{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a6d92ccc-def3-52a0-b3ca-9e3e60f787a5",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "@angular/language-service",
      "purl": "pkg:npm/%40angular/language-service@18.2.14-tuxcare.16",
      "type": "library",
      "bom-ref": "pkg:npm/%40angular/language-service@18.2.14-tuxcare.16",
      "version": "18.2.14-tuxcare.16",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2025-66035",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:0e1e7131-d70a-5bcf-be76-ba4a9925e3b4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66035 is fixed in version 18.2.14-tuxcare.16 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2025-66412",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:2822ba72-7292-5000-abab-b862cd6b0400",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66412 is fixed in version 18.2.14-tuxcare.16 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-101895",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:d459182c-0bb2-54c4-8603-1da795dbbec4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101895 affects version 18.2.14-tuxcare.16 of @angular/language-service, and is fixed in 18.2.14-tuxcare.17."
      }
    },
    {
      "id": "CVE-2026-101896",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:5e59248d-01bc-5cc5-a637-60a694306457",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-101896 affects version 18.2.14-tuxcare.16 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-22610",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:656750a7-c561-5334-8ca8-d4b434a337fa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22610 is fixed in version 18.2.14-tuxcare.16 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-27970",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:d4c2aa1b-a5ef-5976-8fef-e2ad60d761ff",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27970 is fixed in version 18.2.14-tuxcare.16 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-32635",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:0af33666-522c-5772-a54e-0a1b8c32a7e8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32635 is fixed in version 18.2.14-tuxcare.16 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-46417",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:43e550da-58a0-5f23-8fc6-24e551d67b43",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-46417 is fixed in version 18.2.14-tuxcare.16 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-50168",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:b926d9f9-9e11-589f-845a-c271085b1662",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50168 is fixed in version 18.2.14-tuxcare.16 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-50169",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:76428f20-fa6f-5ab0-ad54-e814eccbfff1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50169 is fixed in version 18.2.14-tuxcare.16 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-50170",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:c4fbc487-e248-5e11-96d6-952e54ae0954",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50170 is fixed in version 18.2.14-tuxcare.16 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-50171",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:3278af8d-38e4-59f3-99e5-a3199c27169f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50171 is fixed in version 18.2.14-tuxcare.16 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-50184",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:829e3ca8-5976-5671-9002-f4d62323e6e5",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50184 is fixed in version 18.2.14-tuxcare.16 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-50555",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:493db5f4-1a83-5bcc-bc40-1c49a65993fe",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50555 is fixed in version 18.2.14-tuxcare.16 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-50556",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:50c22830-7abb-5540-9cf1-ed38a7bff876",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50556 is fixed in version 18.2.14-tuxcare.16 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-50557",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:a6bfeebf-98af-5a21-8fec-ab2d6c9e5aaa",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-50557 is fixed in version 18.2.14-tuxcare.16 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-52725",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:9c31ad97-3c88-53bd-8988-a7d24c772b64",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-52725 is fixed in version 18.2.14-tuxcare.16 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-54264",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:1f5854a0-9dca-5e19-a7b5-03034e457a3f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54264 is fixed in version 18.2.14-tuxcare.16 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-54265",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:7bd9b5ea-f3b4-508b-b0c6-aa80f46112c4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54265 is fixed in version 18.2.14-tuxcare.16 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-54266",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:f074db3a-59e9-53ee-be5a-09bfa4bb88d3",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54266 is fixed in version 18.2.14-tuxcare.16 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-54267",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:98b35590-f36b-5b8d-93a4-e5826b8e45ec",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54267 is fixed in version 18.2.14-tuxcare.16 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-54268",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:fbe8d143-1b15-541c-ab35-2b1fd82c451e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-54268 is fixed in version 18.2.14-tuxcare.16 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-68945",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:655d3c53-cee4-5008-8070-fcc12c79c805",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-68945 is fixed in version 18.2.14-tuxcare.16 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-69149",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:fbfd81ed-1123-5406-a70c-c7d8d132078f",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69149 is fixed in version 18.2.14-tuxcare.16 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-69151",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:6d7100fb-7d2e-5622-9e3d-c05fd900a1ee",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-69151 is fixed in version 18.2.14-tuxcare.16 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-88056",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:d0945552-c05c-575d-83d7-1c94d8148fcb",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-88056 does not affect version 18.2.14-tuxcare.16 of @angular/language-service. not_affected \u2014 The target version 18.2.14-tuxcare.13 is NOT affected by CVE-2026-88056. The vulnerable code pattern (calling String.prototype.trim() on URL strings before resolution) was never present in this version. The target uses a refactored parseUrl() implementation introduced via commit 49a60f6045 (May 2026) that correctly handles Unicode whitespace by percent-encoding it rather than stripping it, main...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-88057",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:bae9a0af-d656-51f7-acbe-afc2bbdff37d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88057 is fixed in version 18.2.14-tuxcare.16 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-88058",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:848f82f6-7caa-513f-92aa-1e8d4b9e4409",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88058 is fixed in version 18.2.14-tuxcare.16 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-88059",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:7d297211-3e56-5895-ab99-b586d3fe45e0",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88059 is fixed in version 18.2.14-tuxcare.16 of @angular/language-service."
      }
    },
    {
      "id": "CVE-2026-88060",
      "affects": [
        {
          "ref": "pkg:npm/%40angular/language-service@18.2.14-tuxcare.16"
        }
      ],
      "bom-ref": "urn:uuid:045d450c-c62e-5646-a685-3780214e84bb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-88060 is fixed in version 18.2.14-tuxcare.16 of @angular/language-service."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:npm/%40angular/language-service@18.2.14-tuxcare.16"
    }
  ]
}