.7 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:53229e4f-6335-5b24-896c-087c9d13e0a4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 17.1.0-tuxcare.7 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:89de2cc3-e9ff-53ce-a63f-36abc799923b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 17.1.0-tuxcare.7 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:44550da1-65d3-5438-95ef-acd4189e1842",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 17.1.0-tuxcare.7 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:bdc48538-763b-5878-88ad-3d9b612d8fe3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 17.1.0-tuxcare.7 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:a2f4d4e5-56ae-544f-a463-86a3ac886307",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 17.1.0-tuxcare.7 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:5bbf929a-5298-5f83-ae7c-231296f09115",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-54265 does not affect version 17.1.0-tuxcare.7 of @angular/language-service. not_affected \u2014 Angular v17.1.0 does not have the TwoWayProperty IR operation that is the subject of CVE-2026-54265. Two-way bindings are desugared into separate property and event bindings before template pipeline processing, with the property half using the same parsePropertyBinding() code path as one-way property bindings, which are properly sanitized.",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:04aaf59e-b279-5f75-b0cf-a0d4ea530165",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 17.1.0-tuxcare.7 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:e679eaec-fb00-50fd-9780-3d07562a3c62",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 17.1.0-tuxcare.7 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:216c4177-e3a8-5d17-ba0f-1741506b8b90",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 17.1.0-tuxcare.7 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:fc13a04c-6e69-599e-819a-f1989e2c12bd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 17.1.0-tuxcare.7 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:0195b470-6c12-5ede-883c-6642238b4851",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 17.1.0-tuxcare.7 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:5c1f96d7-4912-5f2d-85ee-753e86a77f59",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 17.1.0-tuxcare.7 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:33503285-83cb-5e06-8238-d00eb8b5f773",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 17.1.0-tuxcare.7 of @angular/language-service. not_affected \u2014 Angular 17.1.0 was never vulnerable to CVE-2026-88056. The vulnerability exists only in newer Angular versions (v18+, v19+, v20+ before fixes) where a url.ts file with a parseUrl function that uses String.prototype.trim() was introduced. Angular 17.1.0 does not have this file in the upstream release. TuxCare created url.ts for their 17.1.0 fork (commit e06d36f339 by ejarocki@cloudlinux.com) but...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:f4c14833-5a2a-5a7c-893b-7d1f44b37ba9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 17.1.0-tuxcare.7 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:05bb89c7-fa34-59a0-8b1e-fd0728fed887",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88058 does not affect version 17.1.0-tuxcare.7 of @angular/language-service. not_affected \u2014 The Angular repository (version 17.1.0-tuxcare.5 at SHA 1b802ce320) is not affected by CVE-2026-88058 because it does not contain the vulnerable source code. The vulnerability exists in the domino library's HTML serialization code (lib/NodeUtils.js), which Angular references as a dependency in package.json but does not vendor. The upstream patch (89b20568dfaee1ec8e0b3bcf1872acdddd2f4fef) is a D...",
        "justification": "requires_dependency"
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:243e659e-f892-516d-85b2-a04d5e87b5cc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 17.1.0-tuxcare.7 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.7"
        }
      ],
      "bom-ref": "urn:uuid:1878058f-1bf1-5ff2-83c8-f4f8203bcac7",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 17.1.0-tuxcare.7 of @angular/language-service."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/language-service@17.1.0-tuxcare.7"
    }
  ]
}